ISPs generally are able to pinpoint the originator of the traffic, ie. for a given connection 3-/5-tuple provide information on the originating customer, their physical address, contract data, etc.
This is the tradeoff when registering an ISP in the jurisdictions I'm familiar with: you are immune to legal action concerning the data that is carried over your network (ie. you won't get raided for a customer sending death threats), but in return you must cooperate with the authorities and provide data on your offending customers. You must do whatever is necessary to be able to provide this data upon a subpoena: from assigning static IP addresses / CGNAT port ranges to customers, to logging every NAT translation from your roaming mobile network.
Source/background: operating an ISP in Poland.