That limit is only for a certain Yubikey model, not for all hardware-based fido2 authenticators.
> upload their keychains to ms/apple/etc clouds where they can be requested by any gov under the sun for x reasons.
If a HSM module (TPM, Apple/Android Secure Enclave) is used the private key is impossible to extract (and upload to a cloud) anyways