Well it depends on your topology and how you are doing change of auth.... Are you switching VLANS or are you applying different roles to guests? Anyway, I wonder if DHCP is coming through the control tunnel because of your config, or you need to change VLANs and the tunnel is down so I don't think that can happen. I am also assuming you are bridging at the AP and have the option set to continue servicing clients in absence of controller...
Oh, that also doesn't mean allow new authenticated sessions. Maybe if it's an open network with no auth or redirects, but if there are any authentication attempts, I could see newly connecting clients failing to gain connectivity / IP address etc.. I could be crazy as it is past my bedtime.