(a) to prove identity -- a digital signature (b) to provide confidentiality -- encryption
If the secret part of an asymmetric key is generated on a device and it lives and dies on that device, Apple doesn't have it -- the device does. Messages encrypted using the public part of that key can only be decrypted with a device that has the key.
Your augment regarding PKI encryption systems is flawed. You don't need or care about a "root authority" to provide confidentiality. If your assertion is/was true, how can or does PGP work? (Hint: signing only affects identification and authenticity of a message)