They are scanning the images on your phone. They open the file, create a hash, and when that file is uploaded to iCloud, they flag it (if it was flagged on the device). If there are enough positive flags, then a human being will look at the content.They are not scanning iCloud. Not at all. This sort of false accusation is what the hubbub is about. People don’t understand how this system works.
I fully understand how this system works. I've created similar systems (though not for images, it was for data protection purposes to ensure data being exfiltrated out of the organization doesn't contain any known prohibited content).
Regardless, whether they are scanning images in iCloud or images on your phone matters little. They are scanning images. And if you use iCloud, it's likely your phone has the same exact images as your iCloud gallery, so there's no point in scanning iCloud.