There is no meaningful sense in which PGP could ever be said to "facilitate" terrorism in the same way that Tornado Cash is rightfully characterized as facilitating money laundering. PGP is a program that runs on your host, encrypting your email. Tornado Cash is a service, run by an individual who was warned to cease serving sanctioned entities, and failed to do so.
This is false. The (vast majority of the) Tornado Cash contracts were either deployed to Ethereum as immutable contracts, or updated in 2020 to revoke mutability (once the final zkSNARK parameters were included) [0], meaning that they could not later be updated by the user(s) that deployed them. Arguing that Tornado Cash is run by an individual means arguing that the entire Ethereum network is run by an individual. There was no way for a warned individual to comply with that warning.
[0] https://www.coincenter.org/education/advanced-topics/how-doe... - Section titled "Can Tornado Cash be removed or updated? If so, by whom?"
Thousands of little contracts doesn't absolve a financial institution from a few many-billion dollar illegal transfers, especially after they've been warned repeatedly.
Usually a smart contract protocol is a set of contracts working together, deployed to the blockchain, which provide application logic that executes regardless of who is interacting with it (via "transactions")