What about EU's CRA?
If you still sell EOL Products, you have to make sure it is still save, even as distributor.
Take control away from the end-user is a good point, I will keep this in mind.
I think the CRA is the right step in the right direction. Companies can finally be fined when they sell a product that has known vulnerabilities.
This is something that is discussed for years - now we have a definite Law.
And we already see changes: if you install Windows, the first thing it does is to get patches and the start over.