Consumers no longer own their physical products when those products adopt AI and internet connectivity. Those connected products also engender new cybersecurity risks. Smart products are first and foremost a cybersecurity risk to individual users, but also affect national security, as these products create a wide attack surface for nation-states to use for attacks and information gathering.
Connected devices are also a new challenge for ownership rights, as the features consumers are paying for are tied to a server controlled by the manufacturer. Consumers have no idea how long they can expect manufacturers to maintain or secure the features enabled by connectivity, nor do they understand the limits of these products when they purchase them as shown by the chart below.
Finally, these devices pose privacy risks as data about their inquiries, their habits and their lives get uploaded to companies that make no promises about how this data will be used or protected. At Consumer Reports we are concerned about the threat that software tethered devices pose to cybersecurity, ownership, and the environment.
As business invests in AI these products will become more common, and the data gathered from them could be used against consumers. For all of these reasons, Consumer Reports is focusing on the potential harms of software tethering and taking several steps to address the issue. In 2024 we called on the Federal Trade Commission asking the agency to issue clear guidelines for companies that use software to control and limit device functions after a consumer buys the device.
CR also released guidelines for manufacturers, regulators and technology standards bodies that would allow connected and AI products to operate securely even after the manufacturer stops providing support. We have also recently updated our model legislation that would address several harms associated with software tethering.
The Connected Device Longevity Act requires manufacturers of connected devices to tell consumers how long they plan to support them. It would address cybersecurity risks by requiring manufacturers of connected devices to tell consumers when they stop releasing security updates, and would require businesses such as ISPs and alarm companies to remove devices when they stop receiving security updates.
But there are other problems that are still unaddressed, so we have created the chart below to detail the harms associated with connected consumer devices and some proposals for addressing them. In some cases, using the FTC or state attorneys general to enforce existing UDAP and privacy laws would suffice. To address other harms we’d need to modernize the existing copyright law and develop new laws to protect consumer’s privacy and ability to resell a product.
We encourage consumers to call their state and federal legislators to ask for better laws and regulations associated with software tethered devices before we trade smart features for short-lived products.
| Tethering Harms | Example of Harms | Potential Fixes |
|---|---|---|
Cybersecurity Risks
|
|
|
Surveillance Risks
|
|
|
Loss of Core Functionality
|
|
|
Loss of Features
|
|
|
| Require payment for once-free features |
|
|
Features Change
|
|
|
Resale Risks
|
|
|
| Locking consumers into an ecosystem |
|
|