In the other hand, if Apple suddenly found out that a good chunk of encrypted volumes weren’t actually encrypted / the key was recoverable by an offline attacker, this would also explain the facts.
But the lack of explanation from Apple is troubling.
And what command line tool are you referencing?
On iOS or macOS? Was a consent dialog presented before the update was installed?
Afterwards I wondered if it was just storing the recovery key I already had in iCloud or if it had generated a new recovery key and my saved one was invalid.
I checked my recovery key ("sudo fdesetup validaterecovery") and it was no longer valid. A bit of Googling failed to turn up a way to get a copy of the recovery key that was in iCloud, and I decided I'd rather have a recovery key I store myself in case I need to recover when I cannot get online so I switched it back.
Switching back is easy. You just turn off FileVault, then turn it back on and choose to manage the new recovery key yourself.