Android has no system-wide content blocking APIs. Furthermore, Google's policy specifically states that VPNs may not "Manipulate ads that can impact apps monetization", proving that this is not about VPNs, but about ad blocking in general.
My solution is a WireGuard VPN to my home network (which is behind PiHole) but a local solution cannot properly block network requests without the VPN API.
Blokada has switched to doing DNS-based blocking through DNS but that's purely to get around Google's arbitrary restrictions on the VPN API.
Users should be able to use whatever network filters they like. If I don't want to send ICMP packets, or DNS packets for certain servers, or any other kind of specific traffic, I should have control over what my device is doing.
Note that the VPN API does not necessitate actually setting up a VPN to a cloud server. The VPN API exposes packets to an Android app so it can decide whether or not to forward the packet, rewrite it, send it through a tunnel, etc. Normally, there is no cloud service when VPN ad blockers are in use. Blokada has switched to a cloud system but only after Google blocked their normal system.
Until Google releases a comprehensive network filter driver API or firewall API there is simply no alternative. The Blokada local DNS server solves one problem (the need for a VPN) but cannot prevent ad libraries from using DoH to work around content blockers.