The difference between the "old" content scanning and the new is indeed that they are now willing to "use" the results of that. Facial recognition was client-side only (or so they said), the results of which never left your phone.
Now they're doing content scanning and sending it to themselves as well as others.
In parallel Apple is starting up a growing advertising business, hiring aggressively and expecting that to be a big part of their future revenue. If they're now "allowed" (by its users) to do content scanning _and_ sharing the results, why wouldn't they use those results for themselves to target you with ads?
What Apple is proposing is basically adding a feature to scan any user's phone for a collection of hashes. Even if they say they will only use this for CSAM this sends a strong message to all government agencies around the world that the capability is over there. Maybe for US citizens this doesn't sound dangerous but if I was a minority or a critic of the government on a more authoritarian country I would jump ship from Apple products right away.