Part of it is also a certification circus.
For example, with Copilot, you get a contractual pinky promise that they cannot access your data.
Can engineers really not access ? Can the police really not access ?
It's like AirTag for example. Apple cannot access it because it's scientifically "impossible" by design, but if they sign-in to your account, well it's over.
Once Apple fills the right audit / certification / paperwork they will be able to enable that feature. It could also be a negotiation lever.