Skip to content

California Revises Age-Verification Law to Exempt Open-Source Linux

California Revises Age-Verification Law to Exempt Open-Source Linux

California lawmakers have approved changes to the state’s Digital Age Assurance Act that would exempt most Linux distributions and open-source software projects from age-verification requirements, while leaving major commercial operating systems subject to the law when it takes effect in 2027.

Bill 1856, passed by state lawmakers, introduces several amendments to the original Digital Age Assurance Act, often referred to as DAAA. Among the most notable changes is a new definition of an “operating system provider.” Under the bill, that term applies to a person or organization that develops, licenses, or otherwise controls an operating system product for computers, phones, or other general-purpose computing devices.

Bill 1856
Bill 1856

The bill also states that operating systems or software applications intended to be copied, redistributed, or modified don’t have “providers” under the legislation. As a result, those projects should not be required to verify users’ ages.

That carve-out means many popular Linux distributions used by consumers and enterprise organizations should now be exempt from the DAAA’s provisions. However, the exemption is not absolute. Some Linux-derived projects, such as SteamOS, may still be required to impose age verification on users. SteamOS is based on the Arch Linux project, but Valve provides its own official operating system images along with the proprietary Steam client, which could place it outside the open-source exemption.

Bill 1856 also provides other clarifications to the original law. The earlier version contained a badly mangled definition of a “user,” which essentially turned every Californian consumer into a child under the statute. Lawmakers have now added a prohibition against potential misuse of the “age signal” provided by an operating system. Under the revised law, operating system providers and app store owners will only be required to disclose a user’s age when law enforcement agencies or other state authorities request it.

The full DAAA package is set to take effect on January 1, 2027. While Linux distributions should be safe from the age-verification mandate, other commercial platforms such as Windows, Android, and iOS will be required to verify a user’s age during the operating system’s setup process. Devices configured before January 1 will have until July 1, 2027, to implement the new age check.

Age-verification requirements are growing in both scope and popularity, but they are also facing pushback. The Electronic Frontier Foundation has heavily criticized California’s DAAA, stating that the law will impose new and potentially unconstitutional barriers preventing adults and younger citizens from freely accessing information online.

Maybe you would like other interesting articles?

Leave a Reply

Your email address will not be published. Required fields are marked *