
California lawmakers have passed AB 1856, a bill that would exclude qualifying open-source software distributors from being treated as operating system providers under the state’s upcoming Digital Age Assurance Act (DAAA).
The measure passed the Senate 39–0 on August 26, and the Assembly concurred with the Senate amendments 69–0 the following day, but still requires Governor Gavin Newsom’s signature before becoming law.
Assembly member Buffy Wicks, who authored both the DAAA and AB 1856, introduced the amendment bill on February 11, 2026, following concerns from Linux developers and the Electronic Frontier Foundation over how the age-signaling requirements could apply to open-source operating systems.
AB 1856 does not mention Linux or software licenses such as GPL, MIT, BSD, or Apache by name. Instead, it changes the definition of an “operating system provider” to exclude a person or entity that distributes an operating system or application under license terms allowing recipients to “copy, redistribute, and modify” the software.
In practice, that language would appear to remove conventional open-source Linux and BSD distributions, including projects such as Debian, Fedora, Ubuntu, Arch Linux, and GrapheneOS, from the operating-system-provider requirements. These projects distribute operating-system software under licenses that generally grant users broad rights to inspect, modify, and redistribute the source code, unlike proprietary platforms such as Windows, macOS, iOS, and Android.
The distinction is important because the DAAA, scheduled to take effect on January 1, 2027, requires covered operating system providers with an account-setup feature to collect a user’s birth date, age, or both. The platform must then make an age-bracket signal available through an API, indicating whether the user is under 13, 13–15, 16–17, or at least 18.
AB 1856 also narrows what qualifies as an application. Software components that are not distributed as standalone executable applications through a covered app store are excluded, which could keep libraries and dependencies delivered through package managers such as apt and pacman outside the law’s application-level requirements. Stores distributing extensions, plug-ins, and add-ons that operate exclusively inside another application are also excluded.
Another amendment deletes the DAAA’s existing definition of “user” as “a child that is the primary user of a device,” wording that conflicted with the law’s requirement to distinguish adult users from minors.
The bill additionally prohibits companies from requesting an age signal unless required by the DAAA or another law, limiting the API’s potential use as a broader data-collection mechanism. Good-faith protections would also shield operating system providers, app stores, and developers from liability when an age signal is erroneous.
Proprietary platforms that remain covered would have to begin collecting age information during account setup on January 1, 2027, while qualifying older devices must receive an age-entry interface by July 1, 2027. Penalties can reach $2,500 per affected child for negligent violations and $7,500 for intentional violations.
The position of mixed systems such as Valve’s SteamOS is less clear because its Arch Linux-based operating system contains open-source components but is distributed alongside proprietary software. The final scope will depend on how the statutory definitions are applied if AB 1856 is signed into law.





Leave a Reply