They might theoretically be on the hook for damages they introduce, but in reality, there's already a ton of services running on every device that can compromise you if the infrastructure behind it is hacked. EVGA wouldn't even be a worthwhile target.
And, as mentioned above, NVidia already has the necessary infrastructure in place. So the effective cost for doing this would be close to zero.
> which might not even work, given that hackers are really good at bypassing DRM solutions anyway.
Hackers are, yes. But the price you fetch for a card will go down massively if you need high technical skills to run it.