California Legislature Passes Amendment Keeping Operating System Age Signals

Browsers are out of the handoff, but app stores and developers still get a live read on user age categories.

A bill amending California’s Digital Age Assurance Act (DAAA), that opponents refer to more directly as a digital ID check bill, has passed in the state’s legislature and is now pending before Governor Gavin Newsom.

The original bill, AB 1043, was signed into law by Newsom last year, while this year’s amendment, AB 1856, was approved in the state Senate on August 26 with a vote that California’s official pages say was either 40-0 or 39-0 (the votes page lists 40, while the bill’s status page says 39), and then in the Assembly on August 27 with a 69-0 vote.

The California Legislature has amended a controversial age-verification law, removing some of its most onerous provisions and broadening the definition of operating systems that are exempt from the law.

However, the essence of the scheme – making operating systems a point of collection and real-time sharing of age data with app stores and developers – has been preserved.

But AB 1856 was changed in the process of making its way through the state’s Senate and Assembly, and is now free of some of the provisions that made the original bill highly controversial, including the requirement that browsers and websites participate in the scheme by collecting and passing on the age signal.

The final version of the bill does not contain these provisions, but it still requires operating systems to collect age or date of birth during setup, and provide a real-time signal to app stores and developers when another law requires age verification.

It appears to exempt many traditional open-source Linux distributions whose licenses allow users to copy, modify, and redistribute the software, and it no longer requires web browsers and websites to directly participate in transmitting age signals.

There are still privacy issues though. Covered, account-based operating systems can still be required to collect a user’s age or date of birth and make a real-time age-category signal available to app stores and developers, effectively turning the operating system into a centralized source of identity-related information.

This will be the case for operating systems that have an account setup feature, but AB 1856 also changed the definition of what an OS provider is by adding that the law does not apply to a person or entity that distributes an OS or app under license terms that allow recipients to copy, redistribute, and modify it.

This means that open source projects that use licenses such as those in the GNU family (like the GPL) are exempt from the bill’s provisions.

However, not every open source project uses such licenses, so it’s unclear at this point how many will qualify for the exemption.

For those that don’t, the law will apply as it originally did: the OS will have to make a signal available to app stores and developers, classifying users as under 13, 13-15, 16-17, and 18 and older.

As before, the law is justified as a way to protect children from harm online, while the privacy and other implications of making operating systems a source of real-time personal data for a wide range of third parties are ignored.

Those operating systems that are covered must support the age signal for new account setups by January 1, 2027, and for accounts created before 2027 by July 1, 2027. Developers must request the signal for new app downloads starting January 1, 2027, and for apps updated on or after January 1, 2026, by July 1, 2027.

The bill also narrows the definition of when a developer has “actual knowledge” of a user’s age to that user’s account and any associated account on an app or website owned or controlled by the developer, and accessed by the same app. This is a change from the previous version that said a developer who received the signal was automatically considered to have “actual knowledge” of a user’s age everywhere.

Other changes include the obligation of OS providers and app stores to apply the same rules to their own apps as to those of third parties, and to not use data collected from third parties to compete against them.

And while the bill removes browsers and websites from the equation, it does not remove the obligation of OS providers to support the age signal for app stores and developers.

The only good news in the bill is the exemption of some open source projects, but it’s an exemption that does not extend to users of proprietary, account-based systems, who will still be subjected to the privacy-invasive provisions of the law.