This is unlike Android, where you still see a lot of apps with a minimum requirement of Android 6.
All this to just say that it's much much worse to be on an non-updated Apple device than an Android one. Your apps won't take too long to stop getting updates.
Am I missing something? Is the technology used on the client side more error prone? Is the process which will lead to the reports different than with the other approaches already in place (including those used by other services such as Google Drive)
If you're on a mac, even "Big Sur", check to see if the CSAM weights file is here at: /System/Library/Frameworks/Vision.framework/Resources/NeuralHashv3b-current.espresso.weights
If you use un-jailbroken iOS 14 of course you can't easily check for the presence of the weights file, so you're already trusting Apple on their word.
If I did want to cook up conspiracy theory, it would be easy: Apple wants to distract from the fact that NeuralHash was broken by researchers. This project apparently is able to create CSAM collisions:
https://github.com/AsuharietYgvar/AppleNeuralHash2ONNX
If NeuralHash is really rolled out, and if this python project can really create collisions, the CSAM system could be DDoS'd by people on their own computers, jamming up Apple's internal censorship review system with false positives. Hence, Apple would be incentivized to sweep this under the rug by "delaying" rollout indeterminately.
There is so much network traffic between macOS services and the internet, I'm not sure how easy it would be for researchers to discover if CSAM reporting is enabled. Little snitch detects 292 macOS services on my M1, all talking to the internet. Network experts in Apple probably even have ways of bypassing little snitch.