California Legislators Unanimously Pass Open-Source OS Exemption from Age-Verification Law

Software distributed under GPL, MIT, BSD, and Apache licenses are exempt, with the bill now headed to Governor Newsom

edit
By LineZotpaper
Published
Updated
Read Time3 min
Sources2 outlets
California lawmakers have unanimously passed Assembly Bill 1856, exempting open-source operating systems and software distributed under permissive licenses from the state's Digital Age Assurance Act, ending months of uncertainty for Linux distributions, including SteamOS and GrapheneOS. The bill now awaits Governor Gavin Newsom's signature.

In a decisive move, California's legislature has approved AB 1856, which amends the state's Digital Age Assurance Act to exempt open-source operating systems from mandatory age-verification requirements. The bill was amended by the Senate on August 21 and passed unanimously on August 26, with the Assembly concurring the following day. It now heads to Governor Gavin Newsom, who signed the original act into law last October.

Under the amendments, the term "operating system provider" is redefined to exclude any person or entity that distributes software under license terms that permit copying, redistribution, and modification. This exemption applies to software distributed under the GNU General Public License (GPL), MIT, BSD, and Apache licenses, effectively removing distributions such as Debian, Fedora, Ubuntu, Arch, and the BSD family from the law's scope.

A second exclusion removes software components that are not "offered to consumers as a stand-alone executable application through a covered application store" from the law's definition of an application. This protects libraries and dependencies distributed through package managers like apt and pacman.

A third carve-out exempts storefronts that distribute extensions or add-ons that run exclusively inside a host application, taking browser extension stores out of scope.

The amendments also correct a flawed original definition of "user," which classified every device owner in California as a child. Under the previous wording, no adult could be flagged as over 18. The new language removes that definition, fixing the signaling framework.

Lawmakers also inserted a provision prohibiting anyone from requesting an age signal from an OS provider or app store unless required by law. This prevents potential abuse of the age API as a general-purpose data collection channel. Platforms and developers gain a good-faith safe harbor against erroneous signals, protecting them from liability when age-gating signals are inaccurate.

Commercial operating systems—Windows, macOS, iOS, and Android—remain fully in scope. Age collection is required at account setup from January 1, 2027, with a later July 1, 2027 deadline for devices set up before January 1.

Uncertainty remains over SteamOS: its Arch-based system components are open source, but Valve distributes the image alongside the proprietary Steam client. GrapheneOS, which had previously said it would refuse to comply with age-verification mandates, is distributed under open-source MIT and Apache licenses and now falls outside the law's scope entirely.

Assemblymember Buffy Wicks, who authored both the Digital Age Assurance Act and the AB 1856 amendment, has not yet commented publicly, but the bipartisan support suggests broad agreement on the need to protect open-source development.

§

Analysis

Why This Matters

  • Removes a major compliance burden from open-source operating systems used by millions of developers, hobbyists, and privacy-focused users.
  • Clarifies that age-verification requirements will not apply to package managers or browser extension stores, preventing disruption of essential development workflows.
  • Sets a precedent for how states can balance child safety concerns with the open-source model, potentially influencing other jurisdictions considering similar laws.

Background

California's Digital Age Assurance Act, signed into law in October 2025, was designed to require operating system providers and app stores to verify users' ages to protect minors online. However, the law's broad language raised alarm in the open-source community, as it technically required all software distributors to collect age data—a requirement nearly impossible for decentralized, community-driven projects. The original law also contained a drafting error that defined every device user as a child, breaking the age-signaling framework. Assemblymember Buffy Wicks introduced AB 1856 to address these issues, and the unanimous votes in both chambers reflect widespread recognition of the problem.

Key Perspectives

Open-source advocates and Linux distributions: The exemption is a major relief, preserving the ability to distribute software without age-verification infrastructure. Groups like Debian, Fedora, and Ubuntu can continue operations without costly compliance measures. Child safety groups: Some may argue that the carve-out creates a loophole, allowing minors to access age-inappropriate content through open-source platforms. The provision prohibiting unnecessary age signal requests is intended to mitigate abuse, but concerns may persist. Critics/Skeptics: The exemption's reliance on license type may lead to edge cases, such as SteamOS, where the open-source OS is bundled with proprietary software. There is also uncertainty about enforcement: commercial OS providers remain in scope, and the law's impact on platforms like SteamOS is still unclear.

What to Watch

  • Governor Gavin Newsom's decision: He may sign AB 1856, veto it, or allow it to become law without his signature.
  • Guidance on SteamOS's status: A definitive ruling from the California Attorney General or courts could clarify whether the proprietary client brings the entire platform into scope.
  • Implementation deadlines: July 1, 2027, for existing devices, and potential legal challenges from commercial OS providers over the age-verification requirements.

Sources

newspaper

Zotpaper

Articles published under the Zotpaper byline are synthesized from multiple source publications by our AI editor and reviewed by our editorial process. Each story combines reporting from credible outlets to give readers a balanced, comprehensive view.