Disallow installing apps from outside the App Store, provide no system UI to do so. Prohibit apps from being app stores themselves or running code that didn't pass app review, with exceptions for dev tools etc. Make apps able to escape the sandbox, at least in some ways.
Even if an app somehow sneaks past app review and gives users unfettered access to their devices, it can't ever get too many users. If it's unpopular, it's not a concern to Apple, if it becomes popular, Apple will know about it and can levy very heavy contractual fines on the dev.