That's true, however I'm not sure I trust "Big Tech" to self-manage this system. After all, "Big Tech" are the ones that forced us into needing this legislation in the first place. And they don't have a great track record at protecting PII.
The federal government already has all the info it needs to run an ID program.
First, we need privacy regulation (eg a US port of the GDPR) that stops the existing widespread abuses of identification and personal data, especially the abuses being facilitated by the current identification systems. Only after this is fixed does it make sense to talk about increasing the technical strength of identification.