If you want to do "inspection" with TLS 1.3 you need to actually build the infrastructure these TLS specifications have always told you to use, rather than a cheap hack where too bad the users' security was destroyed but at least your "inspection" was cheaper.
What TLS 1.3 specifications for the required inspection infrastructure are you referring to?
1. Retain each agreed session key for so long as you might wish to "inspect" that encrypted session. Now there's a signifier you're retaining for the specific session, which makes legal or moral considerations concrete in a way they were not for a vague "inspection" capability that applies for some undefined period over all traffic. The encrypted traffic itself can be retained arbitrarily because without those keys it's worthless.
2. Proxy all the traffic and decrypt/ encrypt at the proxy so that you can make transcripts of the plain traffic live. Everybody understands what these plain transcripts are now, if you're storing them, if some people have access, what that exactly means is obvious.
What you're probably doing, which is much cheaper but is a hack, is to rely on RSA key agreement and then copy the RSA private key to an "inspection" tool which of course can then decrypt absolutely anything, forever. This is obviously a terrible idea even though it was cheaper, which is why it went away in TLS 1.3
What specifications are you talking about?
Probably these standard inspection techniques you refer to have been updated to take TLS 1.3 into account, especially since TLS 1.3 has been out for a long time. Would you please be so nice as to point us to the standard you were referring to ?
Assume your stance :)
Corporate MitM boxes are quite prevalent (they caused 5-10% of TLS 1.3 traffic to get dropped before they changed the protocol to fake TLS 1.2 session resumption) and when it comes to corporate-owned devices, that usually shouldn't pose too much of a privacy/security issue.
These setups were a lot easier back in the day when TLS let you set static keys, but you can still dump TLS key files and/or reject all non-proxied traffic with your MitM proxy if you want to do such a setup. It'll break loads of apps thanks to certificate pinning, but that's probably a good thing for such corporate networks.