I've had my settings updated via remote access. In my case it appears a non-Apple company/person was successfully overriding my settings, primarily by exploiting WebKit vulnerabilities. Sometimes I could see it, and sometimes I could not (e.g., I received a notification and/or I saw the setting change vs. blind override without any toggling/notification but logs showed it).
In my case I filed a report with Apple, on multiple occasions. I also made lots of copies of that data, and stored in different places (i.e., 3-2-1).
Good ol' United (Surveillance) State(s) of America.
Yes, I was informed by Apple Support that this was a maintenance issue. That doesn't satisfy me. The entire premise of Advanced Data Protection hinges on the promise that it only your devices can access your data. If this setting can be disabled remotely (be it malicious or not), that is obviously concerning.