We manage bug bounties for a bunch of different startups, and I can count on zero fingers the number of times I've had to use PGP in the past year for that. In practice, people just send bugs with plain 'ol email.
So I think the result of removing PGP will be even more plain 'ol email than anything else.
We also got super clever reports on that same bounty program. They just sent email.
Hmm I don't see it as theater if you are unable to intercept and decrypt my message. Or forge my signature, etc.