Illinois Just Passed a Law That Puts Linux on the Hook for Age Verification
Illinois Just Passed a Law That Puts Linux on the Hook for Age Verification
伊利诺伊州刚通过一项法律,将 Linux 纳入年龄验证监管范围
HB5511 is officially about TikTok and Instagram. Read past the press release and it’s also about your operating system. Governor JB Pritzker’s press release on HB5511 is thick with quotes from legislators and advocacy groups, and it names Instagram, TikTok, Snapchat, X, Facebook, and Roblox specifically. Device setup gets one mention, framed as something a parent configures during setup. Nowhere does it explain that the law also creates a separate legal category called an operating system provider, with its own 2028 deadline and its own civil penalties, that has nothing to do with what any parent chooses to click.
HB5511 法案名义上是针对 TikTok 和 Instagram 的。但如果你仔细阅读法案内容,会发现它也涉及到了你的操作系统。伊利诺伊州州长 JB Pritzker 关于 HB5511 的新闻稿中充斥着立法者和倡导团体的引言,并明确点名了 Instagram、TikTok、Snapchat、X、Facebook 和 Roblox。其中仅提到了一次设备设置,将其描述为家长在设置过程中进行的操作。然而,文中完全没有解释该法律还创建了一个名为“操作系统提供商”的独立法律类别,该类别有其自身的 2028 年截止日期和民事处罚措施,且与家长点击什么选项毫无关系。
TL;DR HB5511, the Children’s Social Media Safety Act, is now Illinois Public Act 104-0664. Pritzker signed it July 31. The headline provisions target social platforms: no algorithmic feeds for minors by default, no notifications between 10pm and 7am, no contact from adult strangers. A separate part of the bill defines operating system provider and covered manufacturer broadly enough to include anyone who builds an internet-connected OS, commercial or nonprofit. By January 1, 2028, those providers have to build an age-declaration step and hand an age-bracket signal to any app that requests one. Unlike Colorado, and unlike where California is heading, Illinois added no exemption for open source software.
简而言之,HB5511《儿童社交媒体安全法》现已成为伊利诺伊州第 104-0664 号公共法案。Pritzker 州长于 7 月 31 日签署了该法案。其核心条款针对社交平台:默认禁止向未成年人推送算法信息流,晚上 10 点至早上 7 点之间禁止发送通知,禁止成年陌生人联系未成年人。法案的另一部分对“操作系统提供商”和“受监管制造商”的定义非常宽泛,涵盖了任何构建互联网连接操作系统的实体,无论是商业机构还是非营利组织。到 2028 年 1 月 1 日,这些提供商必须构建年龄申报步骤,并向任何请求该信息的应用程序提供年龄段信号。与科罗拉多州不同,也与加利福尼亚州正在推进的方向不同,伊利诺伊州没有为开源软件提供任何豁免。
Enforcement runs through the Illinois Attorney General only. The bill’s own text caps penalties at $7,500 per affected child. The governor’s press release advertises penalties of up to $50,000 per violation. Those numbers don’t obviously square with each other.
该法案仅由伊利诺伊州总检察长负责执行。法案文本规定每名受影响儿童的罚款上限为 7,500 美元。而州长的新闻稿则宣称每次违规罚款最高可达 50,000 美元。这两个数字显然存在矛盾。
The Version Illinois Wants You to Read
伊利诺伊州希望你看到的版本
Set the operating system question aside for a second, because the social media half of this bill is fairly standard for 2026. Platforms built around algorithmic feeds, plus platforms where kids can be contacted by strangers (Roblox is the named example), now have to default minors into chronological, follow-only feeds instead of an engagement-optimized one. Notifications get cut off overnight. Adult strangers can’t see a minor’s profile, message them, or see their location. News sites, email providers, broadband companies, and school software are all carved out by name.
先暂时搁置操作系统的问题,因为该法案中关于社交媒体的部分在 2026 年的标准下相当常规。以算法信息流为核心的平台,以及允许陌生人联系儿童的平台(Roblox 是被点名的例子),现在必须默认将未成年人的信息流设置为按时间顺序排列的“仅关注”模式,而不是基于互动优化的模式。夜间通知将被切断。成年陌生人无法查看未成年人的个人资料、向其发送消息或查看其位置。新闻网站、电子邮件提供商、宽带公司和学校软件均被明确排除在外。
It passed the General Assembly on June 1 without a single no vote, 57-0 in the Senate and 113-0 in the House concurrence. Pritzker signed it July 31, flanked by quotes from Attorney General Kwame Raoul and groups like Common Sense Media and Mothers Against Media Addiction. Nothing about that rollout mentions your desktop.
该法案于 6 月 1 日在州议会以全票通过,参议院投票结果为 57-0,众议院投票结果为 113-0。Pritzker 于 7 月 31 日签署了该法案,随行的还有总检察长 Kwame Raoul 以及 Common Sense Media 和 Mothers Against Media Addiction 等团体的支持言论。整个发布过程中完全没有提到你的桌面电脑。
The Part the Press Release Skipped
新闻稿中被忽略的部分
Here’s what actually set off the Reddit thread: a post claiming Illinois now requires operating system providers, open source projects included, to build age verification by 2028. It wasn’t universally believed. On at least one mirror of the discussion, a commenter argued the framing was misleading and that the post should be corrected. So instead of trusting a screenshot either way, we went and read the bill on the Illinois General Assembly’s own tracker. It holds up.
这就是引发 Reddit 讨论帖的真正原因:一篇帖子声称伊利诺伊州现在要求操作系统提供商(包括开源项目)在 2028 年前建立年龄验证机制。这一说法并未得到普遍信任。在至少一个讨论镜像中,有评论者认为这种表述具有误导性,并要求更正。因此,我们没有盲目相信任何截图,而是直接在伊利诺伊州议会的官方追踪器上阅读了该法案。结论是:该说法属实。
Separate from the social media rules, HB5511 creates duties for an operating system provider and folds device makers, OS vendors, and app stores together under the term covered manufacturer. Legislative trackers that follow this exact category of bill across states file this piece under its own name: Digital Age Assurance, the same bucket Colorado’s and California’s versions land in.
除了社交媒体规则外,HB5511 还为操作系统提供商设定了义务,并将设备制造商、操作系统供应商和应用商店统称为“受监管制造商”。追踪各州此类法案的立法追踪器将其归类为:数字年龄保证(Digital Age Assurance),这与科罗拉多州和加利福尼亚州的相关法案属于同一类别。
What Every Covered Manufacturer Has to Build by 2028
每个受监管制造商必须在 2028 年前构建的内容
-
An accessible setup screen that asks an account holder to indicate a birth date, an age, or both.
-
A way for any app or platform that asks (the bill calls them “operators” and “covered developers”) to receive a signal for that age, delivered through a consistent, encrypted API.
-
A hard limit on what gets shared: only the minimum information needed to answer the question, and no handing it to a third party beyond what the law requires.
-
一个易于访问的设置界面,要求账户持有人注明出生日期、年龄或两者兼有。
-
一种让任何请求该信息的应用程序或平台(法案称其为“运营商”和“受监管开发者”)通过一致的加密 API 接收该年龄信号的方法。
-
对共享信息的严格限制:仅提供回答问题所需的最低限度信息,且不得将信息交给法律规定之外的第三方。
The signal itself isn’t a birthday, it’s a bracket: under 13, 13 to 15, 16 to 17, or 18 and up. Operating systems have until January 1, 2028 to have this built. Platforms then have until July 1, 2028 to start actually requesting that signal for their users. Once an app gets a “minor” bracket back, the law treats it as having actual knowledge the user is underage, which is what flips on every default protection in the social media half of the bill.
信号本身不是生日,而是一个年龄段:13 岁以下、13 至 15 岁、16 至 17 岁或 18 岁及以上。操作系统必须在 2028 年 1 月 1 日前完成此功能的构建。平台则有权在 2028 年 7 月 1 日前开始为其用户请求该信号。一旦应用程序收到“未成年人”年龄段的反馈,法律即视为该应用已获悉用户未成年,从而触发法案中社交媒体部分的所有默认保护措施。
Nothing in the bill requires a passport scan or a face scan at setup. It’s self-declared, the same way most apps ask your birthday today, just centralized once at the OS level instead of repeated app by app. That’s exactly why a good chunk of the r/linux replies were jokes about setting their install’s date of birth to sometime in the Nixon administration.
法案中没有任何条款要求在设置时进行护照扫描或人脸扫描。这属于自我申报,与目前大多数应用程序询问你生日的方式相同,只是将这一过程从每个应用程序重复询问集中到了操作系统层面。这正是为什么 r/linux 上有大量回复在开玩笑说,要把他们安装系统的出生日期设在尼克松政府时期。
Nobody Carved Out an Exception This Time
这次没有人被豁免
This structure, OS hands out an age bracket, apps pull it through an API, already showed up in Colorado and California, and both ran into the same objection: the definitions were broad enough to catch community-run, noncommercial, open source projects with no realistic way to run an age-gated setup wizard, let alone a compliance department.
这种“操作系统提供年龄段,应用程序通过 API 获取”的结构,此前已在科罗拉多州和加利福尼亚州出现,且两者都遇到了同样的反对意见:其定义过于宽泛,以至于将社区运营、非商业性的开源项目也涵盖在内,而这些项目根本没有能力运行年龄限制设置向导,更不用说建立合规部门了。
Colorado fixed it. Governor Jared Polis signed SB26-051 on June 3, and largely because System76 founder Carl Richell worked directly with the bill’s co-author, State Senator Matt Ball, the final version exempts operating systems, apps, code repositories like GitHub and GitLab, and container platforms like Docker and Podman, as long as they’re distributed under an open license. It also blocks a vendor from locking down a modified version of the software just to dodge the exemption.
科罗拉多州解决了这个问题。州长 Jared Polis 于 6 月 3 日签署了 SB26-051 法案。很大程度上是因为 System76 的创始人 Carl Richell 直接与该法案的共同作者、州参议员 Matt Ball 进行了合作,最终版本豁免了操作系统、应用程序、GitHub 和 GitLab 等代码仓库,以及 Docker 和 Podman 等容器平台,只要它们是在开源许可下分发的。它还阻止了供应商为了规避豁免而锁定软件的修改版本。
California is trying to get to the same place. Its original law, AB-1043, had the identical gap. Assemblymember Buffy Wicks, who wrote that bill, introduced a follow-up, AB-1856, specifically to redefine operating system provider so it excludes anyone shipping software under those same open terms. As of this writing, that fix is still moving through Sacramento, not finished. Illinois skipped that.
加利福尼亚州也正试图达到同样的目标。其最初的法律 AB-1043 存在同样的漏洞。撰写该法案的众议员 Buffy Wicks 随后提出了后续法案 AB-1856,专门重新定义了“操作系统提供商”,将其排除在以相同开源条款发布软件的任何人之外。截至本文撰写时,该修正案仍在萨克拉门托推进中,尚未完成。而伊利诺伊州则跳过了这一步。