Cutting regulatory corners is a lot more complicated than “buying cheaper uncertified Chinese aircrafts”, and it’s completely invisible to the general public until an incident occurs.
The level of trust in the US aeronautic safety agencies can be summed up in other countries explicitly requiring non-US investigators.
That is the long term impact I'm talking about - it seems entirely plausible that this will become the norm rather than the exception it is now.
In the EU GDPR was a response to the abject failure of companies to actually self regulate - there was an actual consequence of a failure of self-regulation: the GDPR adding financial penalties for abusing consumers.
If the companies had actually self regulated, and actually self-limited their collection of data, and if only they hadn't sold off everyone's data to anyone and everyone, then they wouldn't have to deal with the GDPR.
So if the companies think it /is/ too aggressive, they've only got themselves to fault.