Assembly Bill 1856 (AB 1856), currently moving through California’s legislature ahead of committee reviews in June, would amend the state’s earlier age-assurance law by excluding software distributed under licenses that allow users to “copy, redistribute, and modify the software.”
The amendment follows months of backlash after California passed the original Assembly Bill 1043 (AB 1043), formally known as the Digital Age Assurance Act, in late 2025. The law sought to shift online age verification away from individual websites and apps and down to the operating-system level instead.
Under the original law, operating systems would be required to request a user’s age or birth date during device setup, then expose an “age bracket signal” to apps and app stores. The law, which defined brackets such as “under 13,” “13–15,” “16–17,” and “18+,” immediately raised questions about how such requirements would apply to decentralized, open-source software ecosystems.
Unlike Apple’s iOS or Google’s Android, most Linux distributions are not centrally controlled commercial platforms. Many are community-run projects maintained by volunteers, often without user accounts, telemetry systems, or even formal corporate ownership structures. Critics argued the law’s wording was so broad that it could technically force open-source operating systems to become age-verification platforms.
Privacy advocates, including the Electronic Frontier Foundation, criticized the legislation as invasive and warned it could create infrastructure for broader identity tracking online. Linux developers also questioned how California could realistically enforce such requirements on infinitely forkable open-source software projects.
The controversy became particularly heated after reports suggested platforms like SteamOS could still fall under the law due to their ties to proprietary application ecosystems. Valve
AB 1856 does not repeal the original Digital Age Assurance Act. Instead, it narrows the definition of who qualifies as an “operating system provider” under the law. Commercial platforms with proprietary app ecosystems could remain subject to California’s age-assurance requirements even if most open-source Linux distributions are ultimately exempted.
California Assembly Member Buffy Wicks introduced the amendment on February 11, 2026. However, the open-source exemption language appeared in later revisions that began drawing attention across Linux and privacy communities. The latest version is dated May 18, 2026, and as of May 19, 2026, the bill was read a second time and ordered to third reading.
(Score: 1, Offtopic) by VLM on Thursday May 28, @05:51PM (1 child)
I don't think anything on my media center has a valid rating/age coding. Emby is just direct streaming a sequence of bytes from an officially unknown source to my Roku streamer boxes. The Roku's are not FOSS and you need a credit card to buy one and install the emby app from their app store. Similar to how my OPNsense firewall doesn't do deep packet inspection of user age, the emby streamer doesn't care, feed it a file and it slowly squirts it out to a streamer hardware device like a Roku.
A fair number of video files can't ever have a legal rating applied to them. "grandma's 80th birthday party.mp4" and "kids little league season 2007.mp4" and similar home movie stuff. Yeah sure by percentage the files are mostly "yo ho ho and a bottle of rum" but those guys have nothing to gain from distributing age-locked files either.
This would make things weird for SteamOS I'd agree with that. But they're not a FOSS org, its an entirely non-FOSS ecosystem with entirely non-FOSS problems.
(Score: 1, Insightful) by Anonymous Coward on Thursday May 28, @09:27PM
The problem is the obvious next step is the banning of media without the age verification. You're saying it will only control stuff that is flagged as over PG13, but it's much more likely to be implemented as requiring default deny, not default allow.