Presumably you would only do this for images you plan on sharing to social media anyways, to prove that it's not AI generated.

PCC is quite good, about as close to private remote compute we can get without doing HME.

If homomorphic encryption is not involved, how does Apple not have access to the raw image data being sent to PCC? (Genuine question)

It's something like SGX, which they pinky promise isn't breakable, even though intel stopped supporting SGX because it was too breakable.

It would be incorrect to presume that.