There's a fundamental problem here, and I don't know how it should be addressed. I agree that manufacturers should be able to silently patch firmware for security holes. But I decidedly do not want them silently adding, removing, or changing functionality. I find this practice absolutely infuriating, and it's a big reason why I abhor the current IoT ecosystem. Sometimes I get busy and don't have time to read a change…
I think Android things is built around this idea, with manufacturers having no control on security updates.
For simple, standalone features, this could work well. But when your features are dependent on interacting in some way with other people's connected products, this might not work.