In a decisive move, California's legislature has approved AB 1856, which amends the state's Digital Age Assurance Act to exempt open-source operating systems from mandatory age-verification requirements. The bill was amended by the Senate on August 21 and passed unanimously on August 26, with the Assembly concurring the following day. It now heads to Governor Gavin Newsom, who signed the original act into law last October.
Under the amendments, the term "operating system provider" is redefined to exclude any person or entity that distributes software under license terms that permit copying, redistribution, and modification. This exemption applies to software distributed under the GNU General Public License (GPL), MIT, BSD, and Apache licenses, effectively removing distributions such as Debian, Fedora, Ubuntu, Arch, and the BSD family from the law's scope.
A second exclusion removes software components that are not "offered to consumers as a stand-alone executable application through a covered application store" from the law's definition of an application. This protects libraries and dependencies distributed through package managers like apt and pacman.
A third carve-out exempts storefronts that distribute extensions or add-ons that run exclusively inside a host application, taking browser extension stores out of scope.
The amendments also correct a flawed original definition of "user," which classified every device owner in California as a child. Under the previous wording, no adult could be flagged as over 18. The new language removes that definition, fixing the signaling framework.
Lawmakers also inserted a provision prohibiting anyone from requesting an age signal from an OS provider or app store unless required by law. This prevents potential abuse of the age API as a general-purpose data collection channel. Platforms and developers gain a good-faith safe harbor against erroneous signals, protecting them from liability when age-gating signals are inaccurate.
Commercial operating systems—Windows, macOS, iOS, and Android—remain fully in scope. Age collection is required at account setup from January 1, 2027, with a later July 1, 2027 deadline for devices set up before January 1.
Uncertainty remains over SteamOS: its Arch-based system components are open source, but Valve distributes the image alongside the proprietary Steam client. GrapheneOS, which had previously said it would refuse to comply with age-verification mandates, is distributed under open-source MIT and Apache licenses and now falls outside the law's scope entirely.
Assemblymember Buffy Wicks, who authored both the Digital Age Assurance Act and the AB 1856 amendment, has not yet commented publicly, but the bipartisan support suggests broad agreement on the need to protect open-source development.