As you may have guessed, this simply pushes out smaller devs. This used to NOT be like this. It should NOT be like this.
EV certificates has always felt like an utter scam and extortion to me. At least now there is an alternative.
10 years ago I wanted to build a Love2D game, and release it for the three major OS's. The .love files are effectively ZIP archives, kinda like cartridges, but you need the correct Love2D version (they broke API compat every year or so). Windows and Mac used to be: "cat love.exe game.zip > game.exe".
Linux gave me the most crap, because making a portable, semi-static build was a nightmare; you couldn't rely on distros because each one shipped a different version of love.
Now Linux is actually becoming more viable, not because it's making that much progress, but because the two mainstream platforms are taking steps back.
And game consoles naturally.
Apple is never first to do something.
You can use an ad-hoc signature to sign, but people who download the app will still have to jump through hoops to run it.
That random exe link is signed by Microsoft.