California moves to exempt Linux from its age-verification law after backlash
AIThis post was created with the assistance of artificial intelligence (AI).

TL;DR

Prime Big Deal Days · Oct 6–7Offer from Amazon

Get the latest gadgets delivered free — and shop member deals

  • Fast, free delivery on millions of items
  • Access to Prime Big Deal Days deals on October 6–7
  • Prime Video, Amazon Music and more included
Start your free Prime trial Free trial for eligible customers · Cancel anytime
As an affiliate, we earn on qualifying purchases.

California is considering an amendment to its Digital Age Assurance Act that would exempt most Linux distributions from age verification requirements. The move follows significant criticism from open-source advocates. The bill is currently under review and its final form remains uncertain.

California is moving to exempt most open-source Linux distributions from its upcoming Digital Age Assurance Act through a proposed legislative amendment, following widespread backlash from the open-source community and privacy advocates.

The amendment, introduced as part of Assembly Bill 1856 (AB 1856), aims to narrow the law’s scope by explicitly excluding software distributed under licenses that permit copying, redistribution, and modification. This would likely exempt mainstream Linux distributions such as Debian, Fedora, Ubuntu, Arch Linux, and Mint from the law’s requirements scheduled to take effect on January 1, 2027.

The original law, passed in late 2025 as AB 1043, mandated device-level age verification, requiring operating systems to request users’ birth dates and provide age brackets to apps and stores. Critics argued that this broad requirement could impact decentralized, community-maintained Linux systems, which lack centralized control and could be forced to implement invasive age verification features.

The proposed amendment was introduced by Assembly Member Buffy Wicks on February 11, 2026, and revisions including the open-source exemption language appeared in May 2026. As of May 19, 2026, the bill has been read a second time and sent for third reading, indicating ongoing legislative review.

Why It Matters

This development is significant because it indicates a potential shift in California’s approach to regulating digital age verification, particularly in relation to open-source software ecosystems. Exempting Linux distributions could prevent widespread disruption to open-source projects and avoid forcing community-maintained operating systems into invasive compliance measures. The move also highlights ongoing tensions between privacy advocates, open-source developers, and regulatory efforts to manage online age verification.

Amazon

Linux compatible privacy-focused operating system

As an affiliate, we earn on qualifying purchases.

As an affiliate, we earn on qualifying purchases.

Background

The California Digital Age Assurance Act was enacted in late 2025 to enhance online age verification at the operating system level, aiming to protect minors. However, the law’s broad language raised concerns because most Linux distributions are community-driven, open-source projects that lack centralized control. Critics argued that the law could impose compliance requirements on these projects, potentially forcing them to implement invasive age verification features or face legal consequences. The backlash prompted legislative revisions, including the current proposed exemption for open-source licenses.

“The amendment seeks to clarify that open-source Linux distributions are not subject to the same requirements as proprietary platforms.”

— California Assembly Member Buffy Wicks

“Broad age verification mandates risk invasive tracking and infringe on user privacy, especially for decentralized software projects.”

— Electronic Frontier Foundation

Amazon

open-source Linux distributions for privacy

As an affiliate, we earn on qualifying purchases.

As an affiliate, we earn on qualifying purchases.

What Remains Unclear

It is not yet clear whether the full legislature will approve the exemption language or if further revisions will be necessary. The final scope of the law, especially regarding proprietary platforms like SteamOS, remains uncertain, and enforcement details are still being worked out.

Amazon

Linux OS for secure online browsing

As an affiliate, we earn on qualifying purchases.

As an affiliate, we earn on qualifying purchases.

What’s Next

The bill is currently under review, with a third reading expected in the coming weeks. Legislative votes and potential amendments will determine whether the open-source exemption is adopted. If approved, the law’s implementation could be significantly limited for Linux distributions, while proprietary platforms may still be subject to the original requirements.

Amazon

Linux distributions for developers

As an affiliate, we earn on qualifying purchases.

As an affiliate, we earn on qualifying purchases.

Key Questions

Will all Linux distributions be exempt from the law?

If the proposed amendment passes as currently drafted, most Linux distributions distributed under licenses permitting copying, redistribution, and modification will be exempt from the age verification requirements.

Does this mean the law is being repealed?

No, the law itself (AB 1043) is not being repealed. The amendment seeks to clarify and narrow its scope, particularly concerning open-source software.

What about proprietary platforms like SteamOS?

Proprietary platforms with closed ecosystems, such as SteamOS, may still be subject to the original age-verification requirements unless further legislative changes occur.

When will the final version of the law be enacted?

The bill is still under review, with legislative approval expected in the upcoming sessions. The scheduled enforcement date remains January 1, 2027.

Source: Hacker News

FALL

Fall Picks

As an affiliate, we earn on qualifying purchases.

You May Also Like

Data Privacy Day 2026: Why Protecting Personal Data Matters

Because your personal data can be vulnerable in numerous ways, understanding why protecting it on Data Privacy Day 2026 is crucial will…

What a Blue Team Does Inside an Organization

I explore how the Blue Team defends organizations from cyber threats and the crucial role they play in maintaining security.

unable to connect to wallet services

Major wallet services are currently unavailable, affecting users’ ability to connect to digital wallets and payment platforms. The cause is under investigation.

Postmortem: TanStack npm supply-chain compromise

An attacker compromised 42 TanStack npm packages on May 11, 2026, deploying malicious code via GitHub Actions and cache poisoning. No npm credentials were stolen.