Any age verification should come with an OAUTH style government run API. The idea being you verify your ID with the government, and the service that required age verification gets back a true or false for does this user meet this age requirement. That way the amount of data shared is kept to a minimum. The UK, and Brazil who passed a similar law, 'cheated' by just forcing private companies to figure it out.
The EU is already implementing this in the best way it's ever going to be implemented: https://digital-strategy.ec.europa.eu/en/policies/eu-age-ver... I really don't like this perfect law enforcement future, but this EU initiative is about the best design one can have.
There are no plans to allow separate, standard AOSP attestation methods for Android. Google's crooked* Play Integrity will be the only one.
*crooked because it confirms Android 8 are safe and with full integrity, even when they're rooted, full of malware and present spoofed certificate.