Makes sense. If they were to update something in their auth protocol or need to patch a security issue most people wouldn't have the tech chops to update firmware.
How does this change anything? You can accept the update, or just let it will stop working with their network. And how is the new update any different in terms of trust than the initial carrier-specific update the modem gets when you activate?