Hi, yes, they will not be compliant. Intune does not lower automatically the value setup by you or check the latest available versions to each phone. It is a baseline defined by you.
If you know based on current reports which users have such devices, create secondary compliance policy with lower value and target this to such users. And from the first policy make a exclusion.