The AllowExtraction option was introduced late in 1.4 ( but had not been forward ported to 2.0, nor ever been added to the feature requirements list of 2.x. Hence it was overlooked.
It instructs to -upon generation of a key- to explicitly add a special option to the HSM to instruct the HSM that this key may be extracted. It has no other implications for OpenDNSSEC.