California Moves to Exempt Open-Source Software From Age-Verification Rules

Elayne Johnson  - VPNs Expert
Last updated: August 31, 2026
Human Written
Share
Radar Rundown
  • California lawmakers have unanimously voted to exempt Linux and other open-source software from the state’s upcoming age-verification law.

  • Software released under GPL, MIT, BSD, and Apache licenses will not need to build age-checking systems into their platforms.

  • Windows, macOS, iOS, and Android remain covered by the law, which takes effect in 2027.

California lawmakers have unanimously passed an exemption for Linux and open-source software. The exemption pulls them out of the state’s upcoming age-verification law.

If Governor Newsom signs the bill, popular Linux versions like Ubuntu, Debian, Fedora, and Arch will not need to add age-checking systems to their platforms.

The main law works by moving age checks away from websites. Instead, the device’s operating system handles it. When a user sets up their device, the system asks for their age. It then tells apps roughly how old the user is. The law is set to take effect in January 2027.

Why Linux got a pass

The original law created a serious problem for Linux. According to ArpokratLeg, Linux has no company behind it. Projects like Debian and Arch run on volunteer work. There is nobody to build an age system, nobody to sue, and no budget to fund it. The law made no room for that reality.

Lawmakers found a clean way to fix this. Instead of listing approved licenses by name, the bill says you are not an “operating system provider” if you distribute software that people can freely copy, change, and pass on. GPL, MIT, BSD, and Apache licenses all meet that test. None of them needed to be named directly in the bill.

As Pirat_Nation noted on X, software released under those licenses now qualifies for the exemption. Windows, macOS, iOS, and Android do not qualify. Those platforms still fall under the law.

One gray area involves SteamOS. Its Linux base is open-source, but Valve’s Steam software on top of it is not. According to Pirat_Nation, it remains unclear whether the full SteamOS package would qualify for the exemption.

The quieter win nobody talked about

The Linux exemption grabbed most of the headlines. But ArpokratLeg points out there was a second important change that got very little attention.

The same bill originally planned to extend age checks beyond operating systems and app stores. It would have pushed those checks into web browsers and websites too. That would have made age gates almost impossible for anyone to avoid online.

The Electronic Frontier Foundation, a US digital rights group, pushed back hard against that part of the bill. In July, lawmakers removed that expansion entirely. So the final result was actually two separate wins. The open-source carve-out received attention. The removal of the browser and website expansion mostly went unnoticed.

Mixed reactions online

Not everyone is celebrating. Thomas shared concern about the direction of the law overall, saying the exemptions are a sign of a slippery slope. His view is that age verification should not apply to any of these platforms at all.

MikeMumbelz took a more blunt approach, suggesting the exemption simply reflects a law that was never enforceable against open-source systems in the first place.

Dwinity pointed to Louisiana as an early example of where this kind of law leads. Louisiana already runs its version of age verification through LA Wallet, the state’s own ID app. The concern is that California’s system, with its open-source exit ramp written into a license file, may not be as clean in practice as it looks on paper.

What comes next

The bill now sits with Governor Newsom. His signature would make the exemption official. Until then, the status of Linux distributions under California’s age-verification law remains technically unresolved.

California’s data broker law has also entered a new enforcement phase, with the California Privacy Protection Agency already issuing fines against companies that failed to register or unlawfully required Californians to provide partial Social Security numbers to opt out of data sales. Data brokers that fail to process deletion requests through DROP face fines of $200 per deletion request, per day, for as long as the personal information remains undeleted.

For everyday users, the practical impact depends on which platform they use. Linux users, especially those on volunteer-run distributions, would face no new requirements under the exemption. Users on Windows, macOS, iOS, or Android would still encounter age-verification prompts when setting up their devices starting in 2027.

The broader debate around digital age verification, who enforces it, who builds it, and who pays for it, is far from settled. California’s approach may set a pattern that other states follow, or push back against, in the years ahead.

Share this article

About the Author

Elayne is a passionate tech blogger and digital security enthusiast. She has extraordinary writing and communication skills, assisting her in performing her tasks very well. She keeps educating herself about new trends in cybersecurity and educates others about it. Elayne loves learning about tech, VPNs, security, and online anonymity. In her free time, she enjoys trying new tech gadgets, watching movies, and using social media.

More from Elayne Johnson

Comments

No comments.