California Governor has signed a bill that would require “reasonable security” for all new IoT devices, making California the first state with an IoT law
Adi Robertson / The Verge :
Context & Ripple Effects
This closes a two-year legislative arc: after senators proposed requiring patchable, password-hygiene-compliant devices for government buyers in a 2017 procurement bill, California extended the idea to every consumer IoT device sold statewide, with the bill clearing the legislature earlier this month before the governor's signature made it the first state IoT security law.
It also lands mid-scramble over California's broader tech-regulation agenda — lawmakers had been racing to pass a privacy bill ahead of a possible ballot initiative (the June deadline fight) — and it set the template the state later reused for AI, from SB 53's safety-disclosure mandate to chatbot rules.
First-order effects
- Device makers shipping any new connected product into California must now build in 'reasonable' security features by default, since the law applies at point of sale rather than to government procurement only.
Second-order effects
- Rather than segment the US market, most manufacturers will likely apply one security baseline nationwide, effectively exporting California's standard to all fifty states without other legislatures acting.
Third-order effects
- If the pattern holds, California's first-mover role hardens into structural rule-setting for emerging tech — the same first-in-the-nation logic that produced this IoT law reappears in the state's 2025 AI safety and chatbot statutes — pushing national policy debates toward whether Congress preempts or codifies the state's defaults.
The trend: California is consolidating its role as the de facto national regulator of connected technology, moving from IoT device security in 2018 to AI disclosure and chatbot rules by 2025.