It's far easier and less risky to update, not to mention roll back, code on servers than it is on embedded devices. If you break the updater on a server, you can SSH in to fix it "manually" get a tech to replace the machine. If you break the updater (or WiFi driver, or bootloader, or...) on embedded devices in the field, you're up Product Recall Creek without a paddle.
In practice, this means that many companies prefer the less-risky approach which still lets them iterate rapidly on feature development, and fix bugs in production without weeks of QA.