The AllowExtraction option was introduced late in 1.4 (https://github.com/opendnssec/opendnssec/commit/672d2c75ccd3cd5f2317bb76af4c9cc4e5aa4a37) but had not been forward ported to 2.0, nor ever been added to the feature requirements list of 2.x. Hence it was overlooked.
It instructs to -upon generation of a key- to explicitly add a special option to the HSM to instruct the HSM that this key may be extracted. It has no other implications for OpenDNSSEC.