How? As far as I understand by having the client download encrypted messages from one Telegram server and keys from another and then place those servers in different datacenters in different jurisdictions.
FTR: of course I am aware that unlike E2E-encrypted messaging in this case you have to trust the vendor. If you do is up to you. I trust them more than WhatsApp (who are E2E-encrypted but backup to NSA^HGoogle and try to extract all kinds of metadata) and less than Signal (even though Signal has had at least one horribly security glitch).
One more thing: Telegram are also pretty open on the fact that they take down public terrorist content.
One justification for sharing keys could be that security services want to use data recorded by SORM (and nowadays we also have the goddamn Yarovaya law) as an evidence and to do that you have decrypt it. Luckily for us modern security frameworks are built around ephemeral keys and forward secrecy.