What the default actually is
Standard iCloud Photos encrypts your library in transit and at rest — with Apple holding the keys. That architecture is why icloud.com can show your photos in a browser and why account recovery can rescue a forgotten password. The same architecture means Apple’s systems can access content, and that lawful requests can too. This is a reasonable default for most people and most photos; it is not a private vault.
What Advanced Data Protection changes — and doesn’t
ADP moves Photos and most other iCloud categories to end-to-end encryption: keys live on your trusted devices, and Apple’s servers store what they cannot read. In exchange, you own recovery — via a recovery key or recovery contact — because nobody can reset what nobody else can open.
What ADP does not change: the devices. Every iPhone, iPad and Mac signed into the account still decrypts and displays the full library. End-to-end encryption protects against the server side; it says nothing about who is holding one of your screens.
The sync surface: devices, family, sharing
Most real-world exposure is not cryptographic. It is the signed-in iPad in the living room, the Mac that still has Photos in the dock, the shared family album that auto-suggests recent pictures, the Shared Library invitation accepted months ago. Each is working as designed; together they mean "my photos" quietly became "our screens".
The practical rule: a photo that must stay private should not live in the synced library at all. Encrypted, non-synced storage — with its own backup path that uploads only ciphertext — keeps the convenience of iCloud for the photos that are ordinary, and takes the sensitive ones out of the pool entirely.