Google could have avoided all of this blowback over WEI by simply calling it "HTTPS+ Everywhere" and pretending it helped user privacy only.
I'll grant there are a few more TLS CA options than possible WEI attestation options (if they really are to come from the OS vendors like the spec suggests). But not that many more and any legal pressure applicable to one is applicable to all. Both Google WEI and Google QUIC HTTP/3 are terrible and both need opposition or at least mitigation.
Self-signed certificates are banned in HTTP/2 onwards, which is really irritating when it is used for internal server-to-server communications.
You have to set up a Root CA certificate and use that to sign a second certificate. It's the same thing but with extra steps.