Your point is more about subnets and less about VLANs. You can have firewall rules that restrict entire subnets from access the Internet; you don't have to define a rule for each device. VLANs just give you assurance that a device can't just change its subnet to your main one and gain access that way. Realistically, there wouldn't be any IoT device that would do this. But I agree if you can do VLANs, you should do them over basic subnets.