Canada has a different approach, where institutions can sign up to using a federal DNS service provided through the domain registrar, which I interpret is not unlike 1.1.1.1 or 9.9.9.9, but with malware detection. I believe it's called Canadian Shield, and it's not active scanning, but rather passive collection from institutions that manage infrastructure.
Active scans by government seems a bit like domestic intelligence collection. Given the techincal capabilities of most of these agencies when they work with ISPs, hairpinning traffic from one of these scanned servers for inspection is trivial. Fine if the threat model involved exceptional cases with clear oversight, and individual decision accountability in response to ticking bomb situations, but the examples of how similar powers have been used in the past are so abundant that I'm having trouble remembering a situation where they were used to protect a mere citizen.