tl;dr: the world is messy, automations and remote control by vendors has shown to be the only working method vs. individual responsibility/organisational responsibility, and the law isn't against that (at least not in the EU so far).
Longer wall of opinion:
There isn't, mainly because that would cut both ways: you'd get the same constructions as budget airlines where the core product would seem to be what you want, but everything becomes a paid add-on.
Right now it's an embedded cost or hidden cost, and there is no service fee. For companies like Apple that can work because the products as sold as a single SKU while that hasn't worked for others (and they tried!) like Windows + Hardware, Android + Hardware etc. It never worked out because the ongoing cost and service requirements aren't something the consumer is willing to pay for separately and the vendor can't eat that cost because they don't sell it as a single product with a single business case.
Technically we could go to a model where this actually gets done:
- Hardware and Software is separate
- Support and Services are separate
- Features are paid for separately
The problem with this is the same as it was 50 years ago: all users will now need to know a lot of things in-depth for realistic use of such compositions. And people just do not care, and do not want to spend time, energy or other forms of effort/resources on such things.
There is a small subset of a niche of a fraction of the market that does want (some of) it, but it nearly never covers the cost to the extent where you get everything you want (i.e. Framework; Fairphone, you get modules and software you can almost self-compile, but the NDAs around MRC, ME, PHYs and GPUs makes it impossible to really do all feature and functionality control yourself).
The same applies to computers and software if you treat them as a black box but are interconnecting them, you now get dependencies, network effects and "your problem is everyones problem". This means that if not enough participants play by the same rules to a high enough degree, the system doesn't work at all and everyone feels that pain. Even things like MTA-TLS, basic PKI, or even basic hygiene like not operating an open relay or open proxy is a bar 'professionals' are unable to consistently pass... We need protections from ourselves and each other (in terms of hosts) and the last few decades have shown that individual responsibility and corporate policy are not working out.
Ideally, if someone really wants this, they would be doing this by not accepting an EULA that has automations they don't want, and go back to first principles where they do have that control, but without attestation they would not be allowed to participate in shared systems (like the internet).
To make further discussion easier, we could make a simple base case like "the OS used to support exFAT but after this automated patch it no longer does". Perhaps the license expired, perhaps it was vulnerable to a zero touch exploit and the cost was too high to fix it and the impact on the brand was too high to leave it in. Not sure what other reasonings we could come up with, but there are similar things related to RSR, MRT and the likes were existing functionality might be impacted in some way shape or form.