I don't get it - why can't the "right holder" who wants a site blocked drag Cloudflare itself to the court over this, just like ISP's are asked to do the blocking now?
This may get interesting in the corporate world where firewalls such as PAN and Fortigates are expected to block unwanted domains. Some companies also filter on internal DNS but may have to start blocking or intercepting MiTM DoH or just outright blocking the DNS "HTTPS" requests which is one documented way to disable ECH. [1]
[1] - https://learn.microsoft.com/en-us/windows-server/networking/...