Browsing through Google Account settings, it looks like anything they think is a logged-in phone is automatically treated as a valid 2FA source for your account regardless of whether you wanted it to be.
This is not just unwanted 2FA but a huge security violation. It means a lost or stolen phone logged into your account, or one a child is using, etc., can be used as a full account takeover vector.