Copy, redistribute, and modify. Those three permissions, rather than the word "Linux," decide who escapes California's coming operating-system age-signal rules. Assembly Bill 1856 passed its final legislative vote 69-0 on August 27 after a 40-0 Senate vote, according to the state's official vote record. That makes the bill a practical licensing test for software distributors, not a named safe harbor for a particular kernel or community. It also leaves the much larger age-assurance system in place for commercial platforms.
The distinction matters to developers because the original Digital Age Assurance Act reaches below individual apps. Starting January 1, 2027, covered operating systems with an account-setup feature must ask an account holder for the primary user's age or birth date, place that user in an age bracket, and make the bracket available through a digital signal. AB 1856 removes many freely licensed systems from the definition of an operating system provider, but it does not repeal that architecture. The bill is now in the enrollment process and still needs action from Governor Gavin Newsom, as the legislative history shows.
The exemption is written as a permissions test
AB 1856 adds one sentence to California's definition of an operating system provider. A distributor falls outside that definition when its license terms let a recipient copy, redistribute, and modify the operating system or application. The enrolled bill text does not list the GPL, MIT, BSD, Apache, Linux, or any distribution by name. Coverage follows the legal permissions granted to recipients.
That approach should cover the mainstream free and open-source licenses commonly used by Linux distributions, which is why Tom's Hardware reported the vote as a Linux exemption. The statutory wording is more useful than a product list because distributions fork, repackage components, and change maintainers. A list of favored projects would age quickly. A license test can travel with the code.
The wording also creates a boundary that maintainers and lawyers will have to read carefully. An operating system can combine freely licensed code with proprietary stores, services, drivers, or media components. AB 1856 says the exemption applies to a person or entity that distributes an operating system or application under qualifying license terms. It does not explain in that sentence how California will assess a mixed distribution or which package defines the system for this purpose. The bill therefore supplies a clear rule for plainly open distributions and less certainty for products assembled from code under different terms. That uncertainty comes from the text itself; the final measure includes no product-specific examples.
Calling this a blanket exemption for all open source would also go too far. The operative definition concerns an "operating system provider." Elsewhere, the bill defines a developer as a person that owns an application or controls its hosting in a covered application store. It separately excludes software components that are not offered to consumers as standalone executable applications through such a store. Those definitions mean a project's role in distribution matters alongside its license, according to the Legislative Counsel's final text.
What the 2025 law still requires
Newsom signed AB 1043 in October 2025 as part of a package of child-safety measures. The governor's signing announcement described it as required age verification by operating-system and app-store providers. The statutory mechanism is more specific: the account holder supplies an age or birth date, and the system generates a bracket rather than handing every app a full birth date.
There are four minimum brackets: under 13, ages 13 through 15, ages 16 and 17, and 18 or older. Under AB 1856, a covered operating system must provide the signal to a covered application store or developer through a reasonably consistent real-time interface. An app store must request the signal from the operating system and pass it to a developer on request. Developers must request it when an application is downloaded and launched on a device. These duties appear in the current bill text, which amends the rules before they take effect.
Receiving a signal has a legal consequence beyond changing a user interface. A developer is deemed to have actual knowledge of the user's age range across covered points of access for that application. The developer generally must treat the signal as the primary age indicator, although internal clear and convincing information can replace it. Account information supplied for a child subaccount is one example the bill gives.
The law limits the data flow on paper. Operating systems may send only the minimum information necessary, and covered entities may not share the signal for unrelated purposes. AB 1856 also prohibits requesting an age signal when neither this law nor another applicable law requires it. Those restrictions narrow permitted use, but they still require covered systems and stores to create an age-data path that many community distributions do not currently operate.
Enforcement gives that path weight. A violation can bring an injunction and civil penalties of up to $2,500 per affected child for negligence or $7,500 per affected child for an intentional violation. Only California's attorney general may bring the civil action under this title. The bill retains a good-faith defense for an operating-system provider or application store when a signal is wrong or a developer mishandles it, provided the provider or store made a good-faith effort to comply.
Why open-source projects did not fit the model
The law assumes there is a provider that controls account setup, can add an age interface, and can maintain a real-time signal for applications. That maps readily onto a proprietary platform with a central vendor and app store. A community distribution may have several installation paths, no mandatory account, and no single entity controlling downstream copies. Anyone entitled to modify and redistribute the system can also remove a mandated interface from their own build.
The exemption acknowledges that mismatch without trying to make every volunteer maintainer part of an age-assurance service. It protects the development and distribution model by using the same freedoms that make forks possible as the legal dividing line. For maintainers, that avoids designing a California-specific setup flow, retaining user-supplied age data, or operating an API solely to satisfy a statute aimed at centralized consumer platforms. Those avoided tasks follow directly from the duties that no longer attach when the distributor is outside the provider definition.
The Electronic Frontier Foundation had criticized both the underlying law and an earlier AB 1856 proposal that would have extended the framework to browsers and websites. In July, the group said lawmakers had removed that expansion and retained the open-source exemption, so EFF withdrew its opposition to AB 1856. It did not endorse the 2025 law. EFF still argues that liability may push commercial providers toward document checks, biometric estimates, or other collection methods even though the statute speaks in terms of an age signal. That is an advocacy group's assessment, distinct from what the text expressly commands.
The vote fixed one implementation problem
AB 1856 began as a set of clarifications to the 2025 act. During the session it was amended six times, most recently in the Senate on August 21. The Senate passed that version without a recorded no vote on August 26, and the Assembly concurred the next day with 69 ayes, no noes, and 10 members not voting. Earlier versions had attracted dissent, including a 68-1 Assembly vote in May, so "unanimous" accurately describes the final floor approvals rather than every step in the bill's history.
The final version does more than add the licensing exemption. It says the account-setup duty applies when an operating system operates on a device and has an account-setup feature. It bars covered entities from prompting a user to change age information, limits unnecessary signal requests, and adjusts how a developer may rely on contrary account data. Devices set up before January 1, 2027 get a later deadline: a covered provider must make the age interface available by July 1, 2027.
Those details also explain why the exemption does not settle the policy debate. Proprietary desktop and mobile systems remain within the provider definition, along with covered app stores and developers. Californians using an exempt distribution may still encounter age-related rules inside services governed by other laws or by a provider's own policies. AB 1856 removes a state duty from qualifying operating-system distributors; it does not promise anonymous access to every app or website.
The next event is procedural but decisive: Newsom can sign or veto the enrolled measure. If it becomes law, implementation guidance and enforcement choices will determine how California treats mixed-license products and distributors that pair an open system with a closed store. Developers should also watch whether other jurisdictions copy the permission-based carve-out. The immediate deadline remains January 1, 2027, when the underlying age-signal duties are scheduled to begin for providers that stay inside the definition.