Should not this be a default installable available in SQL Managed Instance?
Perhaps it should, but it currently is not. You can create a product feedback item here.
Here are some possible workarounds.
You could encrypt with key protected by a Database Master Key in a BYOK TDE encrypted database.
You could store a password in AKV and supply it from the application layer to open a symmetric key or certificate.
Please add to your feedback item enough information about your scenario to motivate the request. And also whether AlwaysEncrypted with Secure Enclaves would be a good fit for your scenario.