I find it amazing that TETRA, which post-dates GSM would leave authentication and Encryption as optional components.
What were those goofy ETSI people thinking?
I believe at the time the first TETRA networks and terminals were being installed/delivered the manufacturers were not able to implement authentication and air-interface encryption (AIE) right away (and GSM encryption was probably not deemed suitable to fullfil the stringent requirements for PSS organizations).
Even later, when authentication was available, encryption wasn't necessarily available, too - or encryption was only available based on common, static keys (AIE Class 2).
Now the major vendors support AIE Class 3, the highest class that uses individual & dynamic keys.
That said IMO not all TETRA networks require AIE, e.g. small commercial networks or certain sectors like transportation may have no use for it, so it may acutally make sense to specify it as an option since it keeps cost down.
But those that demand AIE, like public safety and security organisations, can have it if they want.