California exempts open-source operating systems from age-verification law

California's legislature has passed Assembly Bill 1856, an amendment exempting open-source operating systems from the state's Digital Age Assurance Act, months before that law is due to take effect on January 1, 2027. The Senate amended the bill on August 21 and passed it on the 26th in a 39-0 vote; the Assembly then accepted the Senate's changes in a concurrence vote the following day. AB 1856 has now been sent to Governor Gavin Newsom, who signed the original Digital Age Assurance Act into law last October.
The amendment redefines the term "operating system provider" to exclude any person or entity that distributes an OS or application under license terms that let a recipient copy, redistribute, and modify the software. Any software released under the GPL, MIT, BSD, or Apache licenses meets that test, which takes Debian, Fedora, Ubuntu, Arch, and the BSD family out of the law's reach entirely.
A second exclusion covers software components that are not offered to consumers as a stand-alone executable application through a covered app store, which shields libraries and dependencies distributed through package managers such as apt and pacman. AB 1856 does not say outright that these repositories are not app stores, but a store's core obligation under the law is to request an age signal from the user's OS provider and pass it to developers, and an exempt open-source OS produces no such signal. A third carve-out excludes storefronts that distribute extensions or add-ons running only inside a host application, taking browser extension stores out of scope as well.
The amendment also strikes the original definition of "user," which read "a child that is the primary user of a device" and technically classified every device owner in California as a child. Since the law's signaling framework depends on adults declaring their age at account setup so their devices get flagged as 18 and over, that original wording meant nobody could ever have been flagged as an adult in the first place.
Lawmakers also inserted a new provision barring anyone from requesting an age signal from an OS provider or app store unless the law requires it, closing off the risk of the age API becoming a general-purpose data collection channel. Platforms and developers additionally gain a good-faith safe harbor shielding them from liability when an age-gating signal turns out to be inaccurate.
Windows, macOS, iOS, and Android remain fully covered by the original act, with age collection required at account setup from January 1, 2027, and a later deadline of July 1, 2027, for devices already set up before then. Whether SteamOS itself falls under the law is not yet clear: its Arch-based system components are open source, but Valve distributes the SteamOS image bundled with its proprietary Steam client. GrapheneOS, distributed under the open-source MIT and Apache licenses, now falls outside AB 1856's scope entirely; the project said in March it would refuse to comply with age-verification mandates, though Brazil's separate Digital ECA law still applies to it.
Assemblymember Buffy Wicks, who wrote both the original Digital Age Assurance Act and the AB 1856 amendment, introduced the exemption back in February after criticism from Linux developers and the Electronic Frontier Foundation.
Key facts
- California's Senate passed the AB 1856 amendment 39-0 on August 26, and the Assembly concurred the next day, sending the bill to Governor Gavin Newsom, who signed the original Digital Age Assurance Act into law last October.
- The amendment exempts any operating system distributed under license terms permitting copying, redistribution, and modification, covering the GPL, MIT, BSD, and Apache licenses, which removes Debian, Fedora, Ubuntu, Arch, and the BSD family from the law's scope.
- A second exclusion covers libraries and dependencies distributed through package managers such as apt and pacman, and a third takes browser extension stores out of scope.
- The amendment also deletes an original definition of "user" that had technically classified every device owner as a child, and adds a rule barring anyone from requesting an age signal unless required by law, plus a good-faith safe harbor for inaccurate signals.
- Windows, macOS, iOS, and Android remain fully in scope, with age collection required at account setup from January 1, 2027 (July 1, 2027 for already-set-up devices); SteamOS's status is unresolved, and GrapheneOS falls outside AB 1856 despite still facing Brazil's Digital ECA.
Why it matters
This ends almost a year of uncertainty over whether Linux distributions and SteamOS would have been forced to collect user age data at account setup, the same way the Digital Age Assurance Act already requires of Windows, macOS, iOS, and Android starting January 1, 2027. The fix works by redefining who counts as an "operating system provider": software distributed under license terms that let a recipient copy, redistribute, and modify it, which covers the GPL, MIT, BSD, and Apache licenses, no longer counts as coming from a provider under the law at all. That keeps the Digital Age Assurance Act in force for the commercial platforms it targets, while taking open-source software out of its scope entirely.
Who it affects
Directly exempted: distributions and projects released under the GPL, MIT, BSD, or Apache licenses, including Debian, Fedora, Ubuntu, Arch, the BSD family, and GrapheneOS, plus developers who ship libraries and dependencies through package managers like apt and pacman, and browser extension stores. Left in an unresolved middle ground: SteamOS, whose Arch-based components are open source but which Valve distributes bundled with its proprietary Steam client. Unaffected, and still fully bound by the original law from January 1, 2027: Windows, macOS, iOS, and Android, the platforms the Digital Age Assurance Act was written around.
How to use it
There is no product or price here: the practical effect for anyone distributing a GPL, MIT, BSD, or Apache-licensed operating system, or shipping libraries and dependencies through an open package manager, is that the Digital Age Assurance Act's signaling requirement does not apply to them at all. Under the law, a covered app store's core obligation is to request an age signal from a user's OS provider and pass it to developers, and the amendment establishes that an exempt open-source OS produces no such signal. A new provision also bars anyone from requesting an age signal from an OS provider or app store for any purpose the law does not itself require, and platforms and developers get a good-faith safe harbor protecting them from liability when a signal turns out to be inaccurate.
How solid is it
The account traces a specific legislative record: the Senate amended AB 1856 on August 21 and passed it 39-0 on August 26, the Assembly concurred the following day, and the bill has now been sent to Governor Gavin Newsom, who signed the original Digital Age Assurance Act last October. The source does not state that Newsom has signed this amendment itself, only that it has reached his desk after his earlier signature on the underlying act. Several supporting dates in the piece, including the Senate's August actions, Newsom's October signature, Wicks's February introduction of the exemption, and GrapheneOS's March statement, are given by month and day only, without a year stated.
Risks and caveats
Whether SteamOS itself falls inside or outside AB 1856 remains explicitly unresolved: its Arch-based system components are open source, but Valve distributes the SteamOS image bundled with a proprietary Steam client. The exemption is also jurisdiction-specific: GrapheneOS qualifies for it in California but is still subject to Brazil's separate Digital ECA law, so a project can be exempt from California's requirement while still facing separate rules elsewhere. And the underlying Digital Age Assurance Act itself is untouched for the platforms it targets: Windows, macOS, iOS, and Android still face a January 1, 2027, deadline to begin collecting age data at setup, with a further deadline of July 1, 2027, for devices already in use, and the source does not describe what penalties apply if a covered platform misses either date.
“a child that is the primary user of a device”
— AB 1856's original, now-removed definition of "user"