Re: Encrypt the endpoints!
The decrypting, and then the routing would be inside the "safe zone". After that, anyone checking the metadata for individual routes would be doing so outside the transatlantic cable anyway.
Think of the "cable" only being used as one big VPN between the carriers sites either side of the link.