You're right, it could be a passive inspection. But... if they are your ISP and have access to your packets, chances are they can rewrite and inject traffic too. Sure, they might need a bit more hardware to do so, but it's not exactly difficult.
But you're correct, DPI doesn't necessarily imply MITM capabilities.
But you're correct, DPI doesn't necessarily imply MITM capabilities.