At the absolute worst, they were agnostic to the presence of criminal activity. This is in contrast to Tornado Cash, which was repeatedly told that their service was being used to launder money.
There is no meaningful sense in which PGP could ever be said to "facilitate" terrorism in the same way that Tornado Cash is rightfully characterized as facilitating money laundering. PGP is a program that runs on your host, encrypting your email. Tornado Cash is a service, run by an individual who was warned to cease serving sanctioned entities, and failed to do so.
This is false. The (vast majority of the) Tornado Cash contracts were either deployed to Ethereum as immutable contracts, or updated in 2020 to revoke mutability (once the final zkSNARK parameters were included) [0], meaning that they could not later be updated by the user(s) that deployed them. Arguing that Tornado Cash is run by an individual means arguing that the entire Ethereum network is run by an individual. There was no way for a warned individual to comply with that warning.
[0] https://www.coincenter.org/education/advanced-topics/how-doe... - Section titled "Can Tornado Cash be removed or updated? If so, by whom?"
Thousands of little contracts doesn't absolve a financial institution from a few many-billion dollar illegal transfers, especially after they've been warned repeatedly.
Usually a smart contract protocol is a set of contracts working together, deployed to the blockchain, which provide application logic that executes regardless of who is interacting with it (via "transactions")
This is known as “chilling effect” in a legal context.
People who might otherwise want to use this for financial privacy would be wary, since if they deposit funds to the contract, they don't have any way to know if they'll be able to use the unlinked funds later if withdrawn.