Those requirements are explicitly on the outcomes because companies like Apple used to abuse loopholes in previous, non-outcome defined laws. They, as always, have no one to blame but themselves.
The issue I have with that approach is that I don’t agree with that approach to governance. I believe it’s incumbent on the regulator to define what is acceptable vs. disallowed in unambiguous terms.