California’s Digital Age Assurance Law (AB 1043) sent shockwaves through the technology world when it was signed by Governor Gavin Newsom in October 2025. The law mandated that all operating system providers implement age verification APIs, collecting user age during account setup and categorizing users into four tiers: under 13, 13 to 15, 16 to 17, and 18 and older. The law’s broad definition of “OS provider” encompassed not only commercial giants like Microsoft, Apple, and Google, but also Linux distributions, SteamOS, and virtually any entity that develops, licenses, or manages operating system software. Noncompliance carried penalties of up to $7,500 per child. The open-source community erupted in protest, pointing out the fundamental impossibility of enforcing such a requirement on software that can be freely copied, modified, and redistributed by anyone anywhere in the world. Now, a proposed amendment known as AB 1856 seeks to carve out a critical exemption for open-source operating systems. This article examines the journey of AB 1856, what it means for Linux and the broader open-source ecosystem, and whether the amendment truly resolves the deep tensions between child safety regulation and software freedom.
AB 1043 and the Original Age Verification Mandate
AB 1043, formally titled the Digital Age Assurance Law, required all operating system providers to integrate age verification signals into their platforms. The law specified that during user account setup, the OS must collect age data and communicate it to application developers through a standardized API. The four age tiers were designed to allow apps to adjust content and features appropriately without requiring photo IDs or facial recognition. Users would simply self-declare their age. Assemblymember Buffy Wicks, who authored AB 1043, framed the law as a necessary measure to protect children online. However, the law’s definition of “OS provider” was sweeping: “a person or entity that develops, licenses, or manages operating system software on computers, mobile devices, and other general computing devices.” This language captured not only Windows, macOS, Android, and iOS, but also every Linux distribution, from Debian to Arch Linux, and even specialized variants like SteamOS.
The Open-Source Community’s Immediate Backlash
The Electronic Frontier Foundation (EFF) was among the first to condemn AB 1043, calling it an “Internet-wide age gateaaa” that would create a surveillance infrastructure for online identity tracking. The EFF argued that the law placed disproportionate burdens on smaller developers and non-commercial projects while doing little to actually protect children. The open-source community’s response was even more direct. The MidnightBSD project modified its license to prohibit use by California residents on desktop systems. A distribution called “Ageless Linux” emerged specifically to defy the law by omitting any age collection mechanism. GrapheneOS, a security-focused Android derivative, publicly stated it would refuse to comply, declaring, “If we can’t sell it in California, so be it.” The fundamental question became clear: how do you enforce state law on software that is developed by a global community of volunteers, distributed as ISO files from servers around the world, and licensed under terms that explicitly grant users the freedom to modify and redistribute the code?
AB 1856: The Amendment That Changes Everything
Recognizing the untenable position the original law created for open-source projects, Assemblymember Buffy Wicks herself introduced AB 1856 in February 2026. The amendment does not repeal AB 1043. Instead, it narrows the definition of who qualifies as an “OS provider.” The critical added clause reads: “‘OS provider’ shall not mean an individual or entity that distributes an operating system or application under license terms that permit the recipient to copy, redistribute, and modify the software.” This language directly targets the heart of open-source licensing. The GNU General Public License (GPL), the MIT License, and the Apache License all grant users the rights to copy, redistribute, and modify software. Under AB 1856, any operating system distributed under such terms would be exempt from the age verification mandate.
Application-Level Exemptions
AB 1856 also includes an exemption for software distributed outside of traditional app stores. The amendment states that “software components not offered to consumers as standalone executable applications through an application store” are excluded from the definition of covered applications. This language protects the vast ecosystem of software installed via package managers like apt, dnf, and pacman. When a user installs a program from the official repositories of a Linux distribution, that software is not being delivered through a commercial app store. It falls outside the law’s reach. This exemption is particularly important for the open-source community, where the primary distribution model is through centralized package repositories maintained by the distribution itself, not through storefronts like the Apple App Store or Google Play.
The Gray Area: Where SteamOS Fits In
While AB 1856 exempts the vast majority of Linux distributions, it leaves one notable player in a precarious position: Valve’s SteamOS. SteamOS is built on Linux and uses many open-source components. However, it ships with Valve’s proprietary Steam client and integrates directly with the Steam Store. From a regulatory perspective, SteamOS begins to resemble a commercial platform more than a community-driven distribution. It has a proprietary storefront, a corporate entity managing the operating system, and a clear commercial relationship with its users. The amendment’s exemption for open-source licensing would not automatically protect SteamOS because Valve controls the distribution and has not licensed SteamOS under terms that allow unrestricted copying, redistribution, and modification of the entire platform as delivered to consumers. If AB 1856 passes, Valve may be required to implement age verification APIs specifically for SteamOS users in California. The company already collects birth dates during Steam account registration, so the technical hurdle is not insurmountable. But the requirement to signal age at the OS level, rather than the application level, creates architectural complexities that Valve will need to address.
Timeline of California’s Age Verification Law
OS Type Comparison Under AB 1856
| Characteristic | Commercial OS | OSS Linux | SteamOS |
|---|---|---|---|
| Management Structure | Yes | No | Partial |
| App Store Included | Yes | No | Yes |
| Free Redistribution | No | Yes | Partial |
| Exemption Expected | No | Yes | Uncertain |
The table above illustrates the fundamental divide that AB 1856 creates. Commercial operating systems like Windows, macOS, iOS, and Android have centralized management, corporate legal departments, and distribution models that can feasibly implement age verification. They remain subject to the law. Open-source Linux distributions, which lack centralized control and are distributed under licenses that guarantee user freedom, are exempt. SteamOS sits in the middle, sharing characteristics of both categories. Its ultimate classification will depend on how the courts interpret the amendment’s language regarding “license terms that permit the recipient to copy, redistribute, and modify the software.”
What AB 1856 Does Not Fix
Even if AB 1856 passes, structural concerns about the underlying law remain. The EFF’s warning that age verification mandates create a surveillance infrastructure for online tracking is not addressed by the amendment. The law still requires commercial OS providers to collect and transmit age data, creating a system that could be expanded or abused in the future. Governor Newsom himself, when signing AB 1043, urged the legislature to amend the law before implementation, citing “the complexity of family account sharing and multi-device profile usage.” AB 1856 responds to the open-source exemption but not to the broader privacy and architectural concerns that the governor and civil liberties organizations have raised. The law’s fundamental approach of encoding age verification at the operating system level, rather than leaving content filtering to parents and application developers, remains controversial.
National Implications and the Colorado Parallel
California’s regulatory influence often extends beyond its borders, and AB 1856 is no exception. Colorado is currently advancing a similar OS age verification bill, and legislators there have begun incorporating open-source exemption language modeled on AB 1856. The California approach is becoming the template for how states attempt to reconcile child safety goals with the realities of open-source software. If AB 1856 passes, it will establish a legal precedent that open-source operating systems are fundamentally different from commercial platforms for regulatory purposes. This distinction could shape future laws not only in the United States but globally, as other jurisdictions look to California as a bellwether for technology regulation. The recognition that state law simply cannot apply to software developed and distributed by a global community of volunteers is a pragmatic concession, but it also raises questions about whether the law’s protections will apply unevenly depending on the underlying software model.
The Road Ahead for AB 1856
AB 1856 has advanced to third reading in the California Assembly, with committee review scheduled for June 2026. The path to passage appears increasingly clear, with broad recognition that the original law’s open-source problem needed a legislative fix. If enacted, the amendment would take effect before the January 1, 2027 implementation deadline, giving Linux distributions and the broader open-source ecosystem certainty that they will not be subject to age verification mandates. The bill’s progress reflects a rare moment of consensus: when the Assemblymember who authored the original law introduces an exemption for open-source, it signals that the original drafting was indeed overbroad. Wicks’s willingness to amend her own legislation acknowledges the fundamental incompatibility between traditional state regulation and software that can be infinitely forked, modified, and distributed by anyone with an internet connection.
The story of AB 1856 is ultimately a story about the limits of state power in the age of open-source software. California sought to protect children by requiring age verification at the operating system level, but discovered that the very nature of open-source development makes such mandates unenforceable. The exemption for Linux distributions is not a loophole or a compromise. It is an admission that some software simply cannot be regulated through traditional command-and-control legislation. The question that AB 1856 leaves unanswered is whether a law that exempts the most flexible and widely distributed operating systems can still achieve its stated goal of protecting children. The intersection of privacy, security, and software freedom will continue to evolve as AB 1856 moves toward passage and as other states consider similar legislation. California’s decision to exempt open-source operating systems from age verification may well become the defining precedent for how governments approach the regulation of software in a world where code knows no borders.