[1] Typically ARM these days, but most system vendors aren't picking TPM vendors based on performance
Worth adding that not every outbound connection needs to go through the TPM (IMO). It's for the handful of services where the machine-identity actually matters, a secret store, or an HSM releasing key material onto an attested confidential VM, in my case.
Not suitable for servers, since it's such an easy DoS vector.