"If user = foo, then send the on device keys elsewhere"?
Or if those keys are part of a TPM, then a software update that just asks it to send in the decrypted messages?
Can judges not order this now, but can order decryption if the keys are stored centrally?