It makes any snooping on our network connections more complicated, isn’t it?
Enumerating/blacklisting the IPv6 address space is hard. IPv6 allows us to get as many addresses as needed, so SNI extensions turn useless. DOT/DOH and a TLS handshake encrypted since the first message do the rest. What caveats might appear?
Willing to block SNI-less connections are already doing this. Those, who chose not to adopt IPv6, will remain restricted to IPv4 for ten years or so. I suppose, decisions have been made. No ‘forensic’ will be surprised or scared :).