Blog · Review Essay · Modified August 12, 2026 · Last reviewed August 12, 2026

The Internet in Everything and the Control Network

Laura DeNardis's The Internet in Everything: Freedom and Security in a World with No Off Switch is a governance book about connectivity becoming part of cars, homes, medical devices, factories, energy systems, toys, cameras, and bodies. Its current value is concrete: an AI model cannot be governed in isolation when accounts, clouds, operators, and devices turn its output into a physical or institutional consequence.

For this review, a control network is a sociotechnical chain that senses a condition, represents it as data, applies an inference or rule, assigns authority, and changes a material option. Actuation may be direct, as when a command changes a machine state, or mediated, as when an alert, score, queue, or dashboard causes a person or institution to act. Control requires neither a robot arm nor a conscious machine; it requires a path from representation to consequential change.

The practical test is the actuation boundary: the strongest action the assembled system can reach, how quickly and widely harm could travel, whether the action is reversible, who authorized it, what local or degraded mode survives network failure, and how an affected person can challenge both the triggering record and the resulting action.

The Book

The Internet in Everything was published by Yale University Press in 2020. The Yale listing gives the hardcover at 288 pages, with print ISBN 9780300233070 and ebook ISBN 9780300249330. Oxford Academic's Yale Scholarship Online record places the book in public policy and summarizes its central claim: the diffusion of internet connectivity into physical systems escalates governance problems around privacy, discrimination, safety, democracy, and national security.

The chapter arc moves from cyber-physical disruption through privacy, security, interoperability, freedom, global governance, and policy. That sequence matters. DeNardis is not writing a gadget catalog. She is showing how technical architecture allocates exposure, authority, and responsibility before a public controversy receives a political name.

The author is an internet-governance scholar whose work has long focused on technical arrangements that decide public outcomes. Yale identified her at publication as a professor in American University's School of Communication. Georgetown now lists her as Professor and Endowed Chair in Technology, Ethics, and Society and director of its Center for Digital Ethics. The book sits in that tradition: begin with infrastructure because politics is already operating through it.

Current Context

As of August 12, 2026, cyber-physical governance is a patchwork of standards, labels, guidance, procurement rules, and binding sector or product law. NIST IR 8259r1, finalized in April 2026, recommends manufacturer activities spanning pre-market design and post-market support through end of life. Crucially, it defines the IoT product as more than the visible device: necessary backends, companion applications, and gateways belong to the product boundary. NIST SP 800-213 addresses federal acquisition and system risk from the device perspective, while ETSI EN 303 645 V3.1.3 supplies a consumer-IoT security baseline. None is a general warranty of privacy, functional safety, or legitimate use.

The U.S. Cyber Trust Mark illustrates the difference between a baseline and a remedy. The FCC's establishing order makes the program voluntary and initially limits it to eligible wireless consumer IoT products; it excludes categories including FDA-regulated medical devices, motor vehicles, enterprise products, and wired devices. The order provides for post-market surveillance but declines to create a broad liability safe harbor. A mark can communicate conformity to a cybersecurity baseline without proving that a deployment is safe, private, fair, or appropriate.

The UK's Product Security and Telecommunications Infrastructure regime has applied to covered consumer connectable products since April 29, 2024, with compliance, stop, recall, forfeiture, and monetary-penalty powers. Enforcement matters as much as enactment: in its 2024–2025 delivery report, the Office for Product Safety and Standards said that 75% of 82 connected devices it assessed showed varying levels of non-compliance. That is an official enforcement snapshot, not a prevalence estimate for every UK product, but it shows why a rule on paper cannot substitute for market surveillance and correction.

The EU Cyber Resilience Act entered into force on December 10, 2024. The Commission's July 27, 2026 practical guidance addresses scope, remote data processing, substantial modification, support periods, risk assessment, and reporting. As of this review date, reporting obligations are scheduled to apply from September 11, 2026 and the main obligations from December 11, 2027. FDA's February 2026 medical-device cybersecurity guidance is different again: it gives nonbinding recommendations on design, labeling, and premarket documentation, addresses section 524B of the Federal Food, Drug, and Cosmetic Act for cyber devices, and supersedes the June 2025 version.

NIST's April 2026 concept note for a trustworthy-AI-in-critical-infrastructure profile makes the AI layer explicit across information technology, operational technology, and industrial control systems. The project remains ongoing; a concept note is not a completed profile or certification. Its significance here is narrower: when AI-enabled capability enters critical infrastructure, the model, product components, network conditions, operator, and actuator must be evaluated as one deployed control path.

The most important update is therefore lifecycle and dependency governance. A connected product is not finished at sale or installation. Its continued operation depends on patch delivery, certificates and credentials, vulnerability handling, cloud and identity services, component replacement, support notices, repair channels, export, and retirement. An abandoned device can remain a sensor, actuator, dependency, or attack surface long after its vendor has moved on.

From Communication to Control

The book's strongest move is to show the control path shortening. The screen-based internet always had physical consequences through money, work, policing, reputation, and logistics. Cyber-physical systems add transducers: sensors bring material conditions into the network, and actuators let networked commands alter them without a separate human translation step. The distinction is not “virtual harm” versus “real harm.” It is the speed, proximity, scale, and reversibility of the path from signal to consequence.

That shift changes what governance means. A moderation mistake on a social platform can ruin reputations, distort public knowledge, or incite harm. A failure in a connected medical, mobility, or infrastructure system can injure bodies directly. A compromised camera network, traffic system, building control, or industrial device can become a surveillance layer, attack surface, labor monitor, or coercive instrument.

This is why “no off switch” should be read as a governance problem, not a literal engineering prescription. Connected systems are embedded in rented apartments, workplaces, schools, streets, cars, hospitals, warehouses, and municipal infrastructure. A person may be unable to exit them, while abruptly switching off a medical, transport, or utility system may itself create danger. The real requirement is controlled termination: isolation, local authority, a tested degraded mode, safe shutdown where appropriate, and continuity for people who depend on the service.

A control network has a lifecycle: sensing, inference, decision, authorization, actuation, logging, review, update, and retirement. Each transition needs a named owner and a contestable rule. Who may collect the signal? What converts it into an inference? Who decides that a threshold has been crossed? Who can push a firmware change? What happens when the network, vendor account, certificate, cloud service, or model fails? DeNardis's argument becomes sharper when treated as a chain of institutional decisions rather than a general mood about connectivity.

That lifecycle also shows why "control" should be read concretely rather than conspiratorially. A connected meter can change billing, a badge reader can change access, a camera can change policing, a fleet tracker can change labor discipline, and a health device can change clinical workflow. The network controls by making some options easier, more visible, faster, cheaper, or mandatory, and by making other options harder to notice or justify.

The governance unit is therefore not “the device” alone. It is the system of device, firmware, gateway, companion app, cloud service, account, vendor, integrator, data recipient, operator, and affected person. NIST's current product boundary supports this system view: if removing a backend or other component breaks intended functionality, that component belongs in the product analysis. A smart lock with a landlord dashboard is a housing-governance system; a warehouse scanner with productivity analytics is a labor-governance system; a medical sensor with a cloud dependency is a care-governance system. The device is only the visible endpoint.

The Body as Endpoint

DeNardis's examples matter because they move the internet from the abstract public sphere into ordinary vulnerability. Wearables turn bodies into data emitters. Cardiac monitors and medical devices bring network security into care. Smart homes make domestic space visible to vendors, police requests, landlords, abusers, and compromised accounts. Connected cars and drones make mobility and surveillance part of the same technical field.

The LSE Review of Books account emphasizes this loss of a clean boundary between virtual and physical life. That is the hinge for AI governance. A system that classifies text is different from one that classifies a pedestrian, redirects a vehicle, adjusts a medication workflow, flags a worker, unlocks a door, or routes an emergency response. The question is no longer only whether a model knows. It is what the connected environment lets that model do.

This also changes the meaning of legibility. Networked devices do not merely observe. They format reality into machine-actionable traces: location, movement, temperature, pressure, images, heart rhythms, proximity, voice, payment, presence, energy use, and machine state. Once the world is captured this way, institutions can score it, automate it, insure it, police it, price it, deny it, optimize it, or claim it as evidence.

That makes safety inseparable from power. A device attached to a body, a factory line, a vehicle, or a utility is not just an app with worse consequences. It is a dependency that can become unavailable, misconfigured, remotely changed, or interpreted against the person who relies on it. The relevant question is not whether the device is innovative. It is whether the person exposed to it has notice, alternatives, repair, support, redress, and a way to survive its failure.

The body-as-endpoint frame also changes incident severity. A breach is not only stolen data when it changes an insulin workflow, unlocks a door, exposes an abuse survivor's location, disables a vehicle feature, or causes a caregiver to trust a false alert. Cybersecurity becomes bodily safety when the network can alter conditions of care, shelter, movement, and work.

Privacy Gets Physical

The privacy chapter title is exactly right: privacy gets physical. In a browser, privacy harm can already be serious, but the object being tracked is often a profile. In cyber-physical systems, the profile is joined to rooms, bodies, vehicles, tools, workplaces, and neighborhoods. The record is no longer only about what someone read or clicked. It can include where they slept, how they moved, when they opened the door, how fast they drove, which shelf they scanned, what machine they touched, or whether a device inferred distress.

Consent breaks down under those conditions. A visitor does not meaningfully consent to every microphone, camera, sensor, router, badge reader, and smart appliance in a room. A worker does not freely bargain with every wearable, fleet tracker, warehouse scanner, or productivity sensor when employment depends on compliance. A tenant does not control every connected lock or utility sensor. A patient may have no practical alternative to networked care infrastructure.

The International Journal of Communication review identifies the book's productive tension: cyber-physical systems can create real benefits while also creating privacy, security, and human-safety risks. The answer is not categorical rejection. It is to stop pretending individual choice can govern infrastructure that surrounds workers, tenants, patients, students, visitors, and passersby before they can evaluate it. Data collected for care, maintenance, safety, or access should not quietly become input for discipline, pricing, advertising, policing, or denial. Purpose limitation and data minimization must govern the full data path, not only the device interface.

A useful privacy review therefore asks about bystanders and secondary subjects, not only registered users. A doorbell camera records neighbors and passersby; a classroom sensor records children who did not choose the contract; a fleet tracker records passengers and locations; a smart speaker records visitors. Cyber-physical privacy is often imposed by someone else's device.

Security does not settle that question. A device may encrypt data correctly, authenticate every command, and resist compromise while collecting more than its purpose warrants or sending records to an actor who should not have them. Conversely, privacy-preserving collection does not prove that an actuator is safe. Cybersecurity, privacy, safety, availability, and legitimate authority are related claims that require separate evidence.

Standards as Politics

One reason the book belongs beside media theory and platform governance is its attention to interoperability. Technical standards can sound neutral until they decide who can connect, inspect, repair, or exit; which vendor controls an ecosystem; and which assumptions travel across devices. In the cyber-physical world, compatibility is not merely a convenience feature. It allocates switching costs, update authority, and the power to declare a component trusted.

Closed systems can make people dependent on one vendor for devices that mediate safety, mobility, home life, or work. Open systems can improve repair and competition, but can also enlarge attack surfaces if governance is weak. Fragmentation can limit systemic failure, but it can also trap users in incompatible silos. There is no purely technical answer because every architecture distributes power differently.

This is the institutional lesson: technical governance becomes constitutional before most publics notice. Naming protocols, standards bodies, certification regimes, update policies, security disclosures, procurement rules, and liability arrangements is not boring housekeeping. It is how control over connected reality is allocated. A procurement clause about patch support, a requirement for vulnerability disclosure, or a rule against universal default passwords can matter more than a public slogan about innovation.

The hard cases are not solved by choosing “open” or “closed” once. They require governance at the boundary: documented interfaces, authenticated and recoverable updates, least-privilege defaults, repair and exit rights, vulnerability handling, support commitments, and public capacity to evaluate systems vendors describe as proprietary. An interoperability claim says components can communicate; it does not prove secure implementation, safe behavior, continued vendor support, or a fair policy for access. That is the same institutional problem discussed in vendor and platform governance and digital infrastructure.

Attestation belongs in that boundary politics. A device may need to prove software state or hardware integrity before joining a network, but an integrity proof is not a blanket license to act on people. The claim should stay narrow: what was attested, by whom, under which policy, for which action, and with what fallback when the proof is missing or wrong. Otherwise the trust layer becomes another private gate over public life.

The AI Reading

Read in 2026, The Internet in Everything supplies a missing unit of AI governance: the action path. Deployed systems use accounts, APIs, sensors, databases, permissions, payment rails, cameras, browsers, devices, operators, and institutional workflows. Model evaluation matters, but it does not reveal what credentials the assembled system holds, which commands it may issue, or which downstream users will treat its output as evidence.

This changes the risk analysis. An unsupported generated answer behind a read-only interface is one failure. The same output routed into a medical workflow, building system, police queue, vehicle interface, industrial controller, or benefits record has a different time to harm and recovery burden. The relevant chain is source, inference, authority, command, observed result, and correction. An error becomes materially dangerous through the permissions and dependencies around it, not through fluency alone.

The recursive loop is straightforward. Sensors make the world legible. Models interpret the legible world. Institutions act through the interpretation. Those actions reshape behavior and infrastructure. The changed world produces new sensor records, which then appear to confirm the system's model of reality. A smart city, warehouse, hospital, school, or border checkpoint can become a feedback machine long before anyone calls it artificial intelligence.

This is also why AI safety cannot be reduced to model alignment or benchmark performance. It includes permissions, failover, logging, redress, physical safety, procurement, labor-process design, vendor dependence, incident disclosure, repair, and the ability to preserve essential service when automation is withdrawn. The site's AI in cybersecurity page treats this as an attack-surface problem; the cybernetics review treats it as a participation-and-authority problem. DeNardis shows why the two are joined at the actuator.

The agent layer adds a specific hazard: tool permissions can turn observation into action. A browser agent, building-management assistant, logistics optimizer, care-coordination bot, or maintenance planner should therefore be governed like a delegated operator. It needs bounded authority, evidence logs, human override, tested failure modes, and a clear distinction between recommendation, queueing, remote actuation, and final institutional decision. That connects this review to AI browsers and computer use, embodied AI and robotics, agent tool permissions, and agent observability.

The minimum AI safety distinction is observe, infer, recommend, queue, command, and execute. Procurement and audit files should name the highest action level the assembled system can reach, whether it acts directly or through a person, its credential and network scope, the maximum plausible blast radius, and the recovery window. “Decision support” is not a low-risk category when a ranked queue predictably controls attention or a generated note becomes an official record.

Governance and Safety

Governance starts by naming the object. A thermostat, insulin pump, camera, warehouse scanner, emergency-alert system, traffic sensor, public-benefits portal, fleet tracker, robot, and medical workflow are not one risk class. Each differs by data sensitivity, actuator power, network exposure, support lifetime, user choice, affected population, and available remedy.

Those differences decide which controls matter most. NIST and CISA guidance can shape procurement and professional expectations, but they are not general consumer statutes. ETSI is a standard. The FCC mark is voluntary. The UK and EU regimes create legal duties in their jurisdictions. FDA guidance is specific to medical-device submissions and resilience. "There is a standard" is therefore not the same thing as "a harmed person has an enforceable remedy."

It is equally important to keep assurance claims separate. Cybersecurity asks whether unauthorized parties can compromise confidentiality, integrity, or availability. Functional safety asks whether the system stays within acceptable bounds during faults, misuse, and foreseeable operating conditions, including authenticated but wrong commands. Privacy asks whether collection, inference, sharing, and retention are justified. Governance asks who has legitimate authority, who bears error, and who can obtain correction. Evidence for one claim cannot be silently reused as proof of the others.

The practical controls are concrete. A connected deployment needs an asset inventory, an accountable owner, data-flow maps, a support end date, secure update mechanisms, no universal default passwords, vulnerability disclosure, logging, incident reporting, network segmentation, least-privilege access, local safe modes, manual override, repair and export rights, and a plan for what happens when the vendor, cloud service, or model output is unavailable. In hospitals, schools, public benefits, workplaces, policing, housing, elder care, transport, and utilities, it also needs notice, appeal, human review, and a public record of serious failures.

For AI systems attached to sensors and actuators, the bar should be higher still. Tool access should be explicit and narrow. Consequential actions need tested authority boundaries, per-action permissions, simulation or staged evidence where relevant, an independent interlock for hazards that software alone should not control, rollback where the action is reversible, controlled stop and safe-state procedures where it is not, provenance logs, and post-incident review. Human approval helps only when the reviewer has time, evidence, competence, and actual authority to refuse. “Smart” should never mean that a vendor can silently change the behavior of a dependency people cannot safely leave.

A control-network dossier should exist before deployment in high-impact settings. It should identify the sensor and actuator inventory, model or automation role, account owners, vendors and subcontractors, data flows, retention rules, update authority, support end date, emergency contact, local fallback, manual override, vulnerability-disclosure channel, incident log, accessibility impact, bystander impact, and appeal path. Without that dossier, the institution has bought a dependency it cannot govern.

Public-sector and essential-service deployments need a stronger public record. A school, hospital, benefits office, transit agency, utility, housing provider, jail, or emergency-management office should be able to say which connected systems make or influence consequential decisions, which failures have occurred, what changed after incidents, and how affected people can reach a human route when the device, network, vendor, or model is wrong.

The Actuation Boundary Dossier

The governance artifact this review takes from DeNardis is an actuation-boundary dossier. It should describe, in one place, the highest level of real-world action a connected system can reach: observe, infer, recommend, queue, command, execute, lock, unlock, move, dose, bill, deny, disclose, or write an official record. For that maximum action it should state latency, reversibility, physical or institutional blast radius, rate limits, prerequisite credentials, and the person or mechanism with stopping authority. The boundary should be written before procurement, not discovered during an incident.

The dossier should separate four claims that are often blurred. A security claim says whether the device can resist compromise. A privacy claim says what data is collected, retained, inferred, shared, or deleted. A safety claim says what happens when the device, network, model, or cloud service fails. A governance claim says who may authorize, override, repair, appeal, retire, or publicly account for the system. Passing one category does not satisfy the others.

For AI-enabled control networks, the dossier needs an action receipt for consequential events: sensor source and time; model, rule, and policy version; input and retrieved evidence; output; human reviewer where present; authorization check; tool call; actuator command and acknowledgment; observed result; local safe-state check; affected person; notice; override; and correction route. The receipt must distinguish what the system observed, inferred, proposed, commanded, and confirmed. Otherwise a successful API call can be mistaken for a safe real-world outcome.

The dossier also forces a hard refusal question. If the system cannot preserve an essential service during a vendor-cloud outage, cannot authenticate or patch safely through its declared support period, cannot preserve necessary logs without over-collecting bystander data, cannot be isolated or controlled by trained local staff, or cannot reconstruct why a consequential action occurred, it should not enter that essential service until the boundary is redesigned.

Where the Book Needs Friction

The book is strongest at the infrastructure and governance layer, which means readers should pair it with accounts of labor, race, disability, housing, policing, and environmental extraction. Connected infrastructure does not touch everyone in the same way. A smart thermostat in an owner-occupied home, a surveillance camera in public housing, a delivery scanner in a warehouse, a GPS ankle monitor, and a networked medical device all raise different questions of power and exit.

It also predates widespread deployment of generative and tool-using AI. That is not a defect, but it means the reader has to extend rather than attribute: DeNardis supplies the networked control environment; this review adds generated interpretation, automated summarization, and delegated tool action. The book should not be cited as if it had evaluated systems released after publication.

Finally, the book can make the cyber-physical shift feel nearly inevitable. A little resistance is useful. Connected devices are often sold as convenience before they become dependency. Procurement, standards, right-to-repair law, public alternatives, security requirements, and refusal can still shape what gets connected and on whose terms. So can environmental accounting: every "smart" object also has materials, energy use, update labor, repair constraints, and end-of-life waste.

The strongest limit is scope. DeNardis gives the governance architecture, not a full account of every domain where connected systems land. A workplace scanner, medical device, smart toy, home camera, farm sensor, border technology, connected car, and grid controller all require domain-specific safety and rights analysis. "Internet of Things" is too broad for remedy; the remedy has to name the setting.

What This Changes

The practical lesson is to audit the physical internet before adding automated inference or delegated action. Ask what a connected system can sense, infer, record, and change; who controls its credentials and updates; who can inspect the evidence path; what survives loss of network, cloud, identity, or vendor support; and how a harmed person can correct the record and reverse the consequence where reversal is possible.

For institutions, the book reframes AI deployment as cyber-physical governance. A model inserted into transport, medicine, housing, policing, logistics, education, elder care, utilities, or workplace management is not just software. It is a decision layer attached to material dependency.

The implementation habit is simple: draw the control path before approving the feature. Signal, inference, rule, authority, command, actuator, observed result, record, override, repair, appeal, retirement. If any link is ownerless, invisible, or vendor-only, the system is not ready for a high-impact setting.

This connects the site's recurring themes through mechanism rather than analogy. Smartness makes continuous sensing and optimization feel like default public capacity. Cybernetic governance asks whether affected people can change the loop rather than merely feed it. Managed information systems show that queues, reports, and records can actuate institutions without moving a machine. DeNardis joins the sequence at its material boundary: the same information loop can now change access, movement, care, work, and infrastructure state.

The Internet in Everything therefore changes the default question from “is this device smart?” to “what control network, dependency, and authority structure does this product join?” A read-only text system and a model with credentials to alter a device or official record present different hazards. The latter needs bounded authority, an inspectable action trail, tested degraded operation, local stopping capacity, and a public account of who is permitted to touch the world through the network.

Source Discipline

This review separates four kinds of evidence: book metadata from the publisher and scholarly catalog; reception and criticism from review essays; current author context from Georgetown; and governance claims from standards bodies, regulators, official guidance, and legal text. A review can interpret DeNardis's argument, but it cannot establish the current status or scope of a rule, certification program, enforcement power, or implementation date.

Claims about a connected system should name the device class, connectivity, data recipient, actuator authority, support lifetime, jurisdiction, and enforcement instrument. Marketing language like "smart," "AI-powered," or "secure" is not evidence by itself. Nor is the existence of a standard proof that a person affected by a device can obtain repair, appeal, damages, or a safe alternative.

The sources also distinguish a recommendation, a standard, a voluntary label, binding product law, enforcement practice, and sector-specific guidance. NIST and CISA recommend practices; ETSI specifies a standard; the FCC mark is voluntary and category-limited; UK PSTI and the EU Cyber Resilience Act impose duties within their scopes and application schedules; FDA guidance contains nonbinding recommendations within a statutory device regime. Collapsing those layers makes governance look stronger and more uniform than it is.

The UK non-compliance figure is reported as OPSS's result for 82 assessed devices, not generalized to the whole market. The EU reporting date is described as scheduled because August 12 precedes September 11, 2026. The NIST critical-infrastructure profile is described as an ongoing project, not a finished assurance standard. The actuation boundary, claim separation, and action receipt are this review's synthesis rather than language attributed to the 2020 book.

Current claims were rechecked on August 12, 2026. IoT labels, implementation guidance, application dates, standards, and sector rules can change faster than the book's durable infrastructure argument; official sources and applicable counsel should be checked again before procurement, compliance, or safety decisions.

This review does not claim that AI systems are conscious, divine, or artificial general intelligence. The narrower claim is enough: once networked devices can sense and change the material environment, AI governance must cover the infrastructure through which model outputs become actions.

Sources

Book links are paid affiliate links. As an Amazon Associate I earn from qualifying purchases.


Return to Blog · Return to Books