A GPU could use a TPM to "activate" the "credential" to extract a symmetric session key and then do all the bulk decryption in the GPU. This does not invalidate your argument that the FSF is focusing on the wrong target though because the GPU vendors could just implement the TPM-like protocols in the GPU anyways.
no subject
https://news.ycombinator.com/item?id=42572090