Being able to update roots is important. We can’t guarantee any particular future of our PKI.
Our Root X1 is widely trusted, so it is very likely that any future roots will be cross-signed by Root X1 until its expiry in 2035.
After that, I suspect the web PKI may start to look very different. We may not issue any future RSA roots, and transition entirely to ECDSA and/or post-quantum signing algorithms. We may not issue long-lived roots again at all, as there’s been a push to shorten root lifetimes and replace them more frequently.
If you have devices intended to be supported beyond 2035 that uses Let’s Encrypt, you must build in an update mechanism.