It can be done right: local only connections (no cloud), segmented vlan for iot devices with strict firewall rules, Internet access blocked for anything that doesn’t need it, etc.
Unfortunately that takes a lot of knowledge and effort. The cloud based devices that phone home every few minutes are preconfigured and just work, so most people will just use that and not think about it.
Me: Surely they left their brights on accidentally flashes my brights to alert them
Them: turns on actual brights blinding me for the next 30 seconds