Besides being available now, I would also like to know this.
One idea I'm thinking about is whether as a bearer instrument it is possible to "relieve" oneself of the cash, for it to be passed around as "money" without having to use the mint to destroy/issue it. I can, of course, sign it to you with your pubkey, but that doesn't prevent me from cashing it at the mint (it only prevents others from doing so). I can use the mint to redeem and reissue it to you, but then we're still using the mint. So it would require me to "prove" I've never opened an encrypted thing, without the help of the mint (and offline, for that matter).
Maybe another use case is a temporary ID inside a virtual environment. You pay to "enter" and get a token to use inside that environment. Cound be porn, gambling, games, while giving you privacy.
Or it could be something to make you honest or civil in a particular environment, like a bond.
It's also easy to federate, so it may be better than lightning for quorum decisions or voting, with anonymity.
I think it may come down to being used as coinjoin-type obfuscation, or in another way to evade antiquated regulations or bypass legal technicalities.