California’s legislature has passed Assembly Bill 1856, exempting: The wider industry impact

California's legislature has passed Assembly Bill 1856, exempting: The wider industry impact

Representative Image

California’s legislature has passed Assembly Bill 1856, exempting open-source operating systems from the state’s Digital Age Assurance Act. The California Senate amended and passed the bill this month in a 39-0 vote, and the Assembly accepted the changes in a concurrence vote soon after. AB 1856 has now been sent to Governor Gavin Newsom, who signed the original act into law last October.

The move comes months before the law is due to take effect on January 1, 2027. The amendment ends almost a year of uncertainty surrounding whether Linux distributions and SteamOS would be forced to collect user age data during account setup alongside Windows, macOS, iOS and Android.

Any software distributed under the GPL, MIT, BSD and Apache licenses satisfies that test, which removes the likes of Debian, Fedora, Ubuntu, Arch and the BSD family from AB 1856’s scope. Windows, macOS, iOS and Android remain fully in scope, with age collection required at account setup from January 1, 2027. A later July 1, 2027 deadline applies to devices set up before January 1.

The amendments redefine the term “operating system provider” to exclude any person or entity that distributes an OS or application “under license terms that permit a recipient to copy, redistribute, and modify the software. A second exclusion removes software components that aren’t “offered to consumers as a stand-alone executable application through a covered application store” from the law’s definition of an application, covering libraries and dependencies distributed through package managers like apt and pacman. The amendments to AB 1856 also remove the original definition of “user,” which read, “a child that is the primary user of a device,” and technically classified every device owner in California as a child.

A third carve-out excludes storefronts distributing extensions or add-ons that run exclusively inside a host application, which takes browser extension stores out of scope. Lawmakers also inserted a new provision prohibiting anyone from requesting an age signal from an OS provider or app store unless required by law. That closes off potential abuse of the age API that could have led to it being used as a general-purpose data collection channel even when age verification wasn’t required. Platforms and developers also gain a good-faith safe harbour against erroneous signals, protecting them from liability when age-gating signals are inaccurate.

Leave a Reply

Your email address will not be published. Required fields are marked *