California lawmakers have exempted open-source operating systems and software from the state’s upcoming age-verification law, protecting Linux, BSD and their wider software ecosystems.
California lawmakers have unanimously passed Assembly Bill 1856 (AB 1856), explicitly exempting open-source operating systems from the state’s Digital Age Assurance Act, which takes effect on January 1, 2027.
The amendment removes open-source software from the law’s definition of an “operating system provider” when it is distributed under licences that allow recipients to copy, redistribute and modify it. Software released under the GPL, MIT, BSD and Apache licences therefore qualifies, putting Debian, Fedora, Ubuntu, Arch and BSD variants outside the law’s scope.
The California Senate passed the amended bill 39-0 on August 26, after amendments on August 21. The Assembly accepted the changes on August 27, and the bill has now been sent to Governor Gavin Newsom.
The exemption resolves months of uncertainty over whether Linux distributions would have to collect users’ ages during account setup. It also excludes libraries and dependencies distributed through package managers such as apt and pacman, provided they are not standalone applications offered through covered app stores.
GrapheneOS, distributed under MIT and Apache licences, is also outside the law’s scope. SteamOS remains uncertain because Valve distributes its open-source Arch-based components alongside the proprietary Steam client.
Windows, macOS, iOS and Android remain covered, with age collection required from January 1, 2027. The amended law also bars unnecessary requests for age signals and provides a good-faith safe harbour for inaccurate signals.
Assemblymember Buffy Wicks introduced the Linux exemption in February following criticism from Linux developers and the Electronic Frontier Foundation.
















































































