I didn't read too deeply but I bet the drivetime failures were because the issue manifested after the vehicle started operating. A rolling FOTA update seems like it would not be certified and would be harder to implement anyway.
This would also mean the A/B failover would need to identify the problem as a bad update rather than a bug that pops up minutes later.
Obviously no vehicle should be updated while in operation and all patches should be signed.