I'm ok with enforcing hardware security. Both for banks and governments.
But it must not limit the ability of running custom software on a phone. And especially not enforcing every person to get a Google/Apple signed phone.
Like if I get GrapheneOS on my phone. Banking/gov apps should work. But I believe this could be possible with enforcing hardware security as well.
You can't have both. "Hardware security" means the manufacturer decides which OS can run and you can't override it.
The chain of trust always has a software layer. I don’t believe what you want is possible.
I find the bank talking point strange, why are they special, are they even targeted more. It just feels like a boogeyman “think of your money!”