You bought it. You own it. But you might not be allowed to fix it.
Here's a situation most Indian tech users will immediately recognize: your laptop breaks down, you take it to an authorized service center, they quote you ₹12,000 for a repair that a local shop could do for ₹3,000, and they tell you that using an unauthorized repair shop will void your warranty. You pay the ₹12,000 because you have no real choice.
That's the world that right-to-repair laws are trying to fix. And in the US state of Colorado, they've been doing it more aggressively than anywhere else. Since 2022, Colorado has passed laws giving people the right to repair their own powered wheelchairs, agricultural equipment, and consumer electronics. Real rights — legally enforceable access to tools, spare parts, repair documentation, and software diagnostics that manufacturers have to provide.
Now, Cisco and IBM are lobbying to carve a massive hole in those protections. And the story of how they're doing it tells you everything about how this fight plays out every time — and why India needs to be paying close attention.
What Colorado's right-to-repair law actually does
Colorado's Consumer Right to Repair Digital Electronic Equipment Act was passed in 2024 and came into full effect in January 2026. It's the most comprehensive repair rights law in the United States.
Under this law, manufacturers of consumer electronics — phones, laptops, televisions, household appliances, HVAC systems, servers, routers, IT equipment — must provide consumers and independent repair shops with the tools, software, replacement parts, and documentation needed to diagnose, maintain, and repair covered devices. The law also explicitly bans "parts pairing" — a practice where manufacturers use software to lock components to a specific device, so that a genuine replacement part from the same manufacturer won't work properly unless the manufacturer's own software authorizes it.
Parts pairing is worth understanding because it's been one of the sneakiest anti-repair tactics in the industry. Apple was notorious for this — replacing a genuine Apple screen on an iPhone with another genuine Apple screen would trigger warning messages and disable Face ID unless Apple's authorized system approved the swap. Samsung has done similar things. The Colorado law bans that practice entirely for covered devices.
Danny Katz, executive director of CoPIRG — Colorado's consumer advocacy group — put it simply: "Colorado has the broadest repair rights in the country. We should be proud of leading the way."
SB26-090 — the exemption bill that would gut everything
Here's where it gets frustrating. A new bill has just moved out of the Colorado Senate Business, Labor, and Technology committee — unanimously, which means it now goes to a full senate and house vote. The bill is called SB26-090, and its official title is "Exempt Critical Infrastructure from Right to Repair."
The bill modifies Colorado's right-to-repair law to exempt "information technology equipment that is intended for use in critical infrastructure" from the repair rights the 2024 law established. Cisco and IBM are listed in lobbying disclosures as supporters of this exemption bill.
On the surface, "critical infrastructure" sounds reasonable. You don't want random people tinkering with hospital servers or power grid control systems. That's a legitimate concern.
The problem is how broadly the bill defines both "information technology equipment" and "critical infrastructure." Repair advocates — including PIRG, the Repair Association, and iFixit — say the definitions are so wide that they could cover ordinary enterprise hardware: office servers, corporate routers, workplace computers. Basically, any device that a company like Cisco or IBM manufactures and sells to business customers could potentially qualify as "critical infrastructure IT equipment" under the bill's language.
If that interpretation holds, the exemption doesn't just protect hospital servers. It exempts the majority of Cisco and IBM's product lineup from Colorado's repair law entirely — handing back to the manufacturers exactly the control over repairs, parts, tools, and software that the 2024 law took away from them.
The cybersecurity argument — and why repair advocates say it's a red herring
Cisco and IBM's stated justification is cybersecurity. IBM's spokesperson said the company "supports right-to-repair policies that empower consumers while protecting cybersecurity, intellectual property, and critical infrastructure" and argued that "enterprise-level products" should be treated differently from consumer devices. The argument is that giving independent repair technicians access to diagnostic tools and firmware could also give bad actors a way to exploit those same access points.
This is a standard playbook argument from manufacturers opposing right-to-repair — and repair advocates have been countering it for years. The core rebuttal: repair access and security are separate problems that can be solved separately. You can give a trained independent technician the tools to replace a failed hard drive in a server without simultaneously handing them the keys to the entire network. Repair documentation doesn't have to include network security credentials. Parts availability doesn't compromise encryption.
What actually creates security vulnerabilities is the opposite scenario: when a critical piece of infrastructure breaks down and the only authorized repair technician is weeks away or costs ten times what a local independent shop would charge. Systems stay offline longer. Workarounds get implemented. Desperate IT teams do things they wouldn't normally do. Security through repairability is a real concept — and the manufacturers conveniently never mention it.
The iFixit and Repair Association opposition to SB26-090 makes the same point: the bill as written doesn't actually solve a security problem. It solves a revenue problem for Cisco and IBM by making their products exempt from repair laws that protect customers.
Why this matters for India — right now
India doesn't have a right-to-repair law yet. What it has is a Right to Repair portal launched by the government in 2022, which is a voluntary framework — manufacturers can list repair information if they choose to. It's not legally enforceable. There's no requirement to provide diagnostic software to independent shops, no ban on parts pairing, no obligation to make spare parts available at reasonable prices.
The practical result is the situation every Indian device owner knows well. iPhone repairs at unauthorized shops that trigger software warnings. Laptop manufacturers refusing to sell replacement batteries to independent repair shops. Printer manufacturers using chip-controlled ink cartridges that refuse to work even when ink remains. Washing machine companies that charge more for a service visit than the device is worth because spare parts aren't publicly available.
India's Ministry of Consumer Affairs has been discussing right-to-repair legislation seriously since 2022. The Colorado model — before the Cisco/IBM exemption attempt — is exactly the kind of framework Indian policymakers should be studying. Comprehensive coverage across electronics categories, explicit ban on parts pairing, enforceable obligations for manufacturers to provide tools and documentation to independent repairers.
The Colorado exemption fight is also a preview of exactly what will happen if India passes a strong right-to-repair law. The same companies — Cisco, IBM, Apple, Samsung, whatever manufacturer has the most to lose — will immediately start lobbying for "critical infrastructure" or "enterprise" or "security" carve-outs that hollow out the law before it takes effect. Knowing that playbook in advance is useful.
The repair economy India is missing out on
India has hundreds of thousands of independent device repair shops — phone repair stalls in every market, laptop repair shops in every tech bazaar from Lamington Road in Mumbai to SP Road in Bengaluru. These businesses employ millions of people and serve a population that cannot afford manufacturer service center prices.
Without right-to-repair protections, these shops operate in a legal grey zone and are increasingly squeezed by software locks, parts unavailability, and manufacturer restrictions. A strong right-to-repair law would formalize and protect the independent repair economy India already has, while also making devices cheaper to maintain for the hundreds of millions of Indians who buy mid-range phones and laptops and then use them for five or six years.
The Colorado fight is about whether the US keeps the repair rights it just won. India's fight is about whether it ever gets them in the first place. Both are worth watching.
TamilTech's take
Cisco and IBM's SB26-090 lobbying is exactly what you'd expect from companies that make more money when you can't fix your own stuff. The "cybersecurity" argument sounds serious but doesn't hold up to scrutiny — it's a familiar tactic dressed up in technical language. Colorado's lawmakers should reject the exemption bill and keep their repair law intact. For India, the lesson is: if and when right-to-repair legislation finally arrives, watch carefully for exactly this kind of industry-backed carve-out that shows up quietly after the big headline law passes. The loophole is always in the fine print.




Comments (0)
Be the first to comment!