KontorBund — Note
Age checks move into the operating systemLast checked 4 October 2026
kontorbund.com/notes/os-age-verification.html
Age checks move into the operating system: California, Colorado, Brazil — and the problem for Linux
The short version
Age rules are moving off websites and into the operating system. In the United States, California requires an operating system to ask for the user's birth date, age or age bracket at account setup and to hand that bracket to apps as a signal — from 1 January 2027, as amended by AB 1856 (Chapter 184, signed 10 September 2026). Colorado copied the model in SB26-051, with duties from 1 July 2028. Brazil is already there: age assessment by app stores and operating systems has been required since 17 March 2026. Two of the three expressly exempt open-source operating systems; Brazil as far as we can see does not. None of this is EU law, and no EU measure requiring an age check in an operating system exists today — the EU Kids Act is still a proposal.
The shape of the duty
Three documents, three countries, one model. The building blocks are the same in all of them, and they are worth naming once, because the words are used loosely everywhere else:
- An age declared at account setup
- The account holder — an adult, or a parent on behalf of a child — says how old the user is, or which bracket they fall into. This is attestation: nobody checks a document.
- An age bracket, not a birthday
- The bands are the same on both sides of the Atlantic: under 13, 13 to 15, 16 and 17, 18 and over. California and Colorado write them out in almost identical words.
- A signal to apps
- The operating system (and the app store) exposes the bracket over a real-time programming interface, so an app can ask "is this user a minor?" without ever seeing a date of birth.
- Data minimisation with teeth
- California and Colorado both cap what may be collected, and both forbid passing the signal on for a purpose the law does not require.
- Who pays
- In both US states, the operating system provider and the app store — with a civil penalty per affected child, recoverable by the state attorney general. In Brazil, the regulator is the data protection authority.
California — from 1 January 2027
California did it first. The Digital Age Assurance Act (AB 1043, 2025) added Title 1.81.48 to the Civil Code and takes effect on 1 January 2027. AB 1856, by Assemblymember Buffy Wicks, amended it: it was approved by the Governor and filed with the Secretary of State on 10 September 2026 as Chapter 184, and covers §§ 1798.500–1798.504.
- What the operating system must do
- If an operating system runs on a device and has an account setup feature, the provider must offer an accessible interface at account setup that requires the account holder to indicate the birth date, age, or both, of the primary user — so that a signal about that user's age bracket can go to a covered app store and to developers (§ 1798.501(a)(1)).
- The brackets
- Under 13; at least 13 and under 16; at least 16 and under 18; at least 18 (§ 1798.500(b)). The signal must identify at least one of those categories over a reasonably consistent real-time interface (§ 1798.501(a)(2)).
- What app stores must do
- Request the signal from the user's operating system provider and pass it to a developer on request (§ 1798.501(c)).
- What developers must do
- Ask for a signal when the app is downloaded and launched on a device, and treat it as the user's age — a developer that receives a signal is deemed to have actual knowledge of the age range, even if it willfully disregards the signal (§ 1798.501(d)). A developer may not prompt the user to change their age information, may not ask for more than the minimum, and may not pass the signal on.
- Devices that already exist
- For accounts set up before 1 January 2027 the interface must be offered before 1 July 2027, and apps last updated on or after 1 January 2026 must request a signal by the same date (§ 1798.502).
- Enforcement
- Injunction plus a civil penalty of up to $2,500 per affected child for each negligent violation and up to $7,500 per affected child for each intentional one, recoverable only in a civil action brought by the Attorney General (§ 1798.503(a)). A good-faith effort, given available technology and reasonable technical limits, removes liability for an erroneous signal.
- Who is out of scope
- Broadband internet access services, telecommunications services, the delivery or use of a physical product — and app stores that only distribute extensions, plug-ins or add-ons that run exclusively inside another application (§§ 1798.500(e)(2), 1798.504(f)).
The open-source carve-out is in the definition, and it is the point everyone under the age of forty will care about:
California's law is titled "age verification signals", but the mechanism in the text is a declaration by the account holder. The Electronic Frontier Foundation, which opposed AB 1043 and removed its opposition to AB 1856 after the amendment, puts the criticism this way: AB 1043 does not require age verification, but the liability it creates — up to $7,500 per affected child — will push operating systems and app stores to verify ages, which in their view means more ID checks and more barriers for adults as well as children. That is EFF's reading, not a finding of ours; the text we read requires an indication of age, not proof of it.
Colorado — from 1 July 2028
Colorado's SB26-051, "Concerning age attestation for users of computing devices", adds Article 30 to Title 6 of the Colorado Revised Statutes. The copy we read is the act prepared for signature, and it states its own effective date: 1 July 2028. We have not seen the signature, so check the legislative status sheet before you rely on the date.
- The duty
- From 1 July 2028, an operating system provider that operates a covered app store, or ships one pre-installed, must provide an accessible interface at account setup requiring the account holder to indicate the birth date, age or age bracket of the user, for the purpose of sending an age signal to covered applications (CRS § 6-30-102(1)).
- The brackets
- Identical to California's, written into the definitions as the minimum content of the signal: under 13; 13 to 15; 16 to 17; 18 and over (§ 6-30-101(3)).
- The signal
- Age-bracket data sent through a real-time secure programming interface from an operating system or a covered app store to a covered application (§ 6-30-101(4)). An app that receives it is deemed to have knowledge of the user's age range. The provider or store may not share the signal for any purpose the article does not require.
- Existing devices
- Accounts completed before 1 July 2028 get an interface offering by 1 January 2029, and apps must request a signal for those users by the same date (§ 6-30-103).
- Enforcement
- The same figures as California: up to $2,500 per harmed minor for a negligent violation and $7,500 for an intentional one, assessed by the Attorney General (§ 6-30-104(1)), with the same good-faith protection.
- The open-source carve-out
- The article does not apply to an operating system provider or developer that distributes software under licence terms that permit a recipient to copy, redistribute and modify it without platform-imposed technical or contractual restrictions on installing modified versions (§ 6-30-105(3)(e)). Colorado also carves out code repository providers and containerised software distribution (§ 6-30-101(6)(b)).
- What the state says it is doing
- The legislative declaration is explicit that the aim is a minimal age-category signal that lets apps meet Colorado's own privacy duties for minors, while "avoiding the need for invasive identity verification methods". Whether a self-declared bracket achieves that is the argument everyone is having — see the criticism of bypassability.
Brazil — in force since 17 March 2026
Brazil already requires this, and the date in the headline is exact: 17 March 2026. The Estatuto Digital da Criança e do Adolescente (Lei nº 15.211, signed 17 September 2025 — the "ECA Digital") is in force from that date under Article 41-A as set by Lei nº 15.352 of 2026. The executive decree followed the next day: Decreto nº 12.880 of 18 March 2026, in force on publication, which regulates the law and makes the data protection authority (ANPD) the regulator.
- Who is caught
- The law covers "produtos ou serviços de tecnologia da informação" and names operating systems and internet application stores in the definition, alongside internet applications, computer programs and games connected to the internet (Lei 15.211, Art. 2º I, VI, VII).
- What they must do
- Article 12 requires app stores and terminal operating systems to take proportional, auditable and technically secure measures to ascertain the age or age bracket of users; to let parents configure voluntary parental supervision; and to provide an age signal over a secure API, on a privacy-by-default basis, only for the law's purposes.
- What the decree adds
- Article 25 of the decree requires app stores and operating systems to supply age signals to service providers free of charge, to ask the account holder to declare the age or age bracket when the account is created, to assess age by a reliable method set by the ANPD (preferably with verifiable credentials), to allow a user to contest and correct a classification, and to take measures against multiple accounts or similar circumvention.
- What may not be sent
- The signal is limited to what is needed to confirm a minimum age. Sending the exact date of birth, the civil identity or profiling data is prohibited (decree Art. 25 §1º), and data collected for age assessment may be used for nothing else (Lei 15.211, Art. 13).
- The vocabulary the world should be using
- The decree defines six things separately: aferição de idade (age assessment — all methods), verificação de idade (verification — the high-reliability procedure), sinal de idade (age signal) and autodeclaração de idade (self-declaration, expressly a weaker method) (decree Art. 2º IV–VII). Our explainer uses that set.
The open-source hole
A mandate written for macOS and Windows has a problem with Linux and the BSDs: there is no central account administrator to hold responsible. Who would be the "operating system provider" of Debian? The answer the two US states reached is to exempt the licence model rather than the product — if the licence lets the recipient copy, redistribute and modify the software, the provider is not an operating system provider at all.
- What the exemption does not cover
- Systems that ship proprietary components or lock down modified builds can still be caught. That is the reading the Linux trade press took in May 2026 of both bills, singling out Valve's SteamOS as an example that may not be exempt. That is their reading of the licence language, not ours, and neither of us has a court decision to point at.
- Wider than "operating system"
- Both definitions reach general-purpose computing devices rather than phones alone, and California's app store definition covers anything publicly available that distributes third-party applications — so the same duty can attach to a store with no operating system of its own.
- The developer is the side that binds you
- The exemption helps a distribution, not an app. If you publish a game through a covered app store, the developer duties — request the signal, treat it as knowledge of the user's age range, do not ask the user to change it — reach you whether or not your own software is open source.
What we cannot tell you is how a distribution without a legal entity, a community-run repository, or a downstream rebuild is meant to behave under the Brazilian law, which has no equivalent carve-out. Nobody has published an answer to that.
Microsoft and Windows
Microsoft is building the platform half of this already, and for once there is an official source: a Windows Experience Blog post of 8 September 2026 by Rob Mauceri introduces the Windows Age API, described as bringing age awareness beyond the operating system so that apps and services can deliver age-appropriate experiences. The model stated in the post is user account → age signal → age-appropriate experience and controls, and the named capability is GetUserAgeRangeAsync, which provides a non-personally-identifiable age range.
Reported, not established
This is the part of the story we could not verify, and we are keeping it separate for that reason.
- New York
- A bill is reported to go further than California and Colorado: age assurance for users at the point of device activation, with self-reporting excluded and the permitted methods left to regulations written by the state attorney general. We could not open the bill, and we have no bill number. Reported by the Linux trade press in March 2026, quoting Carl Richell of System76. Do not cite us for it.
- Other states
- The same trade coverage listed operating-system age-check laws in Louisiana (reported effective 1 July 2026), Illinois (1 January 2027), Texas (mobile devices) and Utah. We have verified none of those.
- The bypassability argument
- The criticism that a declared bracket is "little better than a pop-up asking whether you are an adult" is made by commentators — including, in that spirit, the EFF passage quoted above. We are happy to print it as their reading of the text; we are not adopting it as ours.
- Australia and the UK
- Both are earlier, service-level regimes rather than operating-system mandates, and they sit outside this note's scope. We have not verified their details for this page and do not describe them here.
There is no EU measure here
Nothing in this note is EU law. There is no EU provision today that requires an operating system to hold or pass on a user's age, and no EU bill that does that has been adopted. What exists is:
- In force: the DSA, aimed at platforms
- The Digital Services Act's youth-protection duty sits with providers of online platforms accessible to minors and requires appropriate and proportionate measures for their privacy, safety and security (Article 28). An app store can be an online platform; an operating system as such is not the addressee.
- Proposed: the EU Kids Act
- The Commission's proposal of 17 September 2026 (COM(2026) 681, procedure 2026/0286(COD)) does list operating systems among its seven service categories, but the duty it places on them is narrow — on the reading in our Kids Act note, essentially a consent for passing on an age signal the system already holds (Article 29(6)) — and it is draft, with feedback open until 26 November 2026.
- Expectation is not law
- It is often said that the US states show Europe where things are going, and politicians do borrow each other's briefing notes. But no EU institution has proposed an operating-system age mandate. If you read that the EU "will follow", you are reading a prediction.
What it means for a small shop or a game
If you sell physical goods into the EU, nothing here changes what you file. The people this lands on are the ones shipping software — and mostly through the developer duties rather than by owning an operating system.
- You will receive an age bracket
- Under the US laws an app that gets a signal is deemed to know the user's age range. That turns a design decision — what a 14-year-old sees — into a compliance question with a penalty attached to it.
- The app store is the delivery route
- If you distribute through a store, the store requests the signal and passes it to you. You do not build an age check; you handle one.
- Do not build the verification step yourself
- Both US texts forbid requesting more information than the law requires and forbid prompting the user to change their age information. A "confirm your birthday" dialogue is worse than useless — it is the thing the text discourages.
- If you maintain a distribution or a server
- With no central account controller, the honest answer for a community distribution in Brazil is that the law has an addressee-shaped hole. Record what you decided, keep the decision reversible, and tell us what we are missing — that is exactly the sort of source this page wants.
Watch the direction of travel, not the date
California applies from 1 January 2027, Colorado from 1 July 2028, Brazil already applies. Two of the three have open-source carve-outs and one does not, which means the same free operating system can be exempt in Denver and in scope in São Paulo. If you ship software to both, that asymmetry is the thing to design around — not any single deadline.
What we could not establish
- Colorado's signature
- The act we read is prepared for signature and states 1 July 2028. We have not confirmed the Governor's action, and a referendum petition could in principle change it.
- New York, and four other states
- No bill number, no text, no status — see Reported, not established.
- Brazil and free software
- No published statement from the ANPD on how Article 12 applies to a distribution with no legal entity. The exemption question is our reading of the absence of one, not a regulator's answer.
- The Windows rollout
- No confirmed date, no territories. Microsoft's own age-range API is documented; "rollout of age verification on Windows 11" is a headline we could not read behind.
- Guidance on what a signal means for EU users
- If a US operating system sends a bracket to an app about a user sitting in Vienna, no EU rule answers what the app may do with it beyond the GDPR. That is the spill-over question, and it is unanswered.
Sources
The backbone of this note is the four legal texts themselves; everything interpretive is attributed to whoever said it.
-
California Legislative Information — AB 1856, Chapter 184 (approved 10 September 2026) The amended text of Civil Code §§ 1798.500–1798.504. Source for the account-setup interface, the four brackets, the app-store and developer duties, the 1 January 2027 and 1 July 2027 dates, the $2,500/$7,500 penalties and the open-source definition in § 1798.500(g)(2). Read in full for this page
-
Colorado General Assembly — SB26-051, age attestation for users of computing devices (PDF) The act as prepared for signature. Source for the 1 July 2028 effective date, the identical brackets, the signal definitions, the 1 January 2029 retrofit dates, the penalties and the open-source carve-out in § 6-30-105(3)(e). Read in full for this page
-
Planalto — Lei nº 15.211, 17 September 2025 (ECA Digital), consolidated text Source for the scope definitions in Art. 2º, the operating-system and app-store duties in Art. 12, the purpose limitation in Art. 13, and the entry into force on 17 March 2026 under Art. 41-A as set by Lei nº 15.352. Read in full for this page
-
Planalto — Decreto nº 12.880, 18 March 2026 The regulation, in force on publication. Source for the definitions of age assessment, age verification, age signal and self-declaration (Art. 2º IV–VII), the design requirements (Art. 24) and the free age-signal duty, the account-creation declaration and the anti-circumvention measures (Art. 25). Read in full for this page
-
EFF — California Steps Back From Dangerous Expansion of its Age-Gating Law Commentary, 15 July 2026. Source for the attributed criticism: that AB 1043 does not require age verification but the liability will push operating systems to verify; that AB 1856 dropped the browser and website expansion and exempted open-source operating systems; and EFF's position that no one should have to verify their age to access the internet
-
GamingOnLinux — Colorado and California age verification bills exempt open source operating systems Secondary, 25 May 2026. Source for the SteamOS reading and for the Colorado bill number, linked there to the final act we read ourselves
-
GamingOnLinux — Many more US states are planning or already have operating system age verification laws Secondary, 6 March 2026. Source for the New York bill language and the Louisiana, Illinois, Texas and Utah list — all attributed and marked unverified in this note
-
Microsoft — Helping families and educators support safer experiences and healthier habits on Windows Official, 8 September 2026. Source for the Windows Age API, the account → age signal → experience model and the GetUserAgeRangeAsync capability
-
Bangkok Post — Microsoft to roll out age verification system on Windows 11 Headline, 3 October 2026. Listed for transparency: the page would not open for us, so we report only the headline and no content from it
Tell us what we got wrong
The New York bill number, the Colorado signature, and any ANPD statement about free software would each close a gap on this page. If you have one, bring it in — a source we can open beats ten pages of commentary, and we correct this page in public when we have something wrong.