California Lawmakers Exempt Open-Source Software From Upcoming Age-Verification Law

California Lawmakers Exempt Open-Source Software From Upcoming Age-Verification Law

2026-08-30 politics

Sacramento, Saturday, 29 August 2026.
California legislators unanimously passed Assembly Bill 1856, exempting open-source software like Linux from age-verification mandates before the state’s Digital Age Assurance Act takes effect in January 2027.

Legislative Details and Exemptions

The passage of Assembly Bill 1856 marks a significant adjustment to the state’s regulatory landscape, specifically redefining the term “operating system provider” to exclude entities distributing software under licenses that permit copying, redistribution, and modification [1][2]. This legislative change effectively shields distributions such as Debian, Fedora, Ubuntu, and Arch from the compliance requirements mandated by the Digital Age Assurance Act [1]. The bill introduces three specific carve-outs, including open-source operating systems, software components not sold as stand-alone executables, and storefronts distributing extensions that run exclusively inside host applications [1]. While the exemption clarifies the status for most Linux distributions, the regulatory status of SteamOS remains uncertain because Valve distributes the image bundled with the proprietary Steam client despite utilizing open-source Arch-based components [1]. Package managers and infrastructure components are also excluded from the definition of “application,” preventing the obligation of age verification from extending automatically to every module of software distributed [4][6].

Political Context and Voting Record

The legislative journey for AB 1856 involved unanimous support across both chambers of the California Legislature, reflecting broad bipartisan agreement on the technical necessities of open-source development [1][3]. On 2026-08-26, the California Senate passed the bill with a 39-0 vote, following an earlier Assembly vote where the bill secured 69 votes in favor with zero against [2][7]. The amendment was introduced by Assemblymember Buffy Wicks in February 2026 following criticism from the Electronic Frontier Foundation and Linux developers regarding the original law’s scope [1]. While Governor Gavin Newsom signed the original Digital Age Assurance Act into law in October 2025, this amendment corrects a previous definition of “user” that technically classified all device owners as children under the law’s signaling framework [1][7]. Assemblymember Pilar Schiavo noted the broader context of these legislative moves, stating, “This is an opportunity for us to further secure every Californian’s constitutional right to privacy” [3][7].

Implementation Timeline and Compliance

The Digital Age Assurance Act is scheduled to take effect on 2027-01-01, requiring age collection at account setup for non-exempt platforms such as Windows, macOS, iOS, and Android [1][2]. Devices established prior to this date have a compliance deadline of 2027-07-01, providing a six-month grace period for existing hardware to align with the new signaling requirements [1]. The legislation prohibits requesting age signals from operating system providers or app stores unless required by law and establishes a “good-faith safe harbor” for platforms and developers regarding inaccurate age-gating signals [1]. As of 2026-08-29, the bill has passed both legislative houses and awaits final processing, with the regulatory distinction between exempt and subject software set to have practical compliance consequences starting in January 2027 [4][6]. GrapheneOS, which publicly announced its refusal to comply with age-verification mandates in March 2026, is now excluded from the law’s scope due to its open-source MIT and Apache licensing [1].

Sources


Digital Regulation Open Source