A Carve-Out the Bill's Own Author Wrote

On 26 August 2026, California's Senate voted 39-0 to exempt Linux, the BSDs, and every other permissively-licensed operating system from the state's new age-verification law, and the Assembly accepted the change the next day.

The amendment, Assembly Bill 1856, rewrites a single definition inside AB 1043, the Digital Age Assurance Act that Governor Newsom signed in October 2025. Under the original text, any operating system provider would have to collect an age signal from every user during device setup, starting 1 January 2027, and pass an age-bracket flag down to every app installed on that device. AB 1856 adds one exclusion: a person or entity does not count as an operating system provider if the software is distributed under a license that lets anyone copy, redistribute, and modify it.

That single clause reaches Debian, Fedora, Ubuntu, Arch Linux, and Linux Mint, along with FreeBSD and OpenBSD. Windows, macOS, iOS, and Android keep the full duty, because Microsoft, Apple, and Google distribute them under licenses that grant none of those rights.

The amendment's author is Assemblymember Buffy Wicks, the same lawmaker who wrote AB 1043 in the first place.

What Changes on 1 January 2027

The table below is the plain difference the amendment makes, by operating system category, once the underlying law takes effect.

Operating systemLicense modelDuty from 1 January 2027
Windows, macOS, iOS, AndroidProprietary, single-vendor controlledCollect an age signal at setup and pass an age-bracket flag to every app
Debian, Fedora, Ubuntu, Arch Linux, Linux MintGPL, MIT, BSD, or Apache-style licenseExempt under AB 1856
FreeBSD, OpenBSD, and other BSD-licensed systemsBSD licenseExempt under AB 1856

Nothing else in AB 1043 moves. Apps that are themselves age-restricted, in an app store or on the open web, keep whatever separate age-verification duty already applies to them regardless of which operating system they happen to run on.

The date that matters is still 1 January 2027, when the underlying collection-and-signal duty activates for everyone left inside its scope.

Why an Unenforceable Duty Got Written Anyway

The original duty assumed there is always a company on the other end of an operating system, one with a name, an address, and a legal team that a regulator can reach.

That assumption holds for Windows, macOS, iOS, and Android. It does not hold for a Linux distribution that a nonprofit foundation, a volunteer maintainer group, or nobody in particular ships, and it does not hold at all for a fork someone builds from source over a weekend. A duty to collect and transmit an age signal has to attach to somebody who can be fined for skipping it, and open-source operating systems were built, deliberately, so that no single party has to be that somebody.

Wicks did not have to write the carve-out. She had already passed a law with real momentum behind it, backed by child-safety advocates who wanted age checks to move up from the app layer, where self-declaration is easy to fake, to the operating system, where a check happens once and travels everywhere. Open-source maintainers raised a narrower problem: the mechanism could not physically attach to software that no single company controls, and a law that ends up criminalizing the act of distributing a modified operating system is a much bigger fight than anyone in Sacramento intended to start.

Nine to zero in the Senate suggests nobody in Sacramento wanted that fight either.

The Gap Underneath the UK and EU Versions

Neither the UK nor the EU has written this exemption yet, and both are building age-verification systems on the same assumption California just abandoned.

Ofcom's guidance under the UK's Online Safety Act pushes age checks up to the operating system layer on purpose, so that no individual app can dodge the gate: the OS attests to an age range once, and every app inherits it. Windows 11, macOS Sequoia, iPadOS 18, and most current Android builds already tie some features to that kind of identity-backed age check. The guidance assumes, the same way California's original law did, that there is an accountable vendor on the other end of the operating system.

The European Commission is pushing a different but related design: a standalone age-verification app, built to plug into national digital identity wallets, that France, Denmark, Greece, Italy, Spain, Cyprus, and Ireland are piloting ahead of a Commission-recommended rollout by the end of 2026. That model leans on national wallet operators rather than a single OS vendor, but it still needs an accountable party running the app and the wallet, which is exactly the role that does not exist for a Linux distribution nobody in particular controls.

Any business in the EU or UK shipping Linux-based devices, from routers and network-attached storage to developer laptops and point-of-sale terminals, is currently sitting on the same gap California just legislated its way around. Whether Westminster or Brussels ends up writing the same carve-out, or instead tries to regulate distribution and forking directly, will decide how far an age-verification duty can reach into software that nobody owns.

We do this for everyone trying to keep up with what technology is doing to our lives. The people who build it, and the people it happens to. The Servola Journal exists so that what we learn belongs to all of them.

Nobody pays us for this. No ads, no paywall, free to everyone. We just believe that understanding what's happening to all of us shouldn't depend on who can afford to pay for it.

If it gave you something today, tell us to keep going. Follow us, leave a like, or write a positive comment. We read every one, and they are what keeps us going.