"throw away all software written before 2026" does technically solve this problem, if you ignore everything else the article is talking about (deployment and continuity of service)
Throwing away old software is not a requirement, as demonstrated very successfully by Genode and its SculptOS.
Not to mention a whole lot of new vulnerabilities are bound to arise with all this new software.
We really just need better regulations around data retention, especially ppi.
Never going to happen though, no incentives exist to NOT sell my personal data