It's similar to just about any other violation, really: if I injure someone accidentally—even through negligence—I'm going to get a much more lenient punishment if I don't try to cover it up or run away from it.
The fact that such a case even has reporting requirements at all seems nuts to me.
See how that works out for the person who didn’t report it.
The EU is implying that it is illegal to accidentally write vulnerable code. Pure insanity, nearly every software company would go out of business overnight if this was a stance they actually enforced.
For the better, if your attitude is the “healthy SDLC”.
Security reviews are part of a healthy SDLC. You catch vulnerabilities as part of security reviews as they would be totally unnecessary if people simply wrote perfect code to begin with.
I am not gonna go out of my way to "whistleblow on vulnerabilities to the EU" after I have done my job and reported everything to legal.
But, it is also important for the fines to be reduced when taking the right steps to improve. Balancing this will probably be quite difficult.
What executive is going to brush something under the rug when they know their employees can whistle blow and if so, the executive will go to jail.
If they come forward they should be punished more lightly, but if not at all it only encourage "we'll just apologize latter" sort of thinking.
Meta put their customers at risk through negligent actions. A fine in the range you propose would be lower than any investment required to improve security (e.g. by hiring a single additional person). What company in their right mind would do anything to improve security in that case?
So again, why would this make sense?