In a significant move, California’s legislature has amended Assembly Bill 1856 exempting open-source operating systems from the state’s Digital Age Assurance Act. This amendment comes just months before the law was set to take effect on January 1, 2027.
The Senate made crucial amendments on August 21 and passed the bill on the 26th with a unanimous 39-0 vote. The Assembly concurred with these changes the following day, sending the bill to Governor Gavin Newsom for signature. This development resolves nearly a year of uncertainty for Linux distributions and SteamOS which were previously at risk of being forced to collect user age data.
Key Amendments to Assembly Bill 1856
The amendments redefine the term operating system provider to exclude entities that distribute software under licenses permitting copying, redistribution, and modification. This exemption covers software distributed under the GPLMITBSD and Apache licenses, effectively removing popular distributions like DebianFedoraUbuntuArch and the BSD family from the law’s scope.
A second exclusion removes software components that are not offered as stand-alone executable applications through covered application stores. This provision protects libraries and dependencies distributed through package managers like apt and pacman. Additionally, storefronts distributing extensions or add-ons that run exclusively inside a host application are also exempt, taking browser extension stores out of scope.
Impact on Age Verification Requirements
The amendments also remove the original definition of user which previously classified every device owner in California as a child. This change ensures that adults can declare their age during account setup, allowing their devices to be flagged as 18 and over. Furthermore, a new provision prohibits anyone from requesting an age signal from an OS provider or app store unless required by law, preventing potential abuse of the age API.
Platforms and developers gain a good-faith safe harbor against erroneous signals, protecting them from liability when age-gating signals are inaccurate. This provision ensures that developers are not held responsible for inaccurate age verification data.
Scope of the Digital Age Assurance Act
Despite these exemptions, WindowsmacOSiOS and Android remain fully in scope, with age collection required at account setup from January 1, 2027. A later deadline of July 1, 2027 applies to devices set up before January 1. The status of SteamOS remains unclear, as its Arch-based system components are open source, but Valve distributes the image alongside the proprietary Steam client.
GrapheneOS which announced in March its refusal to comply with age-verification mandates, is distributed under open-source MIT and Apache licenses and now falls outside the law’s scope entirely. However, Brazil’s Digital ECA still applies to it.
Legislative Background
Assemblymember Buffy Wicks who authored both the Digital Age Assurance Act and the AB 1856 amendment, introduced the exemption in February following criticism from Linux developers and the Electronic Frontier Foundation. This legislative update ensures that open-source operating systems are not burdened with unnecessary age verification requirements, fostering a more inclusive digital environment.



