The Spectrum Dispatch News

technology

California Lawmakers Unanimously Exempt Open-Source OS From Age-Verification Law

The amendment to AB 1856 excludes operating systems distributed under GPL, MIT, BSD and Apache licenses from California’s Digital Age Assurance Act, which is set to take effect Jan

California Lawmakers Unanimously Exempt Open-Source OS From Age-Verification Law

California’s legislature has passed Assembly Bill 1856, which exempts open‑source operating systems from the state’s Digital Age Assurance Act months before the law is due to take effect on January 1, 2027. According to the source, the Senate amended the bill on August 21 and passed it on August 26 in a 39‑0 vote. The Assembly accepted the changes in a concurrence vote the following day. The bill has now been sent to Governor Gavin Newsom, who signed the original act into law last October. The amendment redefines the term “operating system provider” to exclude any person or entity that distributes an OS or application “under license terms that permit a recipient to copy, redistribute, and modify the software.” The source states that any software distributed under the GPL, MIT, BSD, and Apache licenses satisfies that test, thereby removing distributions such as Debian, Fedora, Ubuntu, Arch, and the BSD family from the law’s scope. A second exclusion removes software components that are not “offered to consumers as a stand‑alone executable application through a covered application store” from the definition of an application, covering libraries and dependencies distributed through package managers like apt and pacman. A third carve‑out excludes storefronts that distribute extensions or add‑ons that run exclusively inside a host application, which takes browser‑extension stores out of scope. The amendments also strike the original definition of “user,” which had read, “a child that is the primary user of a device,” and would have technically classified every device owner in California as a child. Lawmakers added a new provision that prohibits anyone from requesting an age signal from an OS provider or app store unless required by law, closing off potential abuse of the age API as a general‑purpose data‑collection channel. Platforms and developers receive a good‑faith safe harbor against erroneous signals, protecting them from liability when age‑gating signals are inaccurate. While Windows, macOS, iOS, and Android remain fully in scope and must collect age data at account setup from January 1, 2027 (with a later July 1, 2027 deadline for devices set up before that date), the status of SteamOS is uncertain because its Arch‑based components are open source but it is distributed alongside the proprietary Steam client. GrapheneOS, which in March said it would refuse to comply with age‑verification mandates, is distributed under MIT and Apache licenses and now falls outside the law’s scope entirely, although Brazil’s Digital ECA still applies to it. Assemblymember Buffy Wicks, who authored both the Digital Age Assurance Act and the AB 1856 amendment, introduced the exemption in February after criticism from Linux developers and the Electronic Frontier Foundation. The changes aim to address concerns that the original law would have forced open‑source OS providers to collect age data during account setup, a requirement that many in the community viewed as incompatible with the principles of free and open‑source software.

California Lawmakers Unanimously Exempt Open-Source OS From Age-Verification Law

Key facts

Sources

← All posts