Skip to content
Tech News
← Back to articles

California exempts Linux and open-source software from new age verification law

read original more articles
Why This Matters

California's recent legislative amendments exempt Linux and open-source software from its new age verification law, reducing regulatory burdens on these projects and safeguarding their open-source nature. This change highlights the importance of clear legal definitions for open-source projects and their users' privacy. It also underscores ongoing efforts to balance consumer protection with innovation and open access in the tech industry.

Key Takeaways

Recap: California will require software vendors to verify users' ages at the operating system level in the coming months. Thanks to the latest changes approved by the state's Assembly, the new draconian requirements will not apply to software projects designed to be modified or copied.

For the time being, Linux and other open-source software projects are safe from California's upcoming age-verification law. State lawmakers recently passed Bill 1856, which introduces several significant amendments to the original Digital Age Assurance Act (DAAA) and its age-verification requirements.

Bill 1856 defines an "operating system provider" as a person or organization that develops, licenses, or otherwise controls an OS product for computers, phones, or other general-purpose computing devices. The law also states that operating systems or software applications intended to be copied, redistributed, or modified do not have "providers" under the legislation and therefore should not be required to verify users' ages.

Many popular OS projects, including Linux distributions used by both consumers and enterprise organizations, should now be exempt from the DAAA's provisions. However, some Linux-derived projects, such as SteamOS, might still be forced to impose age verification on their users. The gaming-focused operating system is based on the Arch Linux project, but Valve provides its own "official" OS images along with a proprietary Steam client.

Bill 1856 provides other important clarifications to the DAAA. The original law contained a badly mangled definition of a "user," essentially turning every Californian consumer into a child. Lawmakers have also added a new prohibition against potential misuse of the "age signal" provided by an operating system. Under the revised law, OS providers and app store owners will only be required to disclose a user's age when law enforcement agencies or other state authorities request it.

The full DAAA package will take effect on January 1, 2027. While Linux distros should be safe, other commercial platforms such as Windows, Android, and iOS will be required to verify a user's age during the operating system's setup process. Furthermore, devices configured before January 1 will have until July 1, 2027, to implement the new age check.

Age-verification requirements are growing in both scope and popularity, but some users are fighting the new rules. The Electronic Frontier Foundation has heavily criticized California's DAAA, stating that the law will impose new and potentially unconstitutional barriers preventing adults and younger citizens from freely accessing information online.