415.tech
AI & tech, from the frontlines of Silicon Valley
California exempts open-source operating systems from its 2027 age-verification law

California exempts open-source operating systems from its 2027 age-verification law

California's legislature sent AB 1856 to Governor Newsom after 39-0 and unanimous concurrence votes, redefining 'operating system provider' to exclude anything shipped under license terms permitting copy, redistribution, and modification — which takes Debian, Fedora, Ubuntu, Arch, and the BSDs out of scope, along with libraries distributed via apt and pacman. Windows, macOS, iOS, and Android must still collect age at account setup from January 1, 2027 and expose an age bracket through a real-time API, so a developer targeting GPL, MIT, BSD, or Apache-licensed systems gets no age signal at all and has to design for its absence. A new provision also bars requesting an age signal unless the law requires it, closing the API as a general data-collection channel, and platforms get a good-faith safe harbor on inaccurate signals. SteamOS sits unresolved — Arch-based components are open source, but Valve ships the image with the proprietary Steam client.

Source: tomshardware.com

Post on XEmail

Any software distributed under the GPL, MIT, BSD, and Apache licenses satisfies that test, which removes the likes of Debian, Fedora, Ubuntu, Arch, and the BSD family from AB 1856's scope.

Tom's Hardware

Why this matters

  • → Open-source OS developers avoid compliance burden while proprietary platforms must implement age-collection in
  • → Creates legal incentive to adopt GPL/MIT/BSD/Apache licensed systems starting January 2027
  • → Closes loophole that could have turned age API into general surveillance channel
Open source gets a pass
Also in this edition