In Hungary, where the central bank created the same rule about not allowing banking apps on "unoffical" devices, they do, but you need either the app or SMS for 2FA. Apparently they consider SMS secure...
Tbh it's way less annoying, than I tought when they introduced.
The idea is that while SMS may not be "secure" in general, it is secure enough when used as the second authentication factor.