As a matter of interest Shamirs Secret Sharing algorithm (https://en.wikipedia.org/wiki/Shamir's_Secret_Sharing) is quite nice in that respect. The "secret" would be the decryption key. Using Shamirs Secret Sharing algorithm you could split the key into two so you would need both parts in order to work out the decryption key. The government could have a part. The company could have another. Only when both were combined could anyone work out the decryption key.
This would mean neither the company nor the government could decrypt messages until they work together - and therefore reduce the risk of hackers and rogue employees. It wouldn't break the encryption with dangerous backdoors but would allow the authorities to quickly gain access when needed for a specific investigation.
I doubt anyone would ever implement anything like that since it would be (slightly more) complex and you would have to trust that the decryption parts are valid. But I thought I would just mention it in case anyone else might find that algorithm as interesting as I do.