Linux and other open-source operating systems will not be subject to California’s upcoming age-verification requirements after state lawmakers passed Assembly Bill 1856. The measure carves out open-source software from the Digital Age Assurance Act, which is scheduled to take effect on January 1, 2027.
The state Senate amended the bill on August 21 and passed it on the 26th in a 39-0 vote. The Assembly accepted those changes in a concurrence vote the following day. AB 1856 now heads to Governor Gavin Newsom, who signed the original act into law last October. The amendment resolves nearly a year of uncertainty over whether Linux distributions and SteamOS would have to collect user age data during account setup alongside Windows, macOS, iOS, and Android.
How the Exemptions Work
The amendments redefine the term “operating system provider” to exclude any person or entity that distributes an OS or application “under license terms that permit a recipient to copy, redistribute, and modify the software.” Software released under the GPL, MIT, BSD, and Apache licenses meets that test, taking Debian, Fedora, Ubuntu, Arch, and the BSD family out of the law’s scope.
A second exclusion removes software components that aren’t “offered to consumers as a stand-alone executable application through a covered application store” from the law’s definition of an application. That covers libraries and dependencies distributed through package managers such as apt and pacman. While AB 1856 does not explicitly state that repositories aren’t app stores, a store’s main obligation under the law is to request an age signal from the user’s OS provider and pass it to developers. An exempt open-source OS produces no such signal. A third carve-out excludes storefronts that distribute extensions or add-ons running exclusively inside a host application, removing browser extension stores from the scope.
Lawmakers also removed the original definition of “user,” which read “a child that is the primary user of a device” and technically classified every device owner in California as a child. The law’s signaling framework relies on adults declaring their age at account setup so their devices are flagged as 18 and over; under the prior definition, no one could ever be flagged as an adult.
New Safeguards and Remaining Obligations
A new provision now prohibits anyone from requesting an age signal from an OS provider or app store unless required by law, closing off potential misuse of the age API as a general-purpose data collection channel. Platforms and developers also gain a good-faith safe harbor against erroneous signals, shielding them from liability when age-gating signals are inaccurate.
Windows, macOS, iOS, and Android remain fully in scope, with age collection required at account setup starting January 1, 2027. A later deadline of July 1, 2027, applies to devices set up before that date. SteamOS status remains unclear: its Arch-based system components are open source, but Valve distributes the image with the proprietary Steam client. GrapheneOS, which in March said it would refuse to comply with age-verification mandates, is distributed under the MIT and Apache licenses and now falls outside the law’s scope entirely.
Source
Image: tomshardware.com