My understanding is in the USA companies like Apple cannot be legally obligated to ensure that iCloud does not store CSAM. Something about the US Constitution, but I can't remember what. Apple is legally obligated to report CSAM if they come across it themselves though.
This appears to be the case in Europe as well. But may not always be that way. The EU appears to be working on legislation that can compel cloud providers to scan for CSAM: https://9to5mac.com/2022/05/11/apples-csam-troubles-may-be-b...
Welcome sources on this from others. Last time I dug into this was a year ago.