>I understand all site traffic now routes via Secure Connect.
If you are talking about Meraki AnyConnect support using the SecureConnect client, you can you use split tunnel mode, so only traffic for Azure network (and branches if you like) will go over the VPN.
https://documentation.meraki.com/MX/Client_VPN/AnyConnect_on_the_MX_Appliance
(you can search for "split" in the above page).
>Will we have to change anything on the vMX-M appliances?
You'll need to configure AnyConnect, and make sure TCP and UDP 443 are forwarded to the VMX.
>Do the vMX have to change to Routed mode?
No.
>Will the vMX appliances now be seen as a spoke?
Not really.
>What sort of latency will be introduced on top of the current latency seen in the AutoVPN config?
Pretty much nothing.
>Does the Essentials licensing
I would normally use AnyConnect APEX licences. A sample ordering code is L-AC-APX-3Y-S1. This is for a 3 year licence. I usually use 3Y or 5Y to match the Meraki licences, so everything comes up for renewal at the same time.