Earlier quoted context omitted.
> The alternative is upload everything unencrypted to providers who then scan there That's exactly how it should be. If a service provider wants to scan unencrypted documents for legal or PR reasons that's completely understandable. If instead they want to provide true E2EE and risk ending up in court with the regulators, that's also fine. E2EE with black box on device scanning, however, is an absolutely terrible ide…
There's no proper encryption though. In my mind, it's just like having everything unencrypted but using TLS to get it to Apple central. Apple employees can still access it. This is just ever so slightly better than the worst of everything. No real encryption, on-device scanning and scanning on Apple servers. "For privacy", WTF!!
I can't see any reason to implement a scanner in this way other than at least having E2EE as a possibility under consideration. They knew there was the possibility for PR backlash. Doing it on device also adds significant complexity. Meanwhile scanning on upload is a very common and well accepted (both legally and socially) practice.
On its own the current approach is all downsides and no upsides so there has to be something else going on here. Wanting to market iCloud as providing full E2EE is obvious and fits perfectly.