news / 2026 / california + age-verification A software-policy worktable maps operating-system accounts, application stores, developer APIs, and open-source distribution licenses around California's age-signal legislation.

news

California Put Open Source Outside the Age-Gate Stack

California has made software license terms part of its age-assurance architecture: proprietary platforms carry the signal, while modifiable open-source distributions sit outside the statutory operating-system-provider boundary.

California’s Legislature has enrolled AB 1856, a unanimous amendment to the state’s Digital Age Assurance Act. The Senate passed it 39–0 on August 26. The Assembly concurred 69–0 the next day and sent it to engrossing and enrolling, the final legislative step before the governor receives it.[2]

The amendment decides who carries the age gate. Operating systems with account setup must collect a birth date or age, convert it into one of four brackets, and expose that bracket through a secure real-time interface. Application stores request the signal. Developers request it when an app is downloaded and launched. The same bill excludes a distributor whose license lets recipients copy, redistribute, and modify the software from the definition of an operating system provider.[1]

That sentence places Linux distributions, BSD systems, and similar open-source projects outside the operating-system duty described by the statute. Software licensing has become part of California’s identity architecture.

This is a specific new development in the age-assurance story. France prohibited social-media access for children under 15 while leaving the gate undefined. JUUL2 moved an optional age check into a connected nicotine device. California has now named the gatekeepers for general-purpose computing and carved modifiable software distributors out of that role.

The age signal starts at device setup

AB 1856 amends a system scheduled to begin January 1, 2027. An operating system provider with an account-setup feature must ask the account holder for the primary user’s birth date, age, or both. The resulting signal places the user under 13, from 13 through 15, from 16 through 17, or at least 18.[1]

The bill calls the brackets nonpersonally identifiable data and limits providers to the minimum information needed for compliance. Operating system providers and application stores cannot share the signal for unrelated purposes. Developers must use it for applicable law and cannot ask those intermediaries for extra information.[1]

The legal consequence travels farther than the four-value payload suggests. A developer that receives a signal gains actual knowledge of the user’s age range across account creation and login surfaces tied to the same application. Internal clear and convincing information can override the device signal. Civil penalties reach $2,500 per affected child for a negligent violation and $7,500 for an intentional one, with enforcement assigned to the California attorney general.[1]

A tiny API response can therefore alter what the law says a developer knows. The system converts device-account data into liability state.

Open source exits through the definition

The exemption is compact: an operating system provider excludes an entity distributing an operating system or application under terms that allow copying, redistribution, and modification. Phoronix reads the language as relief for Linux distributions, BSDs, and other open-source systems after months of concern about the original law’s compliance burden.[3]

This route avoids assigning centralized identity work to projects that often lack a central account authority, commercial app store, device-registration database, or single organization capable of operating a statewide age API. Debian can distribute an operating system without becoming the identity issuer for every machine that boots it. A small BSD project does not need to build a birth-date registry because somebody in California installed its image.

The exemption also exposes a structural truth about the original design. Device-level age signals assume a platform owner. The architecture fits Apple, Google, and Microsoft because each can bind account setup, operating-system updates, application distribution, policy enforcement, and developer interfaces. A freely redistributable operating system breaks that ownership chain. California solved the mismatch by narrowing the regulated role.

Package ecosystems receive a second boundary. The bill’s definition of an application excludes software components that are not offered to consumers as stand-alone executable applications through a covered application store. A covered store also excludes services distributing extensions, plug-ins, add-ons, or software that runs exclusively inside a separate host application.[1] Those clauses keep every library, codec, shell package, and editor extension from becoming its own age-aware product.

The carve-out protects projects and sharpens platform power

Open-source relief is warranted. A volunteer distribution cannot run the same compliance machinery as a company controlling hardware activation, cloud accounts, and a global store. The amendment recognizes the difference before the law goes live.

The remaining system still concentrates authority. Proprietary operating-system vendors decide how account holders enter age, how shared devices map to a primary user, how bracket changes propagate, how developers authenticate to the API, and how outages or family-account disputes appear. The bill provides good-faith protection for erroneous signals and technical outages, but the interface remains the practical source of truth until stronger internal evidence exists.[1]

Nondiscrimination language tries to constrain the obvious abuse paths. Operating systems and stores must apply equivalent restrictions to their own software and third-party distribution. They cannot use compliance data to compete against third parties, prefer their services, or otherwise turn the consent mechanism into an anticompetitive advantage.[1] Enforcement will depend on whether auditors can observe those behaviors across account systems and store policies.

The privacy claim also needs operational proof. Four brackets reveal less than a full birth date, yet the operating system still collects age information and emits a persistent legal signal to stores and applications. Shared family computers, repaired machines, dual-boot systems, local accounts, institutional devices, and reused hardware all complicate the phrase “primary user.” The statute disclaims liability when somebody else uses a shared device or application. The interface still has to represent that ambiguity without quietly training every developer to treat one device as one person.

A license now changes the compliance topology

AB 1856 does something unusually legible. It draws the architecture around the organizations that can operate it. Proprietary platform owners carry the account and API duty. Open-source distributors avoid inheriting an identity service their production model cannot support. Package components and host-bound extensions stay outside the stand-alone application category.

The amendment still awaits executive action, so describing it as enacted law would outrun the official record. Its unanimous passage shows that California lawmakers accepted the underlying distinction: source custody and modification rights change who can reasonably be treated as the operating system’s identity authority.[2]

That distinction will matter beyond this bill. Legislatures keep pushing child-safety rules downward from websites into stores, operating systems, identity providers, and devices. Each layer needs an owner who can receive process, maintain an interface, absorb liability, and change defaults. Open-source systems distribute those powers across maintainers and users. Commercial systems consolidate them.

California has written that governance difference into the age gate. The exemption saves open-source projects from a ridiculous mandate. The rest of the statute confirms where the mandate lands: inside the account systems of the largest platform companies.

Sources

[1] https://leginfo.legislature.ca.gov/faces/billTextClient.xhtml?bill_id=202520260AB1856 - California AB 1856 bill text [2] https://leginfo.legislature.ca.gov/faces/billStatusClient.xhtml?bill_id=202520260AB1856 - California AB 1856 status [3] https://www.phoronix.com/news/California-AB-1856-Passes - California passes AB 1856 for open-source relief