I consider that to be a deal-breaker. Hardware fails/lost/stolen, and I need to know that I have an offline backup somewhere if disaster strikes.
Are you currently sharing one keypair for all your devices?
If I use ten services registered with my private key, and the single authenticated hardware device goes poof (dies/lost/stolen) -is there an out of band mechanism for me to regain access on a new device? Maybe for some, but possibly not all.
An offsite backup means that if everything goes down Monday, I can be back in business on Tuesday without fear.
You could replicate some of this assurance with redundant hardware devices, but that requires perfect diligence in ensuring you have multiple devices approved to each service. AWS only just recently allowed multiple hardware tokens.
For me to register the backup-only key with other services, it would have to live on my machine, and be simultaneously registered in addition to the primary key. I am not sure what I am gaining vs having a backup of the primary key other than increased operational burden.
But yeah, if the main device is stolen, it can be a pain to go update all the services with the new device’s key.
I personally use the gpg app on my youbikey for this, and the secret key comes from a backup I install on a livecd.
However, that very quickly gets into the problem of untested backups. I am then relying completely upon a private key which has never been validated to work.
Might be appropriate to store keys in Secure Enclave for some but a dedicated TPM (Yubikey/Nitrokey/Trezor/Ledger/etc) is often preferred. Some might want or need backups.
And even then, having multiple implementations widely used is preferred over having everyone relying on the same small group of volunteers or corporate working on any single one.