California Exempts Linux from Age Verification Law
California's AB-1856 unanimously exempts Linux and open-source software from age verification. Here's what changed, what didn't, and why it matters beyond California.
Written by AI. Tomas Reyes-Kim

Picture a sixteen-year-old in Fresno who wants to learn programming. She doesn't have money for a coding bootcamp or a MacBook. She has a five-year-old laptop, a decent internet connection, and a YouTube tutorial telling her to download Ubuntu. Under California's age-verification law, that download could have required her to prove her age before touching software that runs more of the internet's backbone than most people realize.
California just decided that was a bad idea. Unanimously.
The Law, the Problem, and the Fix
California's age-verification legislation was designed to protect minors from harmful online content, a goal that is genuinely defensible. But the language, as originally written, was broad enough to sweep in software distribution in ways that alarmed the open-source community. The concern wasn't hypothetical: if a platform distributes software and is subject to the law, and the law requires age verification, then downloading a Linux ISO or a Python package from a repository could theoretically trigger compliance requirements that no volunteer-maintained open-source project is equipped to handle.
The fix is called AB-1856. According to Tom's Hardware, California lawmakers unanimously passed the bill, exempting Linux and any software distributed under open-source licenses including GPL, MIT, BSD, and Apache from the age-verification requirement. Phoronix confirmed the bill's passage and framed it as "open-source relief," which is accurate without being dramatic. Slashdot covered the community's reaction, which was broadly relieved.
The unanimous vote is worth noting. This wasn't a close call or a partisan fight. When a California legislature votes unanimously on a tech bill, it usually means either everyone agrees the original law went too far, or the fix is narrow enough that nobody has a reason to oppose it. AB-1856 looks like both.
What "Open Source" Actually Covers Here
This is the part where it gets interesting if you're willing to sit with the plumbing for a second.
GPL, MIT, BSD, Apache: these aren't just Linux licenses. They cover a staggering portion of the software that powers modern digital life. Python, one of the most widely taught programming languages in schools and universities, is open source. Git, the version control system that underlies essentially all collaborative software development, is open source. The web servers, the databases, the package managers, the compilers: open source, open source, open source, open source.
The question the original law raised wasn't just "can a teenager download Ubuntu?" It was: does any platform that distributes open-source software now have age-verification obligations? If the answer was yes, the compliance burden would have landed on the Linux Foundation, on package repositories like PyPI and npm, on university mirror servers run by IT departments with three staff members. None of those entities were built to card users at the door.
The Verge framed the broader fight well: Linux developers were actively pushing back against the trend of age-gated internet infrastructure. AB-1856 is California's answer to that pushback. It draws a line between platforms distributing content to minors (the actual target of age-verification laws) and platforms distributing software under free licenses (not the target, regardless of what the original text implied).
The honest version of the open question: that line is cleaner in AB-1856 than it might be in whatever the next legislature drafts. The exemption is specific to recognized open-source licenses. That's actually a thoughtful construction, because it's not a blanket "software is exempt" carve-out; it requires the license to be a known free and open-source license. But it does mean that future laws in other states would need to replicate that specificity intentionally, not accidentally.
California Isn't Alone in Figuring This Out
System76, the Linux hardware company, noted that Colorado moved in the same direction, also exempting open source from age attestation requirements. Two states, same conclusion, roughly the same time. That's not a coincidence; it's a signal that the open-source community's lobbying and education efforts are landing with legislators who hadn't previously had to think carefully about how software distribution works.
The pattern here is familiar to anyone who watches tech regulation: a law gets written with a clear target, the language is broader than the intent, and an affected community has to scramble to get the language tightened before enforcement creates chaos. The good news in this cycle is that both California and Colorado caught it before enforcement. The less reassuring news is that there are fifty states, and not all of them have tech-literate legislators, active Linux communities, or hardware companies like System76 making the case in committee hearings.
Why This Matters to Anyone Who Works Remotely
I want to be direct about why this story lands differently for my readers than it might for a general tech audience.
The digital nomad ecosystem runs on open-source infrastructure in ways that are weirdly specific once you start noticing them. The developer who sets up a new laptop in a Lisbon coworking space uses a package manager to pull in dependencies: apt, brew, pip, cargo. Those tools pull from repositories governed by exactly the licenses AB-1856 covers. The freelance web developer building client sites from a guesthouse in Chiang Mai runs a Linux server on a five-dollar-a-month VPS. The remote worker doing data analysis from a Medellín Airbnb relies on Python libraries that live on PyPI.
None of this is glamorous infrastructure. It's the unglamorous kind, which is exactly why it matters. The moment age-verification compliance burdens land on the maintainers of these repositories, the people who feel it first are the ones without institutional backing: the solo developers, the budget-laptop crowd, the people who chose open-source specifically because they couldn't afford the proprietary alternative.
That sixteen-year-old in Fresno is also, five years from now, the person writing code from a coffee shop in Bangkok and telling people on Reddit that you can actually do this for under $1,500 a month. The pipeline from "kid who downloaded Ubuntu for free" to "adult who works from anywhere" is real, and it runs on exactly the software this law was about to complicate.
What Actually Changes for the Girl in Fresno
She can download Ubuntu without proving her age. So can you, so can anyone with a California IP address, and the repository maintainers don't have to build an age-gate into their distribution infrastructure to serve her.
What doesn't change: the underlying age-verification law still exists for its actual targets. Platforms distributing content that's genuinely harmful to minors still have compliance obligations. AB-1856 didn't gut the law; it drew the line where the line probably should have been in the first place.
The obsessive specific detail I keep coming back to: the bill covers software distributed under GPL, MIT, BSD, and Apache licenses by name. That's not boilerplate. Someone in that legislative process knew enough to enumerate the major license families rather than write something vague like "open-source software as generally understood," which would have invited exactly the kind of definitional fight that slows enforcement and creates legal uncertainty. The specificity is the feature.
Whether other states get this right on the first draft is genuinely unknown. California and Colorado did. The rest of the map is still being drawn.
By Tomas Reyes-Kim, Budget Travel and Digital Nomad Correspondent
More Like This
Can Unreal Engine 5 Run on a $500 MacBook? Sort Of.
Testing Unreal Engine 5.7 on the MacBook Neo reveals what happens when professional software meets budget hardware—and why friction matters.
Dual Internet Connections Are Still Needlessly Hard to Set Up
IPv6 multihoming could let you plug two ISPs into one network and get automatic failover. Here's how close we actually are—and what's still broken.
Hacking a Ball Bearing for Precision on a Budget
A father-son engineering duo modified a standard ball bearing with a grinder to achieve wobble-free precision — no expensive parts required.
How Hobbyists Are Sourcing Used Industrial Robots
A YouTuber's deep dive into buying surplus industrial robots reveals a working secondhand market—and the steep knowledge gap that still keeps most people out.
Building Voice Agents: The Hard Engineering Reality
Rishabh Bhargava of Together AI breaks down the latency budgets, model size constraints, and pipeline tradeoffs behind production voice agents in 2025.
Ancient Amazon Civilizations Revealed by Archaeology
LiDAR mapping and new excavations are overturning the myth of a pristine, empty Amazon—revealing cities, roads, and millions of lost inhabitants.
RAG·vector embedding
2026-08-31This article is indexed as a 1536-dimensional vector for semantic retrieval. Crawlers that parse structured data can use the embedded payload below.