Locked down devices are kind of the only solution that both (A) preserves privacy and (B) solves the problem. However, it indeed strips a user of the freedom to use their device in the way that they want; although, safe to say that the US doesn't have all that much problem with that, given Apple's continued market dominance.
The alternative is what we're getting right now: laws that require verifying ID documents, often in ways that restrict even the notion of maintaining the user's privacy. Attestation might be an "OK" to "good" solution while this is between bad and really bad.
Client-side filtering solves the problem, because children's clients are owned by their parents. We should mandate that websites and apps send metadata about the content being served (eg extending the Rating: RTA header from 20 years ago) and mandate that OSs/browsers allow filtering to be easily configured at setup. This is a more private but also much more granular/useful solution, it's only difficult today because of a lack of coordination
Locked down devices will never preserve privacy since the government can just mandate spyware that you won't be able to remove.
There is no form of digital ID that isn't evil, but anything requiring attestation is super evil.