Isn't that a bit of an exaggeration? Surely what the EU is proposing is that browsers have to accept just those companies which pay the necessary fee and which some EU body declares to be trustworthy.
You're right, though, that this still adds to the attack surface, because now you have to trust not just your browser vendor, and all the CAs that they trust, but also this EU body and all the CAs that they trust.
(For those who haven't been following, here's what the EFF has to say about it: https://www.eff.org/fa/deeplinks/2021/12/eus-digital-identit... )