California passes Linux exemption from age law


Featured image California passes Linux exemption from age law

In a major victory for digital freedom, California’s legislature has carved out a significant exemption for open-source operating systems, ensuring that the digital age assurance laws will not force these systems to collect sensitive user age data. This move arrives months ahead of the law’s scheduled implementation on January 1, 2027, ending a lengthy period of uncertainty for developers and users alike.

The legislative maneuver involved amendments to Assembly Bill 1856, which successfully redefined the terms of the law. By redefining “operating system provider,” lawmakers excluded entities that distribute software under licenses that permit recipients to copy, redistribute, and modify the code. This crucial change immediately removes major open-source players, such as Debian, Fedora, Ubuntu, Arch, and the BSD family, from the scope of the age-verification requirements.

Beyond the operating system layer, the bill addressed how age verification is applied to the broader application ecosystem. It also extended this protection to software components distributed through standard package managers like apt and pacman, ensuring that the machinery of open-source development remains free from unnecessary data collection mandates.

The changes also extended relief into the distribution layer, carving out exceptions for storefronts that distribute extensions or add-ons running within a host application. This effectively removes browser extension stores from the direct scope of the age-gating rules, protecting user privacy within their chosen applications.

Perhaps the most transformative change involved redefining the very concept of a “user.” The original law had classified every device owner in California as a child, creating a confusing and technically impossible framework for adult age declarations. The amendments removed this restrictive definition, setting the stage for a framework where age signaling relies on adults declaring their age during account setup, rather than automatically classifying all device owners as minors.

To prevent potential misuse of age data, lawmakers inserted a strict new provision. This provision prohibits any entity from requesting an age signal from an operating system provider or app store unless explicitly required by law. This acts as a vital safeguard, closing off the door on potential abuse of the age API and offering a good-faith safe harbor to platforms and developers against liability should age-gating signals prove inaccurate.

While major commercial operating systems—Windows, macOS, iOS, and Android—remain fully within the scope of the law, the exemption provides substantial relief for the vast world of open-source software. Systems like GrapheneOS, which operates under open-source MIT and Apache licenses, are now entirely outside the law’s scope, providing further protection for privacy-focused development.

This proactive legislative action, championed by Assemblymember Buffy Wicks, demonstrates a commitment to balancing digital safety with the principles of open-source innovation. The successful passage of these amendments ensures that the push for age verification does not come at the cost of stifling the creative and free spirit of open-source development in California.

You may also like: