California Digital Age Assurance Act
| Digital Age Assurance Act | |
|---|---|
| |
| Signed by | Gavin Newsom |
| Signed | October 13, 2025 |
| Effective | January 1, 2027 |
| Bill citation | Assembly Bill 1043 (AB 1043), Chapter 675, Statutes of 2025 |
| Introduced by | Buffy Wicks |
| Status: Not yet in force | |
The Digital Age Assurance Act (DAAA), formally Assembly Bill 1043, is a California law that requires operating system providers to collect age information from users at device account setup and to transmit an age-bracket signal to application developers.[1][2]
Legislative history
[edit]The bill's stated objective is to address a gap in California's existing legal framework for protecting minors online. Prior California laws attempted to impose obligations on platforms likely to be accessed by children, but they have been enjoined by federal courts on First Amendment grounds. AB 1043 was designed to sidestep constitutional objections by imposing no direct content restrictions, instead creating an age-signaling infrastructure that other laws could act upon.[3]
AB 1043 was introduced by Assemblymember Buffy Wicks, who had previously authored the California Age-Appropriate Design Code Act.[2] The bill passed the California State Assembly 76-0 in June 2025 and the California State Senate 38-0 in September 2025.[1][2] It was signed into law by Governor Newsom on October 13, 2025, and filed the same day with the California Secretary of State.[4] Governor Newsom issued a signing statement noting concerns from streaming services and video game developers about the law, specifically "complexities such as multi-user accounts shared by a family member and user profiles utilized across multiple devices."[1] Newsom urged the Legislature to amend the law to address these concerns before its effective date.[2] Wicks subsequently indicated willingness to work with streaming providers on possible remedies.[5]
Provisions
[edit]The law establishes four age brackets for purposes of the required signal: under 13 years of age, 13 to under 16, 16 to under 18, and 18 or older. Under the law, "operating system providers" must display an interface at account setup that requires the birth date, age, or both, of the device's primary user and provide a digital signal specifying the associated age bracket via a "reasonably consistent real-time application programming interface."[1][5][6] Developers must request an age bracket signal when an application covered by the law is downloaded and launched.[6] Upon receiving a signal, a developer is "deemed to have actual knowledge" of the user's age range, triggering potential obligations under other laws such as the Children's Online Privacy Protection Act and the California Consumer Privacy Act.[7]
Violations are subject to civil penalties of up to $2,500 per affected child for each negligent violation and up to $7,500 per affected child for each intentional violation.[4]
Reception
[edit]The Reason Foundation said that the bill "represents a meaningful advancement in the national debate on age verification. It replaces high-risk identity checks with privacy-preserving signals, curtails constitutional litigation risks, and clarifies enforcement responsibility," but added that the law should be amended so the protections were opt-in.[8]
The Electronic Frontier Foundation (EFF) characterized OS-level age gates as creating "unnecessary and unconstitutional barriers for adults and young people to access information and express themselves online." EFF argued that because developers receiving an age signal are "deemed to have actual knowledge" of a minor user's age, they face legal incentives to restrict access to applications beyond what the law requires, amounting to outsourced censorship. They noted that the law's burdens fall disproportionately on developers who are not part of large, well-resourced companies, particularly free and open-source software developers, for whom building age-collection and signaling functionality may not be feasible.[9]
More than 400 computer scientists signed an open letter protesting such laws, stating that they will create surveillance infrastructure without effectively preventing minors' access to age-restricted content.[10] Several open-source projects announced that they would not implement the law's requirements, including GrapheneOS, MidnightBSD, DB48X,[11] and Ageless Linux, which was launched as an act of civil disobedience against AB 1043, declaring itself to be in "full, knowing, and intentional noncompliance" with the law.[12]
In May 2026, Wicks introduced amendments to the bill in AB 1856, intended to reduce its burden on the distributors of open-source operating systems. The amendment redefines an "operating system provider" to exclude "a person or entity that distributes an operating system or application under license terms that permit a recipient to copy, redistribute, and modify the software", and "application" to exclude "software components that are not themselves offered to consumers as a stand-alone executable application through a covered application store".[13][14][15]
References
[edit]- 1 2 3 4 "California introduces age verification law for all operating systems, including Linux and SteamOS". Tom's Hardware. March 4, 2026. Retrieved March 25, 2026.
- 1 2 3 4 "Analyzing California's Digital Age Assurance Act". Troutman Pepper Privacy + Cyber + AI. October 27, 2025. Retrieved March 25, 2026.
- â "AB 1043 Senate Judiciary Committee Analysis" (PDF). California Senate Judiciary Committee. 2025. Retrieved March 25, 2026.
- 1 2 "AB-1043 Age verification signals: software applications and online services". California Legislative Information. Retrieved March 25, 2026.
- 1 2 "FAQs on the Digital Age Assurance Act". Kelley Drye Ad Law Access. October 21, 2025. Retrieved March 25, 2026.
- 1 2 "California Introduces New Age Verification Requirements for Software Applications". Hunton Andrews Kurth Privacy and Cybersecurity Law Blog. Retrieved March 25, 2026.
- â Oh, Maki DePalo, Hyun Jai (October 23, 2025). "California Enacts Digital Age Verification Law". Alston & Bird Privacy, Cyber & Data Strategy Blog. Retrieved March 25, 2026.
{{cite web}}: CS1 maint: multiple names: authors list (link) - â "Examining California's Digital Age Assurance Act". Reason Foundation. January 5, 2026. Retrieved March 25, 2026.
- â "A.B. 1043's Internet Age Gates Hurt Everyone". Electronic Frontier Foundation. 2026. Retrieved March 25, 2026.
- â Ridley, Jacob (March 3, 2026). "Scientists warn against crappy age verification: 'if implemented without careful considerationâĶ the new regulation might cause more harm than good'". PC Magazine. Retrieved March 25, 2026.
- â "GrapheneOS (@GrapheneOS@grapheneos.social)". GrapheneOS Mastodon. March 20, 2026. Archived from the original on May 3, 2026. Retrieved March 23, 2026.
- James, Luke (March 22, 2026). "GrapheneOS refuses to comply with new age verification laws for operating systems â group says it will never require personal information". Tom's Hardware. Archived from the original on March 23, 2026. Retrieved March 23, 2026.
- Simons, Hadlee (March 23, 2026). "GrapheneOS won't comply with age check laws for operating systems". Android Authority. Archived from the original on March 23, 2026. Retrieved March 23, 2026.
- Hector, Hamish (March 23, 2026). "GrapheneOS is taking a stand against digital age verification laws â can its defiance last?". TechRadar. Archived from the original on March 23, 2026. Retrieved March 23, 2026.
- â ""Ageless Linux â Software for Humans of Indeterminate Age"". Retrieved March 25, 2026.
- â Uko, Etiido (May 25, 2026). "California moves to exempt Linux from its upcoming age-verification law after backlash over forcing operating systems to collect users' ages â amendment proposed by the same lawmaker who wrote the original law". Tom's Hardware. Retrieved May 28, 2026.
- â Bonifield, Stevie (May 14, 2026). "Linux devs are fighting the new age-gated internet". The Verge. Retrieved May 28, 2026.
- â "AB 1856- AMENDED". leginfo.legislature.ca.gov. Retrieved May 28, 2026.