Whatever an "antivirus firewall" does, it sounds like something that should be tied to permissions or not have an API for it, either way easy to stop all apps from doing.
And I'm skeptical that governments would stop Apple from enforcing a rule that says apps have to let you refuse permissions.
By definition apple can’t do anything in that situation, because people don’t want third-party app stores and sideloading to be managed or notarized by apple at all.
This is the very definition of bad-faith motte-and-bailey argumentation, and it’s logically incoherent to boot. Get apple out of regulating apps and App Stores, no more telling developers what they can do! Oh and i guess they can tell developers to do one thing…
These apps usually simply refuse to work without permissions, so this is not a solution. Empty/fake permissions are easily detectable too. Someone will make a “framework” for that and we’ll see it in most important apps.