I think for any FDE, including FileVault, the disk encryption helps but there are many more potential avenues for attack if the system was not off when stolen. Those avenues include remote exploits on anything listening for incoming network traffic on the Mac and DMA attacks through Thunderbolt. I don't know what the current status is of exploits through physical ports on a Mac but they have existed in the past.
It's not just Mac users, I mentioned this issue in a meeting with an Apple sales engineer last month and he acted like you don't need to turn off a Mac to make it safer (he's not a security engineer so I don't really expect him to know how un/safe a running system with FileVault is). It may well be that the current OS and/or T2 chip makes it very, very hard to access the boot volume of a running Mac without a user's login but there's still a network exploit risk.
Plug in an Ethernet adapter or wake the computer around unencrypted WiFi (or encrypted WiFi but with a broadly shared password) with the same name as one the computer has used. In addition to direct attacks on anything listening for incoming network connections, I believe applications will keep running and using the network while the screen saver lock is enabled; it may be possible to inject an exploit in a server response to a request from a browser, an email client, etc. though the broad use of encryption at the application transport level makes that much less likely.
It's not just Mac users, I mentioned this issue in a meeting with an Apple sales engineer last month and he acted like you don't need to turn off a Mac to make it safer (he's not a security engineer so I don't really expect him to know how un/safe a running system with FileVault is). It may well be that the current OS and/or T2 chip makes it very, very hard to access the boot volume of a running Mac without a user's login but there's still a network exploit risk.