INFRA Signal 598 2 feeds carried it
California exempts GPL, MIT, BSD, and Apache-licensed software from age-verification law
California’s Assembly Bill 1856 carves out open-source operating systems and components from the state’s upcoming age-verification requirements.
The exemption removes a compliance burden for open-source projects and package managers that would have required age data collection. It also sets a precedent for how open-source software is treated under age-verification laws, contrasting with proprietary platforms still subject to the rules.
Written by elseif from the cluster below · every claim links back to a sourceThe three things worth knowing
Open-source OS distributions like Debian, Fedora, and Ubuntu are now exempt from California’s age-verification law.
Libraries and dependencies distributed via package managers are excluded from the law’s scope.
Proprietary platforms like Windows, macOS, iOS, and Android remain subject to the age-verification requirements.
THE READ
What the cluster adds up to.
California’s Assembly Bill 1856 amends the state’s Digital Age Assurance Act to exclude software distributed under open-source licenses like GPL, MIT, BSD, and Apache. This change means Linux distributions, BSD variants, and other open-source operating systems no longer need to implement age-verification mechanisms during account setup. The exemption applies to any software where the license permits copying, redistribution, and modification, which covers most major open-source projects. The law’s original scope would have required these projects to collect and transmit age data, creating technical and logistical challenges for community-driven development models.
The exemption also extends to software components distributed through package managers like apt and pacman. These tools are not classified as “covered application stores” under the law, so libraries and dependencies remain outside its requirements. This avoids a scenario where package maintainers would need to integrate age-verification APIs, which would complicate dependency management and slow down updates. The law’s signaling framework relies on OS providers transmitting age data to app stores, but open-source OS providers are now exempt from generating or transmitting such signals. This reduces the risk of unintended data collection or misuse of the age-verification system.
Proprietary platforms like Windows, macOS, iOS, and Android remain fully subject to the law, with age verification required at account setup starting January 1, 2027. The law includes a safe harbor provision protecting platforms and developers from liability if age signals are inaccurate, but this does not apply to open-source projects since they are no longer required to generate signals. The exemption also raises questions about hybrid systems like SteamOS, where open-source components coexist with proprietary software. While the Arch-based system components are exempt, Valve’s proprietary Steam client may still fall under the law’s scope, leaving ambiguity for such cases.
The amendments address earlier concerns about the law’s broad definition of “user,” which initially classified all device owners as children. This would have made it impossible for adults to declare their age, breaking the law’s signaling framework. The new language ensures that adults can self-declare their age, allowing the system to function as intended. Additionally, the law now prohibits requesting age signals unless legally required, preventing potential abuse of the API for unrelated data collection. This change reflects feedback from developers and advocacy groups, who argued that the original law would impose unnecessary burdens on open-source projects without improving child safety.
Written by elseif from the cluster below · checked for specifics the sources never containedTHE CLUSTER
↗