This ended up being a longer post than I intended, but overall I think your entire idea is fundamentally flawed, requires taking control of a computer away from the owner, and wouldn't even solve the issue.
> to voluntarily run a CSAM scan on our systems
The results of such a scan are meaningless to anybody who doesn't control the computer that performed the scan. If these results are to be trusted by authorities, that implies that we no longer control the computers that you are describing as "our systems".
> nuetral arbiter (ideally something like an online jury of ones peers, but who don't know you) take a quick glance at the photo, determine it's your kids in the bathtub and not CSAM, and click "It's Fine".
Wait, wait, wait. So the response to finding suspected CSAM would be to make a copy of it, then to deliver that copy TO OTHER PEOPLE OVER THE INTERNET!? Every single study about Facebook's CSAM reviewers shows it to be an emotionally damaging job, because you're constantly shown psychologically damaging material. With that in mind, who do you think would volunteer to be on such a review board?
> We would subscribe to updates to a CSAM scanning corpus
This introduces an unnecessary failure mode to devices whose core functionality does not require internet access. If I have a digital camera, a tv, or a picture frame, those fundamentally do not require internet access. Given the prevalence of targeted advertising and surveillance of customers, any device requesting internet access should be viewed with immediate suspicion.
> The whole thing requires "trusting the client" but I bet there are ways to make it work
There aren't. There really, really aren't. You can only trust computers that you control, or that are controlled by people that you trust. Trying to implement these leads to obscenities such as the Clipper Chip, Sony's rootkit, ring-0 DRM, and so on. Every single one takes control of the computer away from the owner and gives it to somebody else.
> defuse this movement toward total black box checking of content
Your suggestions would require implementing a black box checking of content, running on my computer, and not under my control. Calling it "voluntary" in the sales pitch makes it useless, because the person who controls the computer can disable any reports from it.
> presumes that the intersection of child porn consumers and users sophisticated enough to disable a scan like the one I'm imagining is very small
The size of the intersection doesn't matter, because only a single person needs to write a script that disables the scan. In addition, if a scan requires sophistication to disable, that implies that it is an opt-in scan, and that goes against your sales pitch as "voluntary".