VYPR
advisoryPublished Sep 3, 2026· 1 source

California's Digital Age Assurance Act Mandates Age Bracketing on Major Operating Systems

California's new Digital Age Assurance Act will require Windows, macOS, iOS, and Android to collect user age brackets starting January 1, 2027, aiming to protect minors.

California has enacted the Digital Age Assurance Act (DAAA), a significant piece of legislation that will mandate major operating systems to begin collecting user age information. Starting January 1, 2027, users setting up Windows, macOS, iOS, and Android devices within the state will be required to provide their age bracket. For devices already set up before this date, a grace period extends the deadline to July 1, 2027, for compliance.

The DAAA categorizes users into four distinct age brackets: under 13, 13–15, 16–17, and 18+. This information will be transmitted as a non-identifying signal to app developers, who must request it from the operating system provider or app store upon a user's first download and launch of an application. This mechanism aims to inform developers about the age bracket of their users, enabling them to enforce age-appropriate content restrictions and feature limitations.

The primary objective behind the DAAA is to shield minors from potentially harmful online content and behaviors. This includes preventing children from accessing applications designed for adults and curbing addictive social media features. The law aligns with broader efforts to regulate children's online activities, such as Meta's recent settlement to impose time limits on minors' social network use and other proposed legislation targeting addictive features for those under 16.

However, the DAAA has drawn criticism from digital rights advocates like the Electronic Frontier Foundation (EFF). The EFF argues that the law outsources censorship responsibilities to developers and raises privacy concerns. A significant point of contention has been the potential burden on open-source operating systems, which often lack the extensive development resources of commercial giants like Microsoft, Apple, and Google. This could force smaller projects to either invest heavily in compliance or risk being unavailable in California.

In response to these concerns, Assembly member Buffy Wicks introduced Bill AB1856, which proposes exemptions for open-source operating systems that adhere to common licenses such as GPL, MIT, BSD, and Apache. This amendment, passed by California lawmakers in late August and awaiting the governor's decision, aims to alleviate the compliance burden on volunteer-driven projects while still upholding the law's intent for commercial systems.

California is not the first state to implement such measures. Colorado's SB26-051 and Illinois have also passed similar age assurance legislation, with Colorado also incorporating open-source exemptions following lobbying efforts. New York is reportedly considering similar legislation.

While the exemptions for open-source software may appease some privacy advocates, the broader implications for user privacy and data collection remain a concern. Users of mainstream operating systems can anticipate being asked for their age bracket soon, prompting a potential shift towards open-source alternatives for those prioritizing privacy and avoiding such data collection.

The implementation of the DAAA signifies a growing trend of state-level regulation targeting online child protection, with significant implications for how operating systems and applications handle user age data. The balance between protecting minors and preserving user privacy and open-source development will continue to be a critical discussion point.

Synthesized by Vypr AI