For example, one might imagine that eIDAS 2 isn’t backed by a consortium of would-be spies but is more likely backed by a small consortium of crappy CAs that are sick of being forced to comply with CA/B Forum rules and want regulation to override the rules.
(The CA/B rules are very specific and extremely aggressively enforced. It’s not like the GDPR where you can apparently get away with messing around for quite a while. Multiple fairly large companies have had their CA operations effectively shut down by the CA/B Forum for noncompliance.)