deniz.in

Markets

Weather

Loading weather

· via Hacker News – Front Page (hnrss.org)

California unanimously exempts open-source operating systems from age-verification law

California lawmakers voted 39-0 to exempt open-source software — including Linux distributions — from the Digital Age Assurance Act's age-verification requirements, which take effect in January 2027.

California unanimously exempts open-source operating systems from age-verification law

What happened

California's legislature has passed Assembly Bill 1856, an amendment to the state's Digital Age Assurance Act that exempts open-source operating systems from its age-verification requirements months before the mandate takes effect on January 1, 2027. According to Tom's Hardware, the state Senate amended the bill on August 21 and passed it on August 26 in a 39-0 vote, with the Assembly accepting those changes in a concurrence vote the following day. The bill now heads to Governor Gavin Newsom, who signed the original act into law last October.

The vote resolves nearly a year of uncertainty over whether Linux distributions and other community-maintained operating systems would have been forced to collect age data from users during account setup, alongside Windows, macOS, iOS and Android. Assemblymember Buffy Wicks, who authored both the original act and the amendment, introduced the exemption in February after criticism from Linux developers and the Electronic Frontier Foundation.

How the exemption works

Rather than naming specific projects, the amendment redefines "operating system provider" to exclude any person or entity that distributes an operating system or application "under license terms that permit a recipient to copy, redistribute, and modify the software." As Tom's Hardware explains, any software distributed under the GPL, MIT, BSD or Apache licenses satisfies that test, which takes Debian, Fedora, Ubuntu, Arch and the BSD family out of the law's scope.

Two further carve-outs narrow the law's reach. Software components that are not "offered to consumers as a stand-alone executable application through a covered application store" no longer count as applications under the law, which covers libraries and dependencies distributed through package managers such as apt and pacman. Storefronts that distribute extensions or add-ons running exclusively inside a host application — browser extension stores, for example — are also excluded.

The amendment does not explicitly declare Linux repositories to be non-app-stores, but as the report notes, a store's main obligation under the law is to request an age signal from the user's OS provider and pass it along to developers. An exempt open-source operating system produces no such signal.

Other fixes tucked into the bill

Lawmakers also removed the original law's definition of a "user" as "a child that is the primary user of a device" — wording that technically classified every device owner in California as a child. Under that definition no one could ever be flagged as an adult, even though the law's signaling framework depends on adults declaring their age at account setup so their devices can be marked as 18 and over.

A new provision prohibits anyone from requesting an age signal from an OS provider or app store unless required by law, closing off a route by which the age API could have been used as a general-purpose data collection channel even where age verification was not needed. Platforms and developers also gain a good-faith safe harbor protecting them from liability when age-gating signals turn out to be inaccurate.

What remains in scope

Windows, macOS, iOS and Android are still fully covered, with age collection required at account setup from January 1, 2027. A later deadline of July 1, 2027 applies to devices set up before that date.

The status of SteamOS is not yet clear: its Arch-based system components are open source, but Valve distributes the image alongside the proprietary Steam client. GrapheneOS, which said in March that it would refuse to comply with age-verification mandates, is distributed under the MIT and Apache licenses and now falls outside California's law entirely — though Tom's Hardware notes that Brazil's Digital ECA still applies to it.

Why it matters

The exemption spares volunteer-run projects from building age-verification infrastructure they have neither the resources nor the legal machinery to operate, and it sets a notable precedent: lawmakers adjusting a technically flawed mandate before it takes effect rather than after. It also shows how license terms — rather than project identity — can serve as the legal dividing line for regulatory compliance, an approach other jurisdictions pursuing age-assurance laws may end up copying. The major commercial platforms remain covered, so the core mandate is intact; open source simply will not be collateral damage.

  • #open-source
  • #linux
  • #age-verification
  • #regulation
  • #california

Related posts