[news] California lawmakers unanimously pass Linux exemption from age-verification law — software distributed under the GPL, MIT, BSD, and Apache licenses are exempt
2 messages · started by Devi Garcia on Aug 30, 2026
[news] California lawmakers unanimously pass Linux exemption from age-verification law — software distributed under the GPL, MIT, BSD, and Apache licenses are exempt
From Devi Garcia · Aug 30, 2026
These amendments redefine the term “operating system provider” to exclude any person or entity that distributes an OS or application “under license terms that permit a recipient to copy, redistribute, and modify the software.” Any software distributed under the GPL, MIT, BSD, and Apache licenses satisfies that test, which removes the likes of Debian, Fedora, Ubuntu, Arch, and the BSD family from AB 1856’s scope.
A second exclusion removes software components that aren’t “offered to consumers as a stand-alone executable application through a covered application store” from the law’s definition of an application, covering libraries and dependencies distributed through package managers like apt and pacman. AB 1856 doesn’t explicitly say that repos aren’t app stores, but a store’s main obligation under the law is to request an age signal from the user’s OS provider and pass it to developers; an exempt open-source OS produces no signal. A third carve-out excludes storefronts distributing extensions or add-ons that run exclusively inside a host application, which takes browser extension stores out of scope.
The amendments to AB 1856 also remove the original definition of “user,” which read, “a child that is the primary user of a device,” and technically classified every device owner in California as a child. The law’s signaling framework depends on adults declaring their age on account setup, so their devices get flagged as 18 and over, but under that definition nobody could ever be flagged as an adult.
In addition, lawmakers inserted a new provision prohibiting anyone from requesting an age signal from an OS provider or app store unless required by law. That closes off potential abuse of the age API that could have led to it being used as a general-purpose data collection channel even when age verification wasn’t required. Platforms and developers also gain a good-faith safe harbor against erroneous signals, protecting them from liability when age-gating signals are inaccurate.
https://www.tomshardware.com/software/linux/california-lawmakers-unanimously-pass-linux-exemption-from-age-verification-law-software-distributed-under-the-gpl-mit-bsd-and-apache-licenses-are-exempt
Re: [cochiselinux] [news] California lawmakers unanimously pass Linux exemption from age-verification law — software distributed under the GPL, MIT, BSD, and Apache licenses are exempt
From George Self · Aug 31, 2026
This is really good news, but the fight is far from over. I got this back from a perplexity search:
Quoted reply (78 lines)Illinois is the state to watch if the concern is a Linux distro, BSD, independent OS project, or another open-source OS supplier. HB 5511’s text requires an OS provider to provide an
Illinois is the state to watch if the concern is a Linux distro, BSD, independent OS project, or another open-source OS supplier. HB 5511’s text requires an OS provider to provide an account-setup interface that requires age, DOB, or both, for the purpose of supplying an age-category signal to applications; the deadline is no later than January 1, 2028.
The distinction from California and Colorado is meaningful: sources discussing the enacted/passed Illinois bill say it reaches broadly across internet-enabled hardware and operating systems and does not contain an open-source exception. The Electronic Frontier Foundation characterized it as a device-level age-gating system that makes platforms collect and share age information, and urged a veto before the reported signing. A separate report says Governor Pritzker signed it in early August and expressly notes that Linux, FreeBSD, and similar systems are covered.
There is also a proposed federal legislation, the "Digital Age Assurance Act of 2026," that would require OS providers to verify age. However, that proposal was only introduced and not acted on. Unfortunately, given the current state of our federal government, I suspect some sort of age verification requirement will bubble up again.
California’s legislature has passed Assembly Bill 1856, exempting open-source operating systems from the State’s Digital Age Assurance Act months before the law is due to take effect on January 1, 2027. The Senate amended the Bill on August 21 before passing it on the 26th in a 39-0 vote, with the Assembly then accepting these changes in a concurrence vote the following day. The amendment ends almost a year of uncertainty surrounding whether Linux distributions and SteamOS would be forced to collect user age data during account setup alongside Windows, macOS, iOS, and Android. AB 1856 has now been sent to Governor Gavin Newsom, who signed the original act into law last October.
These amendments redefine the term “operating system provider” to exclude any person or entity that distributes an OS or application “under license terms that permit a recipient to copy, redistribute, and modify the software.” Any software distributed under the GPL, MIT, BSD, and Apache licenses satisfies that test, which removes the likes of Debian, Fedora, Ubuntu, Arch, and the BSD family from AB 1856’s scope.
A second exclusion removes software components that aren’t “offered to consumers as a stand-alone executable application through a covered application store” from the law’s definition of an application, covering libraries and dependencies distributed through package managers like apt and pacman. AB 1856 doesn’t explicitly say that repos aren’t app stores, but a store’s main obligation under the law is to request an age signal from the user’s OS provider and pass it to developers; an exempt open-source OS produces no signal. A third carve-out excludes storefronts distributing extensions or add-ons that run exclusively inside a host application, which takes browser extension stores out of scope.
The amendments to AB 1856 also remove the original definition of “user,” which read, “a child that is the primary user of a device,” and technically classified every device owner in California as a child. The law’s signaling framework depends on adults declaring their age on account setup, so their devices get flagged as 18 and over, but under that definition nobody could ever be flagged as an adult.
In addition, lawmakers inserted a new provision prohibiting anyone from requesting an age signal from an OS provider or app store unless required by law. That closes off potential abuse of the age API that could have led to it being used as a general-purpose data collection channel even when age verification wasn’t required. Platforms and developers also gain a good-faith safe harbor against erroneous signals, protecting them from liability when age-gating signals are inaccurate.
https://www.tomshardware.com/software/linux/california-lawmakers-unanimously-pass-linux-exemption-from-age-verification-law-software-distributed-under-the-gpl-mit-bsd-and-apache-licenses-are-exempt