I think this is kind of a ticking time bomb with a lot of companies depending on personal devices for 2FA.
Where "access" is specifically defined as full functionality on a device of an individual's choice, and offers safe harbor for example options. Like HTML over HTTP (without javascript) or REST APIs.
This should be built on top of existing accessibility requirements, with the goal of preventing not having a Google / Apple smartphone from being an access barrier.
"Covered services" should be defined two-fold, either by market share above a certain threshold or services that are required for normal life/studying/work (and tied to any public funding).
It should be default illegal for entities to make bargains with Google/Apple (or app developers) that exclusively rely on certified devices, except for extremely limited special circumstances.