California's legislature has unanimously passed Assembly Bill 1856, a measure that exempts open-source operating systems distributed under licenses like the GPL, MIT, BSD, and Apache from the state's upcoming Digital Age Assurance Act. The exemption means Linux distributions, and other software released under those open licenses, will not be required to collect or verify users' ages the way commercial operating systems will.

The unanimous vote is notable given how contentious age-verification legislation has become nationwide. It also raises a practical question that lawmakers appear to have grappled with directly: how do you enforce an age-verification mandate on software that anyone can freely copy, modify, and redistribute?

What AB 1856 Actually Exempts

The Digital Age Assurance Act, as originally conceived, would have required operating systems sold or distributed in California to verify a user's age, likely during account setup or initial device configuration. AB 1856 carves out an exception for operating systems distributed under recognized open-source licenses, meaning Linux distributions such as Debian, Fedora, Arch, and others that ship under the GPL, MIT, BSD, or Apache frameworks fall outside the law's reach.

This isn't the first adjustment to California's age-verification push. As covered in our earlier report on how AB 1856 dropped its browser rule while AB 1043's OS-level age checks stayed intact, lawmakers have been narrowing the scope of these bills in response to pushback from developers, civil liberties groups, and the tech industry. The Linux exemption is the latest example of that recalibration, but it doesn't eliminate OS-level age verification altogether. Commercial and closed-source operating systems, the ones most consumers actually use day to day, remain subject to the requirements under AB 1043.

Why Lawmakers Carved Out Open Source

The practical case for exempting open-source software is straightforward. Once code is released under a permissive or copyleft license, it can be forked, rebranded, and redistributed by anyone, anywhere, with no central company to hold accountable. There's no single entity to fine or sue if a Linux distribution doesn't implement age verification, because there's no single entity in control of Linux the way there is with Windows or macOS.

That structural reality made a blanket mandate on open-source software nearly impossible to enforce. A hobbyist maintaining a niche distribution, or a developer building a custom Linux image for a specific use case, would have faced compliance obligations designed for large corporations with legal and engineering resources to spare. Exempting these projects avoids putting volunteer maintainers and small open-source communities in legal jeopardy for something they have no realistic way to comply with.

Privacy Implications: Who's Still On the Hook

For privacy-conscious users, the exemption is a meaningful, if narrow, win. Linux users will not have their age collected or verified at the operating system level, preserving one of the platform's longstanding appeals: the ability to use a computer without handing over identifying information just to boot it up.

But the carve-out doesn't change the picture for the vast majority of internet users, since most people run commercial operating systems that still fall under age-verification requirements. That leaves privacy advocates watching closely for how those OS-level checks are implemented and what data gets collected, stored, and potentially shared in the process. Age-verification schemes have already drawn scrutiny at the federal level too. Senator Andy Kim's proposed Digital Age Assurance Act shifts verification responsibility to app stores, reflecting a broader trend of pushing age checks further up the software stack, closer to the platforms and operating systems people rely on daily.

It's also worth noting that California isn't acting in isolation. Age-verification mandates have been advancing in dozens of states, often traced back to advocacy groups with roots in the UK's Online Safety Act. That broader legislative momentum means the Linux exemption, while a relief for open-source users, is unlikely to signal a slowdown in age-verification efforts more generally.

What This Means For You

If you run a Linux distribution or other open-source operating system, AB 1856 means you won't be asked to verify your age just to use your device, at least under this specific California law. That's a genuine privacy benefit worth appreciating, especially for anyone who chose open-source software partly to avoid the data collection practices common on commercial platforms.

If you use Windows, macOS, or another closed-source, commercial operating system, the exemption doesn't apply to you. You should expect age-verification requirements to roll out under AB 1043 and similar laws, and it's worth paying attention to how those systems handle your data: what's collected, how long it's retained, and whether it's shared with third parties. Age-verification technology varies widely in how privacy-respecting it is, and not all implementations are created equal.

Key Takeaways

California's AB 1856 exempts open-source operating systems distributed under the GPL, MIT, BSD, and Apache licenses from the state's Digital Age Assurance Act, largely because enforcing age checks on freely forkable software proved impractical. The unanimous vote reflects a pragmatic compromise rather than a retreat from age verification broadly, since commercial operating systems remain subject to similar mandates under AB 1043. For Linux users, this is a clear privacy win. For everyone else, the age-verification landscape is still evolving, and staying informed about how these laws are implemented at the operating system level remains the best way to protect your privacy going forward.