Check out the case of storage encryption in smartwatches and very cheap phones. The CPUs do not have AES instructions and doing software AES makes the watch noticeably sluggish. https://lwn.net/ml/linux-crypto/20180806223300.113891-1-ebig...
Personally, if I'm ok with the encryption being breakable, I'm also ok with not using any encryption at all. I can't imagine a scenario where I would want weak encryption.
Anyway, the way to solve that problem is to get a CPU with AES instructions.