Note: This post was written by Claude Fable 5. The following is a synthesis of legislative records and reporting from technology news outlets.
On Wednesday the California Senate voted 40โ0 to pass Assembly Bill 1856, and on Thursday the Assembly concurred 69โ0, sending Governor Gavin Newsom a fix for a problem his state created last October: an age-verification law written so broadly that every Linux distribution, the BSDs, and arguably SteamOS were on the hook to collect birth dates from their users. The bill exempts open-source operating systems from the Digital Age Assurance Act before it takes effect on January 1, 2027 โ and not a single legislator in either chamber voted to keep them in.
The Law That Swept In Linux
The Digital Age Assurance Act (AB 1043), authored by Assemblymember Buffy Wicks and signed by Newsom in October 2025, requires operating system providers to ask for a user’s birth date at account setup and hand an age bracket โ under 13, 13โ15, 16โ17, or 18-plus โ to app stores and developers through a real-time API. New devices must comply on January 1, 2027; devices set up earlier get until July 1.
The statute was plainly drafted with Apple, Google, and Microsoft in mind. But its definition of a covered provider โ anyone who “develops, licenses, or controls” the OS on a general-purpose computing device โ contains no size floor and no business-model test. Read literally, it reached Debian, Fedora, Arch, Ubuntu, and the BSD family: volunteer-run projects with no user accounts to attach an age to, no legal departments, and no revenue to fund compliance. The Electronic Frontier Foundation and Linux developers spent months pointing this out; the privacy-focused Android derivative GrapheneOS said in March it would refuse to comply outright.
The original text carried a second tell about its drafting quality. It defined “user” as “a child that is the primary user of a device” โ meaning that, as written, every adult in California was legally a child and no device could ever be flagged 18-plus. AB 1856 repeals that definition along with the rest of the cleanup.
A License Test, Not a Product List
What makes the exemption interesting beyond California is how it draws the line. The amended law excludes anyone who distributes an operating system or application “under license terms that permit a recipient to copy, redistribute, and modify the software.” That is a license test, not a product list: the GPL, MIT, BSD, and Apache licenses all satisfy it, so the statute never has to name Linux, track distributions, or decide what counts as a “real” vendor.
The same logic explains who stays in. Windows, macOS, iOS, and Android remain covered, because what ships to consumers is not freely redistributable โ Android’s open-source core doesn’t help Google when the build on actual phones comes bundled with proprietary services. SteamOS sits in genuine limbo: its Arch-based system is open, but Valve distributes the image with the proprietary Steam client attached. Two companion carve-outs handle the plumbing โ software that isn’t a stand-alone application offered through an app store (the libraries and dependencies that flow through apt and pacman) is out of scope, as are storefronts for extensions that only run inside a host application, which excuses browser extension stores.
The Detour Through Browsers
The bill that passed unanimously is not the bill that spent the spring in Sacramento. Earlier versions paired the open-source exemption with an expansion of the age-gating framework to browsers and websites โ a trade the EFF summarized in a May post titled “One Step Forward, Two Steps Back.” The Senate stripped the browser and website mandates in July, and the foundation dropped its fight: “Given these changes, EFF has removed its opposition to A.B. 1856.”
The final version also adds guardrails the original law lacked. No one may request an age signal from an OS provider or app store unless a law requires it โ closing off the API’s potential second life as a general-purpose data-collection channel โ and platforms acting in good faith get a safe harbor when a signal turns out to be wrong.
What Happens Now
Newsom is expected to sign a unanimous cleanup of his own statute, written by the law’s own author. The January 1 clock keeps running for the commercial platforms either way. Colorado has already followed the same path: after backlash from open-source developers โ Denver-based System76 among the voices โ its age-attestation law (SB 26-051, effective mid-2028) picked up a nearly identical license-based exemption this spring.
That makes this the emerging template for a collision that will keep happening. Age-verification mandates are spreading across states and countries, and most are drafted around the two account ecosystems legislators actually use. Community-developed software โ no vendor, no accounts, no one to serve papers on โ breaks those assumptions, and California just showed the least-damaging way to acknowledge that. The EFF, for its part, signed off on the exemption without blessing the framework underneath it: “no one should have to provide or verify their age to access the internet. Once users’ personal data is collected, it can easily be leaked, hacked, or misused.” The Linux problem is solved. The argument it was part of is not.
Sources
- Tom’s Hardware - California lawmakers unanimously pass Linux exemption from age-verification law
- California Legislature - AB-1856 Age verification signals: software applications (votes and text)
- Linuxiac - California’s Age Verification Bill Passes with Linux Exemption Intact
- EFF - California Steps Back From Dangerous Expansion of its Age-Gating Law
- EFF - One Step Forward, Two Steps Back: CA’s AB 1856 Exempts Open Source But Expands Age-Gating
- The Register - California may let Linux bypass age check
- GamingOnLinux - Colorado and California age verification bills exempt open source operating systems
