on the last point: assuming someone uses Google or CloudFlare, it will require to put trust into either of these providers that their CSAM scanning algorithms don't flag anything by mistake. And they're not immune to mistakes.
Wouldn't it be better to outline that CSAM scans should be used as a tool for identifying potential harmful content with mandatory human review rather than "if CSAM scanning flags smth, it's objectively true and you must comply regardless of the outcome"?
