This is why there are regulatory bodies and people's entire career devoted to this. The government can create regulatory bodies to answer these questions and then regulate companies.
I don’t think saying it’s someone else’s problem to sweat the details cuts it. It sounds too much to me like wanting to wave a magic wand to make the problem go away, but there is no magic wand. Never, in any of the debates I’ve had on this, any of the blog posts a I’ve read about it, even the EFF articles about this (and organisation I have enormous respect for), has anyone actually tackled this issue of saying how a law like this would work in any specific way and what devices it should or should not apply to, specifically.