From a technical point of view, there is no meaningful way to put any access controls in place other than server admins choosing to un-federate any misbehaving servers and create their own little bubble. And cutting off most of the fediverse would defeat the point of having one.
Making the information public kind of is the point of putting it on the web on a public url without authentication. Don't do that if you don't want it. And think twice before you publish something you are not comfortable with sharing in public. Not that hard.
But yes, it's a matter of time before these things get crawled, scraped, etc. by all sorts of media organizations, marketing companies, etc. Once you have a critical mass of people who are relatively well educated, with disposable income, etc. any self respecting spammer, advertiser, marketing person, etc. is going to want to be all over this. The fact they haven't shown up yet (at least not a lot) has nothing to do with access controls, just with a lack of critical mass. The fediverse just wasn't that interesting until people started showing up a few months ago. Now we suddenly have people like Tim Bray and other tech influencers showing up. The more clued in linked in junkies are already getting mastodon accounts. That kind of is the point of a good public forum. These people will want to be a part of it.
There are technical solutions of course but they are going to have to involve making mastodon more like a federated signal/telegram, which does not seem to exist just yet. Mastodon just isn't it. Encryption is what you need if you want things to stay private. Of course it doesn't prevent anyone with their own modified client making some modifications that archives the plain text after decryption and information leaking that way. But it would be a lot harder to scrape everything. You basically have to infiltrate every group you want to scrape.
Mastodon with some crypto added would be nice though. The mistake with email was that pgp usage never caught on (too complicated to manage for most people to bother). Signing message content would be a nice start for mastodon. It would allow people to build reputations and verify that messages are coming from who they claim to be. Impersonating people is a thing on Twitter. Without message signatures, it's going to be a thing on mastodon too. And the nice thing with reputations is that they are a great basis for filtering too. If enough servers flag a particular public signature, they might just decline to accept content by that particular signature. Or accept it but filter it out of the public feed by default.