It isn't TPMs nor attestation nor DRM making this possible. It isn't secure boot either. It's walled gardens with secure boot -yes, secure boot- that the consumer can't bypass. Secure booting isn't the problem in an enterprise setting -- of course we _want secure booting_ in the enterprise. It's consumer devices that can't be jail-broken that are the problem. Although even then, the silly age verification laws and the people pushing them don't even care if the OSes run on walled garden devices.
I would posit that any device that can't be jailbroken is a walled garden. Whether the wall is made of an app store or an operating system, it's not yours if you can't do what you want with it.
Would it? Parents who so choose could restrict their teenagers from owning a device and instead give them one owned by the parent and configured not to show adult content.
A sufficiently adversarial teenager could get a different one, but they could do that regardless since it generally costs even less to get some 18 year old high school senior or homeless adult etc. to lend you their ID than to buy another device.