The UK (not the EU) wants to just force Apple to backdoor iCloud. Insamuch as this backdoor involves any on-device code, it's the standard iCloud daemon (ubiquityd, AFAIK) that runs so long as you have an Apple Account sign-in. (can you even use an Apple device without one?) There isn't going to be a mandatory "UK Surveillance" app that everyone has to install, it's all going to be done server-side without your knowledge.
If your goal is to spy on people's phones, shipping an app is not a great way to do that. You have to trick the user into granting specific permissions, use fingerprinting to correlate different data streams, and hope Apple doesn't catch and ban you. Furthermore, third-party app distribution means you have to convince your user to install random shit from the web, which lots of people are afraid of. And finally, Apple still reviews third-party distributed apps and still has the right to reject malware. The only control they ceded is that now apps they don't want on the App Store for non-technical reasons (e.g. they're a brand risk or the developers refuse to pay their tithes[0]) can live on AltStore PAL. But there's no additional spying being enabled that wouldn't have been available had Apple not been forced to respect third-party app stores.
[0] Note that if you do use third-party distribution you still have to pay a "core technology fee" per install, so you still have to pay a tithe, but it's a different and potentially smaller one.