Findings in the article aside, of course.
If the RIAA gets a court order to reveal who streamed something, shared illegally, etc. would they be able to comply?
Someone who can monitor all the entry points and exit points can probably tie the connection together, but someone in that position can probably also do that for any other vpn service (Nord, proton, etc - though those providers don't have any privacy options).
This whitelist is implemented using the regular macOS/iOS per-app firewall. Not only this is accessible to users, but the whitelist matches based on the Mach-O UUID, which is an arbitrary number put in by the linker...
The restriction on which apps can use iCloud Private Relay is trivially defeatable.
Private Relay hides your IP address and browsing activity in Safari and protects your unencrypted internet traffic so that no one-including Apple-can see both who you are and what sites you're visiting
They made it a few years ago they all apps had to use encryption. Long before private relay came out. I have wondered if this was why.