EME is the standardized specification on the browser side... That's all it is.
CDMs could technically only work for one browser via fingerprinting, but that could already happen without EME (or DRM entorely) using browser fingerprinting to only serve content to UAs the publishers "trust".
A standard way to allow anyone to run one of those CDMs and removing the publishers as the gatekeepers.