That's a better way to install things, but it's not the only way that installation is done, and it's still excessive to need the internet for what could easily be a purely local operation. For device classes where "on/off" has historically been attached to the device itself (washer, stove, ...), it's more common than in the lightbulb case for the internet connection to be mandatory.
Pushing closer to tin-foil hat territory, when your lights can be controlled over the internet by servers you don't own, that operator can do nearly whatever they'd like. A common pattern in other industries (ocean navigation apps, OB2 monitors, ...) is to require a server for no good reason, sell a device at full market value, and then later extort the customer into some sort of subscription/data-leak to continue using their own devices. It's common for the remote server to just shut down (startup goes out of business, manufacturer decides it'd be nice if you bought a new device, ...). Less likely but worse if it happened, the server operator _could_ trigger epilectic seizures or whatever.