"(d) (1) ...that is not capable of being decrypted and unlocked by its manufacturer or its operating system provider shall not result in liability to the seller or lessor if the inability of the manufacturer and operating system provider to decrypt and unlock the smartphone is the result of actions taken by a person or entity other than the manufacturer, the operating system provider, the seller, or the lessor and those actions were unauthorized by the manufacturer, the operating system provider, the seller, or the lessor."
Presumably the "those actions were unauthorized" could be construed as prohibiting a FDE option from being built into the OS and provided by the manufacturer and this in conjunction with signed kernels in phones, would present a very high barrier on the user to be able to obtain device encryption without key escrow as we understand it today.