Frames and Fans
Live
Handhelds & consoles

California exempts open-source OS from age

California lawmakers have passed AB 1856, exempting software under GPL, MIT, BSD, and Apache licenses from the state's upcoming Digital Age Assurance Act.

California lawmakers have passed AB 1856, exempting software under GPL, MIT, BSD, and Apache licenses from the state's...

California lawmakers have unanimously passed an exemption for open-source operating systems from the state's upcoming age-verification law. Assembly Bill 1856, which passed the Senate in a 39-0 vote on August 26, excludes software distributed under the GPL, MIT, BSD, and Apache licenses from the Digital Age Assurance Act set to take effect on January 1, 2027.

The amendment redefines the term "operating system provider" to exclude any entity that distributes an OS or application under license terms permitting copying, redistribution, and modification. This removes major Linux distributions like Debian, Fedora, Ubuntu, and Arch, as well as the BSD family, from the law's scope. The Assembly accepted the Senate's changes in a concurrence vote on August 27, sending the bill to Governor Gavin Newsom.

Scope of the Exemptions

A second exclusion removes software components that are not "offered to consumers as a stand-alone executable application through a covered application store." This covers libraries and dependencies distributed through package managers such as apt and pacman. The law's framework requires app stores to request an age signal from the user's OS provider and pass it to developers; an exempt open-source OS produces no such signal.

A third carve-out exempts storefronts distributing extensions or add-ons that run exclusively inside a host application, which takes browser extension stores out of scope. The amendments also remove the original problematic definition of "user" as "a child that is the primary user of a device," which had technically classified every device owner in California as a child.

Remaining Obligations and Unclear Cases

Major proprietary operating systems remain fully under the law's requirements. Windows, macOS, iOS, and Android will be required to collect user age data during account setup starting January 1, 2027. A later deadline of July 1, 2027, applies to devices set up before the new year.

The status of SteamOS is not yet clear. While its Arch-based system components are open source, Valve distributes the image alongside the proprietary Steam client. GrapheneOS, which stated in March it would refuse to comply with age-verification mandates, is distributed under the MIT and Apache licenses and now falls outside the California law's scope entirely.

Additional Provisions and Background

Lawmakers inserted a new provision prohibiting anyone from requesting an age signal from an OS provider or app store unless required by law. This aims to prevent potential abuse of the age API as a general-purpose data collection channel. Platforms and developers also gain a good-faith safe harbor against liability for inaccurate age-gating signals.

Assemblymember Buffy Wicks, who authored both the original Digital Age Assurance Act and the AB 1856 amendment, introduced the exemption in February following criticism from Linux developers and the Electronic Frontier Foundation. The amendment ends nearly a year of uncertainty for the open-source community regarding the law's application.

Related coverage

More from Handhelds & consoles