I don't want to go out and blatantly state that Apple lied about the "only icloud photos" thing but I am can only assume that they would scan on-device so that way that all modern devices are scanned regularly for CSAM. Otherwise, the nasty people that actually have such content would simply need to disable icloud photos to get around the new policy shift.Still doesn't answer why this method and on device. No other company does this.
With that said, at this point, I would treat anything that you have on your phone as information that may not be private from this point on. It might be a paranoid approach but given the circumstances and how privacy has seemingly been thrown out when it comes to all tech, nothing would surprise me.
Apple scans our phones, Google scans our phones, history, location, and other things, Microsoft scans our PCs, our TVs serve us Ads now and monitors what we watch to serve more ads(SmartTV).