It's tied to a key stored in your iCloud. So basically as long as you have a device tied to your iCloud you can get in. Presumably, if you lose access to iCloud you will have problems.
My understanding is the QR code is used to establish a quick BLE connection. The phone then pretends to to be a simple FIDO2 key. After that things proceed like any other FIDO2 workflow.
interesting, but it still needs an iPhone> -- I was kind of burned hard when trying to migrate my iCloud keychain passwords to something else so I'm curious how smooth it actually is
Semantics aside, holding private keys hostage with no recourse is Orwellian. A for-profit company has no business being a centralized identity authority.