For an example, with alternative app stores it's very likely you could release a jailbreak and have it installable without a computer since most (non-checkm8) jailbreaks break out of the sandbox and exploit their way to root access and installing an dpkg frontend. That's all well and good until someone does the same but hides jailbreak code in an inconspicuous app that initiates the jailbreak in the background, and instead of installing dpkg it installs a keylogger/keychain dumper that sends all passwords to a remote server.
Either Apple will still need to review these, have IPAs notarized, or have contracts in place with each app store developer to ensure the same app review quality. I don't see epic accepting any of these scenarios without a fight.