The key factor is the compatibility with international roaming - customers, manufacturers and operators really want the phone to "just work" when you step out of a plane in a random place where the only cell tower in range is run by an operator that was established after your phone was made. There can't be a global list of 'trusted operators' for political reasons (long story), and in order to make calls, your phone needs to work with that operator directly - it can't do end-to-end to your home provider, your data streams won't get routed halway across the world and back for no good reason, they'll route only the billing info and metadata as per the roaming agreements.
The other problem IIRC is virtual towers - when operator A gains improved coverage by renting capacity on a tower of operator B, they want the phone to seamlessly connect to that tower as if it's run by operator A (even if it's not) without the phone being able to inform the customer that hey, you're now connected to operator B - because it might rise confusion about roaming charges, and also give bad PR about coverage which might suggest the customer to switch to that competitor.
What could work is the combination of (a) your phone being able to cryptographically verify if it's really connected to your 'main' operator or someone they explicitly authorized (isn't this something that 5g and even 4g protocol supports?) and (b) requiring explicit confirmation if connecting to someone that's not. Of course, (a) would mean that police Stingrays would be recognized as legitimate cell towers, they'd need cooperation from the cell network, but's IMHO not really a problem, just some paperwork whenever they need to activate a new batch of intercepting devices.