Yeah but I want to distribute the result to users and patching driver signing checks out of their Windows installs is not an option. You are right though.
Instead of patching out one approach could be to add your own certificate to Microsoft's to allow yourself to sign your own drivers. but not nefarious actors.