From now onwards you are able to configure a default encryption for OBS buckets on a per bucket level. When default encryption is enabled all objects uploaded to the corresponding bucket will automatically be encrypted with the defined KMS Key. You can either configure this at the initial creation of a bucket or later on within the bucket configuration. When you change (enable/disable) the default encryption setting after creation of the bucket, the change will not touch existing objects already stored in the bucket.
More information about the behavior can be found in the documentation https://docs.otc.t-systems.com/en-us/usermanual/obs/obs_03_0321.html of the OBS.