That's already required if you want to sell the device in the EU (or EEA?) at all. So far, Motorola hasn't left the market with their low-end devices so I presume they intend to deliver on the updates
The secure element can be on the same CPU die as Apple does with the SEP but a device with only TrustZone wouldn't meet the requirements. It also needs to be a high quality implementation providing the expected features.