It is not possible to migrate an existing single-region Cloud KMS key to a multi-regional configuration without creating a new key and re-encrypting the data. This is due to the security policies and the fixed regionality property of the keys. It is not explicitly mentioned in the docs, but somewhere in the creation process, there are detailed instructions about this.