I see this comment a lot but I have never seen any evidence for this.While this is not intended as a criticism of you personally, you have ironically just demonstrated a big part of the problem. I might reply that I have seen this response a lot, no matter how often I have previously given detailed examples, sometimes even in the same forum. A lot of people who haven't themselves tried to run a business in this environment are almost completely unaware of the hassle it can be. Here in the UK, this is a particularly poignant issue because of the poor quality of "debate" around Brexit a few years ago.
Now, to answer your question, here are a few of the different barriers a new tech business would face here in the UK right now.
1. It's been difficult-to-impossible to open a new business bank account for the past several months. The big banks have (they claim) been so busy administering government support schemes for existing business customers that they couldn't take on any more. Government have been mostly ineffective at dealing with this problem.
2. To hire anyone (other than owner-directors, when some of this might not apply) means drawing up employment contracts with all the required elements, establishing formal grievance and disciplinary processes, being aware of numerous employment regulations, arranging all required insurance policies, identifying what evidence you need to keep to confirm a candidate's legal right to work for you, understanding any relevant minimum wages and time off including many kinds of statutory leave and pay, understanding your health and safety obligations including things you must say/provide/fund for your employee, establishing a payroll system and integrating that with the government's real-time information system if you haven't already done this, setting up a compliant company pension scheme if you haven't already done this, and who knows what else because this sentence is already half a screen long.
3. All of your personal data processing needs to be GDPR compliant. Its defenders like to say this isn't a big burden because it "just" means you have to do a few reasonable-looking things they can type out in a single comment. However, the main GDPR document alone is nearly 100 pages long and that's before you consider all the supporting material and the views of 28 different regulators. One of these things is not the same scale as the other.
4. If you're selling B2C, the consumer rights rules will apply. Again, on the face of it, that's fine. Who can object to fair protections for consumers, right? But when you actually read them, they are full of things that aren't well considered, like defaults that probably no-one would ever want, long and highly context-sensitive lists of information that must be provided at different times, obscenely disproportionate penalties for minor infractions by merchants, etc.
5. VAT. I'm not going to elaborate much, though I could write a pretty long book on the subject at this point. You're welcome to Google the numerous extensive criticisms out there. I suggest starting with #vatmess. Pay particular attention to how the EU changed the rules so what used to be a single market where merchants treated customers anywhere in Europe the same as in their home country got turned into a situation where merchants had to understand and comply with the tax rates and rules in every one of 28 member states. This is literally the opposite of the EU promise of creating a single market.
6. The IP landscape is unclear. Attempts to standardise it have repeatedly failed. No-one really knows what you can or can't get a patent for, or even what types of inventions you can or can't get a patent for. Copyright rules differ significantly with geographical location, and in some places additional related rights exist.
7. Lots of relatively minor stuff like the "cookie law", which is a tiny and yet totemic issue. It was well-intentioned but written by people who didn't really understand the technology and its implications. It doesn't do much to protect anyone. It annoys almost everyone. Non-compliance is widespread, whether deliberately or through simple misunderstanding or ignorance of what is technically required. There is little enforcement in practice, so operators who do make the effort to comply are left at a disadvantage. And years later, all of this still hasn't been properly fixed even though just about everyone agrees on it.
Edit to add:
8. How could I forget PSD2/SCA? There's nothing like putting obstacles in the way of actually collecting money from your customers to help a business grow.