That's not a conundrum at all. Permissionlessness dictates that both are true: you can't force anyone to use their coins in a particular way, and it also dictates you can't *stop* people using their coins in a particular way.
Forced upgrades to security are a valid way of doing this if users don't have an expectation of autonomy. Bitcoin users do, and must, have that expectation.
No auto-updates.
Also, rational economic interest dictates against your proposal, because it destroys bitcoin's value.
