For reference, the change that rolled out is #2857. Adding a passkey no longer turns it into a second factor. Passkeys work as a way to sign in without a password, and using one as two-factor authentication is a separate opt-in: the "Require a passkey as your second factor" toggle in the Passkeys section of your security settings.
Accounts that had a passkey registered before this change kept it switched on, so nobody's security was quietly lowered. If you added a passkey without meaning to use it as 2FA, sign in on the device that has it (or with a backup code) and turn that toggle off. After that, email and password works on any device again.
Thread
Comment by Hampus