The idea is to make ECH too large of a target to make blocking it practical. If you block ECH you end up blocking access to a large portion of the internet in that region. It's why some major browsers have chosen to not gracefully fallback to non-ECH handshakes upon connection failure.
Greetings, residents of Arstotzka! To access Arstotzkan government websites, please install this Ministry of Digits TLS root certificate on all your devices. Also, all new phones sold in Arstotzka must have the certificate preinstalled, starting from 2025.
Freedom of information is an existential threat to authoritarian states. There is no amount of money they're not willing to give up if it mean they stay in power.
That's said, it will not come to that. They'll just mandate spyware installation.
Many such countries already block traffic with ECH entirely. There's no technical solutions to a polical problem.
I remember when you can just change your DNS provider to bypass censorship. Nowadays, browsers and OS provide safe DNS by default, and thus censors had mostly switched to DPI based method. As this cat and mouse game continue, inevitably these governments will mandate spyware on every machine.
These privacy enhancements invented by westerner only work for western citizens threat model.