"We can’t allow IoT vendors to pass off all such liability to the consumer": Investigating the U.S. Legal Perspectives on Liability for IoT Product Security

Prianka Mandal, Amit Seal Ami, Iria Giuffrida, Daniel Shin, Ella Sullivan, Adwait NadkarniWilliam & Mary

IEEE Symposium on Security and Privacy 2025 · Day 3 · Embedded and Wireless Security

Overview

The proliferation of Internet of Things (IoT) devices has introduced unprecedented convenience into daily life, yet it has simultaneously opened a Pandora's Box of security vulnerabilities. With billions of connected devices entering homes and critical infrastructure, the question of who bears responsibility when these devices are exploited—especially those that have undergone security certification—remains critically ambiguous. This talk, presented by Prianka Mandal and a collaborative team of security and law researchers from William & Mary, delves into the complex landscape of legal liability for IoT product security in the United States. It meticulously examines how IoT vendors attempt to contractually disclaim responsibility and contrasts these practices with the perspectives of legal experts.

Watch on YouTube

Visual summary for "We can’t allow IoT vendors to pass off all such liability to the consumer": Investigating the U.S. Legal Perspectives on Liability for IoT Product Security by Prianka Mandal, Amit Seal Ami, Iria Giuffrida, Daniel Shin, Ella Sullivan, Adwait NadkarniWilliam & Mary
Visual summary for "We can’t allow IoT vendors to pass off all such liability to the consumer": Investigating the U.S. Legal Perspectives on Liability for IoT Product Security by Prianka Mandal, Amit Seal Ami, Iria Giuffrida, Daniel Shin, Ella Sullivan, Adwait NadkarniWilliam & Mary

Key moments

  1. 0:00 Introduction: IoT product security liability problem
  2. 1:55 Research questions: vendor contracts and legal expert perspectives
  3. 3:00 Vendor contracts: disclaiming all liability, even illegally
  4. 3:45 Vendor contracts: ambiguous clauses, misleading product claims
  5. 4:15 Legal experts: vendors primarily liable, labs' liability conditional
  6. 4:50 Legal experts: US Cyber Trust Mark impact and success factors
  7. 5:45 Conclusion: significant gap, need clear IoT liability framework

"We can’t allow IoT vendors to pass off all such liability to the consumer": Investigating the U.S. Legal Perspectives on Liability for IoT Product Security

Speakers: Prianka Mandal, PhD Student, William & Mary; Amit Seal Ami; Iria Giuffrida; Daniel Shin; Ella Sullivan; Adwait Nadkarni

Conference: IEEE S&P

YouTube: https://www.youtube.com/watch?v=tlTYOXSIgb4

Overview

The proliferation of Internet of Things (IoT) devices has introduced unprecedented convenience into daily life, yet it has simultaneously opened a Pandora's Box of security vulnerabilities. With billions of connected devices entering homes and critical infrastructure, the question of who bears responsibility when these devices are exploited—especially those that have undergone security certification—remains critically ambiguous. This talk, presented by Prianka Mandal and a collaborative team of security and law researchers from William & Mary, delves into the complex landscape of legal liability for IoT product security in the United States. It meticulously examines how IoT vendors attempt to contractually disclaim responsibility and contrasts these practices with the perspectives of legal experts.

The research highlights a significant disconnect between the contractual language employed by vendors, which often seeks to absolve them of nearly all liability, and the prevailing legal opinion that places primary responsibility on the vendors themselves. This gap is not merely an academic concern; it has profound implications for consumer protection, vendor accountability, and the efficacy of emerging policy initiatives like the US Cyber Trust Mark for smart devices. By shedding light on the existing ambiguities and problematic contractual clauses, the work underscores an urgent need for a clear and comprehensive liability framework that can genuinely incentivize IoT vendors to prioritize robust security and privacy standards, thereby safeguarding consumers from harm and fostering trust in the burgeoning IoT ecosystem.

Background

▶ Watch: Introduction: IoT product security liability problem (0:00)

The rapid expansion of the Internet of Things has transformed nearly every facet of modern living, integrating smart devices into homes, vehicles, and critical infrastructure. This pervasive connectivity, while offering immense benefits, also presents an expansive attack surface for cyber threats. Despite growing public awareness and increasing regulatory focus on IoT security and privacy—exemplified by initiatives such as the FCC’s announcement of the US Cyber Trust Mark for smart devices—the security posture of many IoT products remains woefully inadequate. Vendors are increasingly encouraged to adopt higher security standards and seek product security certifications, often paying certification labs to assess and validate their devices.

However, prior research, including work by the presenting team, has revealed a troubling reality: even certified IoT products can harbor known and common vulnerabilities. This creates a false sense of security for consumers who, trusting in the certification mark, may erroneously believe a product is secure. When these vulnerabilities are exploited, leading to financial loss, data breaches, or even physical harm, the question of legal responsibility becomes paramount. Is it the vendor who designed and manufactured the device? The certification lab that assessed it? Or is the consumer left bearing the brunt of the damage? The current legal landscape in the U.S. offers little clarity, contributing to a lack of accountability within the IoT security certification infrastructure. This ambiguity not only undermines consumer trust but also removes a crucial incentive for vendors to invest adequately in security, as they can often disclaim liability through their terms of service. This talk directly addresses this critical void, investigating both the contractual realities and expert legal opinions to propose a path toward a more accountable future.

Key Findings

▶ Watch: Vendor contracts: disclaiming all liability, even illegally (3:00)

The research yielded 14 distinct findings, broadly categorized into insights from the user agreement analysis and the legal expert survey, revealing a stark contrast between vendor practices and legal perspectives on liability.

From the user agreement analysis, which examined 20 contractual documents from IoT vendors, several problematic patterns emerged:

  • Striking Liability Exclusion Clauses: Vendors routinely employ sweeping clauses designed to shield themselves from nearly all liability. Disturbingly, these exclusions often extend to areas not permitted under U.S. law, such as personal injury or death. This suggests an aggressive, potentially unenforceable, attempt to shift all risk to the consumer.
  • Contradictory Disclaimers for Security Products: A particularly egregious finding was that vendors of products explicitly designed for safety and security purposes (e.g., security cameras, door locks) included clauses stating their products were "not intended for safety and security purposes" and disclaiming responsibility for any damages caused by them. This directly contradicts the core function and marketing of such devices, creating significant ambiguity and consumer risk.
  • Vague and Ambiguous Language: Many clauses were found to be overly vague, leaving critical terms undefined. For instance, phrases like "inferior quality" for batteries were used without specifying objective criteria, making it impossible for users to understand their rights or the vendor's obligations. This ambiguity further complicates legal recourse for consumers.

The legal expert survey, conducted with 18 lawyers possessing diverse expertise, provided a contrasting and critical perspective:

  • Vendor Primary Liability: A consensus emerged among legal practitioners that IoT vendors are liable by default. This is because vendors are ultimately responsible for the design, implementation, and inherent security of their products. This directly contradicts the vendors' attempts to disclaim all liability in their user agreements.
  • Conditional Certification Lab Liability: The liability of certification labs was viewed as more nuanced and conditional. Experts indicated that a lab's liability would depend heavily on the specific contracts established between the lab and the vendor, as well as the nature of the vulnerability. A lab might be held liable if the vulnerability fell within the scope of the security standards they were contracted to assess and certify, implying a failure in their due diligence or assessment process.
  • Impact of the US Cyber Trust Mark: Participants identified three key factors determining the success of the US Cyber Trust Mark program: the quality of the certification process, the adoption rate by vendors, and consumer knowledge about the certification's meaning and limitations. While the mark could positively impact overall product security, experts also cautioned that simply adhering to specific guidelines might leave a significant number of vulnerabilities unaddressed, creating another form of false security.

In essence, the research highlights a critical liability gap: while vendors aggressively attempt to disclaim all responsibility through their contracts, legal experts firmly believe vendors bear primary liability. This disconnect, coupled with the unclear definition of liability within the broader certification ecosystem, underscores a pressing need for a clear, enforceable liability framework to drive genuine security improvements in the IoT market.

Technical Deep Dive

▶ Watch: Vendor contracts: ambiguous clauses, misleading product claims (3:45)

While this talk delves into legal and policy analysis rather than traditional software engineering or network protocols, the "technical deep dive" here refers to the rigorous methodologies employed by the interdisciplinary team to systematically investigate the complex legal landscape of IoT liability. The research was guided by two core questions: how IoT vendors describe liability in their contracts, and what legal experts perceive as appropriate liability.

To address the first research question concerning vendor contractual descriptions of liability, the team performed a user agreement analysis. This involved collecting 20 contractual documents from 20 distinct IoT vendors. The selection criteria for these vendors and their products, though not explicitly detailed in the brief overview, would typically involve a diverse range of device types (e.g., smart home, health, security) to ensure representativeness of the broader IoT market. The analysis itself was a qualitative content analysis, a robust methodology often used in social sciences and legal research to systematically interpret textual data. This process involved a collaborative effort between security researchers and legal scholars, which is crucial for interpreting both the technical implications of security clauses and their legal enforceability.

The core of this qualitative analysis was the creation of a codebook. This codebook was developed iteratively, drawing upon established legal theories of liability (e.g., product liability, contract law, negligence) and an understanding of the current liability landscape in the context of emerging technologies. The codebook would have defined specific categories and themes for analysis, such as:

  • Exclusion of Liability Clauses: Identifying explicit statements where vendors attempt to disclaim responsibility for various types of harm (e.g., direct, indirect, consequential damages, personal injury, property damage).
  • Disclaimer of Warranties: Analyzing clauses that limit or disclaim implied or express warranties (e.g., fitness for a particular purpose, merchantability).
  • Limitation of Remedies: Examining provisions that restrict the types or amounts of compensation available to users.
  • Indemnification Clauses: Identifying clauses where users might be required to indemnify the vendor.
  • Specific Exclusions: Noting any product-specific disclaimers, such as those for "safety and security purposes" in the context of security devices.
  • Ambiguity and Vagueness: Coding for instances where language was unclear, undefined, or open to multiple interpretations.

Through this detailed coding process, the researchers systematically identified recurring patterns and specific examples of problematic clauses. For instance, the finding that vendors disclaim liability for "personal injury or death that are not even permitted under US law" highlights a critical legal misstep or an aggressive attempt to deter claims, irrespective of enforceability. The observation of ambiguity in clauses, such as those referring to "inferior quality" without objective metrics, points to a deliberate or inadvertent strategy to create legal loopholes. The analysis meticulously documented these "striking clauses" and their potential implications for consumer protection and vendor accountability.

To address the second research question, which explored legal expert perspectives on liability, the team conducted a legal expert survey. This involved surveying 18 lawyers with diverse fields of expertise, ensuring a broad range of legal opinions were captured. The diversity in expertise is critical, as different areas of law (e.g., consumer law, product liability, intellectual property, contract law, cybersecurity law) might offer varying interpretations of IoT liability. The survey likely consisted of structured questions designed to elicit opinions on:

  • Primary Responsible Parties: Who, in their professional opinion, should bear primary responsibility for security vulnerabilities in IoT products?
  • Factors Influencing Liability: What specific factors would influence the attribution of liability (e.g., severity of vulnerability, vendor's due diligence, user's actions, certification status)?
  • Role of Certification Labs: How should the liability of certification labs be determined, considering their contractual relationships with vendors and the scope of their assessments?
  • Impact of Policy Initiatives: Their views on the potential effects and necessary conditions for success of programs like the US Cyber Trust Mark.

The survey findings revealed a strong consensus among legal experts that IoT vendors bear primary liability due to their control over product design and security implementation. This expert opinion directly contrasts with the prevalent contractual disclaimers. Furthermore, the nuanced perspective on certification lab liability—dependent on contractual agreements with vendors and the specific scope of vulnerabilities covered by standards—underscores the complexity of establishing accountability in a multi-party ecosystem. The experts' insights into the US Cyber Trust Mark, particularly the emphasis on the quality of certification and consumer knowledge, provide critical feedback for policymakers.

In sum, the "technical deep dive" into this research is about the systematic, interdisciplinary application of qualitative research methodologies to dissect complex legal documents and expert opinions, thereby revealing critical gaps and proposing pathways for improved accountability in the rapidly evolving IoT security landscape. The rigor of combining legal and security expertise in both data collection and analysis ensures that the findings are robust and actionable.

Demo / Proof of Concept

▶ Watch: Legal experts: US Cyber Trust Mark impact and success factors (4:50)

This talk focused on a legal and policy analysis of liability within the IoT security ecosystem, rather than the exploitation of technical vulnerabilities or the demonstration of security tools. Therefore, no live demo or proof of concept was presented as part of this research. The findings were derived from the qualitative analysis of vendor user agreements and a survey of legal experts.

Defensive Implications

▶ Watch: Conclusion: significant gap, need clear IoT liability framework (5:45)

The findings from this investigation into IoT product security liability carry significant implications for various stakeholders, necessitating a multi-pronged defensive strategy. The current landscape, characterized by vendor disclaimers and legal ambiguities, demands proactive measures from consumers, vendors, regulators, and certification bodies alike.

For Consumers:

  • Skepticism Towards Certifications: While programs like the US Cyber Trust Mark aim to improve security, consumers should maintain a healthy skepticism. A certification mark does not guarantee absolute security, nor does it necessarily clarify liability in the event of a breach. Consumers must understand the limitations of such programs.
  • Scrutinize User Agreements: Although often lengthy and complex, consumers should be aware that many contractual clauses in End User License Agreements (EULAs) or Terms of Service (ToS) are designed to broadly disclaim vendor liability, potentially even for severe harms. While some of these disclaimers may not hold up in court, they reflect the vendor's intent to shift risk.
  • Advocate for Stronger Protections: Consumers should support legislative and regulatory efforts aimed at establishing clear liability frameworks for IoT products, ensuring that vendors are held accountable for security failures.

For IoT Vendors:

  • Re-evaluate Contractual Practices: Vendors must critically review their user agreements. Broad disclaimers for all liability, especially for personal injury or death, may be unenforceable under U.S. law and can significantly damage consumer trust. Instead, contracts should clearly define responsibilities without attempting to absolve the vendor of fundamental duties, particularly for products marketed for safety.
  • Embrace Proactive Security: The legal expert consensus that vendors are primarily liable by default should serve as a strong incentive. Investing in security-by-design principles, robust vulnerability management programs, and transparent communication about security practices is not just good practice but a potential legal imperative. This means going beyond minimal compliance with certification guidelines to address a broader spectrum of potential vulnerabilities.
  • Transparent Communication: If a product is genuinely not intended for safety-critical applications, this should be communicated clearly and consistently, rather than embedding contradictory disclaimers within the terms for products like security cameras.
  • Collaborate with Regulators: Engage constructively with policymakers to develop clear, fair, and enforceable liability frameworks that provide both consumer protection and predictable operating environments for businesses.

For Regulators and Policymakers (e.g., FCC, FTC):

  • Develop Clear Liability Frameworks: The most critical defensive implication is the urgent need for a comprehensive and unambiguous legal framework for IoT product security liability. This framework should explicitly define the responsibilities of vendors, certification labs, and other stakeholders, ensuring accountability.
  • Strengthen Certification Programs: For initiatives like the US Cyber Trust Mark to be truly effective, the quality of the certification process must be rigorously maintained. This includes ensuring that standards are comprehensive, assessments are thorough, and that the mark genuinely signifies a high level of security, not just minimal compliance that leaves significant vulnerabilities unaddressed.
  • Educate Consumers: Alongside certifying products, agencies should invest in educating consumers about what these certifications mean, their limitations, and what responsibilities still fall on the user. This helps manage expectations and prevents a false sense of security.
  • Enforce Against Misleading Claims: Regulators should actively monitor and take action against vendors whose contractual disclaimers are legally unenforceable or whose marketing contradicts their product's stated purpose or security capabilities.

For Certification Labs:

  • Define Scope of Liability Clearly: Certification labs need to establish clear, legally sound contracts with vendors that explicitly define the scope of their assessment and, crucially, the limits and conditions of their own liability. This includes specifying which standards are being tested against and what types of vulnerabilities are within scope.
  • Ensure Robust Assessment: To mitigate their own potential liability, labs must ensure their assessment processes are thorough and align with the highest industry standards, covering known and common vulnerabilities relevant to the certified product.
  • Transparency in Standards: Be transparent about the standards being applied and their limitations, both to vendors and, where appropriate, to the public, to avoid contributing to a false sense of security.

In conclusion, the current environment where IoT vendors attempt to disclaim all liability while legal experts consider them primarily responsible is unsustainable. A robust defensive posture requires a concerted effort to close this liability gap through improved contractual practices, proactive security investments, and, most importantly, the establishment of clear and enforceable legal frameworks that align responsibility with the ability to secure these ubiquitous devices.

Key Takeaways

  • Significant Liability Gap: There is a critical disconnect between IoT vendors' contractual attempts to disclaim all liability and legal experts' consensus that vendors are primarily responsible for product security.
  • Problematic Vendor Contracts: IoT user agreements frequently contain "striking clauses" that attempt to exclude liability even for personal injury or death (often unenforceable) and include vague language or contradictory disclaimers for products explicitly marketed for security.
  • Vendor Primary Responsibility: Legal practitioners overwhelmingly believe that IoT vendors hold primary liability for security vulnerabilities, as they design and implement the product's security features.
  • Conditional Lab Liability: Certification labs' liability is nuanced, depending on their contracts with vendors and whether a vulnerability falls within the scope of the standards they were contracted to assess.
  • US Cyber Trust Mark Challenges: The success of initiatives like the US Cyber Trust Mark hinges on the quality of the certification process, vendor adoption, and consumer understanding, with risks of unaddressed vulnerabilities if only minimum guidelines are met.
  • Urgent Need for Clear Framework: A clear, comprehensive liability framework is essential to incentivize IoT vendors to prioritize security and privacy, ensure accountability, and protect consumers from harm.

About the Speaker(s)

The primary presenter for this talk was Prianka Mandal, a PhD student at William & Mary. This research was a collaborative endeavor conducted between security and law researchers, specifically from William & Mary. The full team included Amit Seal Ami, Iria Giuffrida, Daniel Shin, Ella Sullivan, and Adwait Nadkarni, indicating a strong interdisciplinary approach combining expertise in cybersecurity and legal studies. Their joint effort highlights the necessity of bridging the gap between technical security challenges and their complex legal implications in the rapidly evolving landscape of IoT.

All talks from IEEE Symposium on Security and Privacy 2025