The premise is not that it couldn't be faked. It would be more practical to remove the key from the hardware and just use it to sign images if you wanted to do that.
The idea is that a centralized source of trust would revoke certificates belonging to bad actors or those that were stolen.
Cool. Every time I want to pass off AI images I'll buy a new Nikon camera. Always a Nikon until their cert is revoked. I'll short their stock before that.
The idea is that a centralized source of trust would revoke certificates belonging to bad actors or those that were stolen.