Hey Johnny,
It looks like the behaviour of the content filter action Encrypt and Deliver now falls as per your findings, on the PXE encryption settings defined at GUI > Security Services > Cisco Ironport Email Encryption.
The TLS, while it's TLS -- as the action of the filter is basing off the PXE encryption settings, you would need to increase the limit of the PXE encryption to match the size you would like to allow (Note: 20MB is the limit)
Whereas to use the global mail limits, it would be to disregard the filter and use the destination controls for TLS requirement and there will be essentially no limit for the delivery from ESA side if it was allowed through at the HAT level (ICID).
Regards,
Matthew