Linux avoids age verification but SteamOS is in danger
The Great Age Verification Shuffle: How California Law Tussled with Open Source
A sweeping new mandate is coming for the digital world: California’s Digital Age Assurance Act is set to bring mandatory age verification checks to the forefront of operating system setup, slated to take effect at the start of 2027. This move forces system providers to implement checks to lock down certain functions, sparking immediate and intense debate, particularly within the open-source community.
The potential implications were felt strongly by Linux developers, who had already voiced concerns over how such measures might impact the philosophy of free and open software. Fortunately, legislators recognized the potential for disruption and quickly moved to ensure the ecosystem could continue to thrive.
The good news arrived swiftly in the form of Assembly Bill 1856, an amendment that passed with a decisive 39-0 vote. This amendment grants an exemption to open-source operating systems, ensuring that software distributed under licenses like GPL, MIT, and BSD are released from the direct compliance requirements of the age verification law.
The legal loophole itself is quite clever. The amendment specifically defines who is considered an “operating system provider” in a way that excludes entities that permit recipients to copy, redistribute, and modify the software. This technical distinction allows users of open-source code to proceed without age verification, safeguarding the principles of open source in the state.
Beyond the technical exemption, the law also attempts to temper the power of these providers. It mandates that OS providers can only acquire the “minimum amount of information necessary” to comply with age checks. This is a crucial safeguard, designed to prevent providers from accumulating unnecessary data or engaging in unwarranted surveillance under the guise of age verification.
While Linux distributions enjoy this protection, the legal landscape remains complex for proprietary systems. Operating systems like Windows, Android, macOS, and iOS are directly affected, and even systems built upon Linux, such as Valve’s SteamOS, face nuanced application of these rules, particularly when accessing specific game functions.
The rollout of age checks is not an isolated event. The past few years have seen a continuous push for digital age verification, seen in various platforms. For instance, Discord proactively rolled out checks but clarified that they already possess the necessary age group information, avoiding the need for intrusive face scans or ID uploads. This move, coupled with the background ties between platform development and surveillance architecture, has fueled widespread cynicism about centralized digital age checks.
The sentiment is amplified by global regulatory shifts, such as the UK’s Online Safety Act, which also imposed age verification requirements on certain services. As the user base for open-source systems continues to expand—often in reaction to failures in proprietary systems—the ability to navigate these digital checks becomes increasingly important. The question remains: as the digital age matures, how will the balance between user safety, provider compliance, and the freedom of open source truly be defined?