Both quotes hold, and they're about different parties.

The BAA-attested key is Apple-facing. "Signatures that Apple can attribute to that specific phone" is what makes sensor-level revocation possible: images being "revoked and flagged retroactively, without revealing which images came from the same sensor."

The privacy bullet is observer-facing, and says so: "an outside observer cannot determine whether any pair of reference images were taken by the same device." A verifier gets no way to correlate two images.

So Apple holds an internal device handle for revocation, outside observers get none, and image contents aren't exposed to Apple either. Whether that handle stays constrained is a fair question, but the two statements aren't in conflict.