Yes any document you migrate to the new tenant should first be decrypted otherwise disruption will occur when accessing that content in the future.
For example: - when the user's identity is migrated from the source tenant to the target tenant, for example, the UPN suffix (@domain.com) then the users won't be able to authenticate to open the AIP encrypted data - if the source tenant is ever decommissioned then the AIP content will be unreadable. - Probably several other scenarios too numerous to mention.
The Auto-Label policy doesn't have any setting of automatically removing encryption from all documents that it has applied to. This means if a user has downloaded a document to their local hard drive then you won't be able to decrypt that document.