From the other perspective: am I going to accept a contribution from anyone who may be remotely connected to any company in the EU? Well, nope. I don't want to deal with that stuff in my private time just because some EU bureaucrat decided that accepting a contribution from a corporate contributor is now legally speaking a "commercial activity".
They will now hold a huge fat stick but there's no carrot. So when it's a commercial activity, can I have benefits like any other commercial entity? Say, claim VAT back?
Unless EU itself employs developers to contribute to OSS and ensure verification, this will only do harm.
It also means that companies will be reluctant to allow their employees to contribute to software as that would practically force the maintainers to abide by this which costs a lot.
It also sets impossible standards like “must shop code that doesn’t have vulnerabilities”.
And screws the process of dealing with exploits. Instead of informing ahead of time the authors and getting them fixed, then after 3 months issuing an announcement, you first need to inform a public organisation within hours of finding the exploit and then get the organisation to fix the bug again within hours.