Perhaps they should store such things on hardened secured servers in NSA data-centers (yes, related) instead of Google servers unless the plan is to integrate the CSAM into Google. Otherwise generate the signatures on hardened infrastructure that Google employees do not have access to and then share the signatures with all the hosting providers. (Checksums, Microsoft PhotoDNA, etc...)
This was labelled a dupe by HN but where is the original and why does it link to age-verify?
https://www.justice.gov/epstein/files/DataSet%209/EFTA001735...