The main fall down here was a lack of rigor on their part, and Crowdstrike's. Thorough testing of all configurations of Windows is likely impossible - but it's clear this one affected so many it was a common one - why was this not caught?
As for the EU - I'd say where their problems lie is in applying rules and regulations, but only in the context of that time and space - there is no regulatory follow-up from the initial conditions to ensure that software continues to be safe, and few certifications offered outside private companies own certification. It's just been announced they are diverting budget away from FOSS projects towards AI ones in their Horizon 2025 budget, once again weakening the software ecosystem in favour of the-popular-thing-at-the-moment.
For their own sake they should be funding independent Red/Blue teams, and securing the internal supply chain of software - both to protect it from current threats, and future geo-political changes. But this is where they leave it up to market forces and this is why this situation will absolutely happen again and again.