I didn't read too deeply but I bet the drivetime failures were because the issue manifested after the vehicle started operating. A rolling FOTA update seems like it would not be certified and would be harder to implement anyway.
This would also mean the A/B failover would need to identify the problem as a bad update rather than a bug that pops up minutes later.
Obviously, "software update while traveling at highway speeds" is just rolling too many drama dice.
OTA is fine. Ideally parked, or minimally A/B on the firmware, new version only run on next startup.