Oh, I think I see where the misunderstanding lays. How does your UKI get signed? I always forget that you develop systemd with a focus on distros like Fedora and such.
On ArchLinux the keys to sign it generally also lay on the system itself it gets signed locally...