California lawmakers unanimously pass Linux exemption from age-verification law
California lawmakers unanimously pass Linux exemption from age-verification law
加州立法机构全票通过法案,将 Linux 排除在年龄验证法之外
California’s legislature has passed Assembly Bill 1856, exempting open-source operating systems from the State’s Digital Age Assurance Act months before the law is due to take effect on January 1, 2027. The Senate amended the Bill on August 21 before passing it on the 26th in a 39-0 vote, with the Assembly then accepting these changes in a concurrence vote the following day. 加州立法机构已通过第 1856 号众议院法案(AB 1856),在《数字时代保障法》(Digital Age Assurance Act)于 2027 年 1 月 1 日正式生效前几个月,将开源操作系统排除在该法案的适用范围之外。参议院于 8 月 21 日对该法案进行了修订,并于 26 日以 39 票对 0 票全票通过;众议院随后在次日的投票中表示赞同。
The amendment ends almost a year of uncertainty surrounding whether Linux distributions and SteamOS would be forced to collect user age data during account setup alongside Windows, macOS, iOS, and Android. AB 1856 has now been sent to Governor Gavin Newsom, who signed the original act into law last October. 此次修订结束了近一年来的不确定性——此前人们一直担心 Linux 发行版和 SteamOS 是否会像 Windows、macOS、iOS 和 Android 一样,被迫在账户设置过程中收集用户年龄数据。AB 1856 现已提交给加州州长加文·纽森(Gavin Newsom),他曾于去年 10 月签署了该法案的原始版本。
These amendments redefine the term “operating system provider” to exclude any person or entity that distributes an OS or application “under license terms that permit a recipient to copy, redistribute, and modify the software.” Any software distributed under the GPL, MIT, BSD, and Apache licenses satisfies that test, which removes the likes of Debian, Fedora, Ubuntu, Arch, and the BSD family from AB 1856’s scope. 这些修订重新定义了“操作系统提供商”一词,将任何“根据允许接收者复制、重新分发和修改软件的许可条款”分发操作系统或应用程序的个人或实体排除在外。任何根据 GPL、MIT、BSD 和 Apache 许可分发的软件均符合此标准,这意味着 Debian、Fedora、Ubuntu、Arch 和 BSD 家族等系统不再受 AB 1856 的约束。
A second exclusion removes software components that aren’t “offered to consumers as a stand-alone executable application through a covered application store” from the law’s definition of an application, covering libraries and dependencies distributed through package managers like apt and pacman. AB 1856 doesn’t explicitly say that repos aren’t app stores, but a store’s main obligation under the law is to request an age signal from the user’s OS provider and pass it to developers; an exempt open-source OS produces no signal. 第二项豁免将那些“并非通过受监管的应用商店作为独立可执行应用程序提供给消费者”的软件组件从法律定义的“应用程序”中剔除,这涵盖了通过 apt 和 pacman 等包管理器分发的库和依赖项。虽然 AB 1856 没有明确说明软件仓库不是应用商店,但根据法律,商店的主要义务是向用户的操作系统提供商请求年龄信号并将其传递给开发者;而获得豁免的开源操作系统不会产生此类信号。
A third carve-out excludes storefronts distributing extensions or add-ons that run exclusively inside a host application, which takes browser extension stores out of scope. 第三项豁免排除了那些仅在宿主应用程序内运行的扩展程序或插件的分发平台,这意味着浏览器扩展商店也不在监管范围内。
The amendments to AB 1856 also remove the original definition of “user,” which read, “a child that is the primary user of a device,” and technically classified every device owner in California as a child. The law’s signaling framework depends on adults declaring their age on account setup, so their devices get flagged as 18 and over, but under that definition nobody could ever be flagged as an adult. AB 1856 的修订还删除了“用户”的原始定义,即“作为设备主要使用者的儿童”,该定义在技术上将加州每一位设备所有者都归类为儿童。该法律的信号机制依赖于成年人在账户设置时声明年龄,从而将其设备标记为 18 岁及以上,但在原定义下,没有人能被标记为成年人。
In addition, lawmakers inserted a new provision prohibiting anyone from requesting an age signal from an OS provider or app store unless required by law. That closes off potential abuse of the age API that could have led to it being used as a general-purpose data collection channel even when age verification wasn’t required. Platforms and developers also gain a good-faith safe harbor against erroneous signals, protecting them from liability when age-gating signals are inaccurate. 此外,立法者还加入了一项新条款,禁止任何人在法律未要求的情况下向操作系统提供商或应用商店请求年龄信号。这杜绝了对年龄 API 的潜在滥用,防止其在无需年龄验证的情况下被用作通用数据收集渠道。平台和开发者还获得了针对错误信号的“善意安全港”保护,当年龄限制信号不准确时,可免于承担法律责任。
Windows, macOS, iOS, and Android remain fully in scope, with age collection required at account setup from January 1, 2027. A later July 1, 2027, deadline applies to devices set up before January 1. Whether SteamOS is in scope isn’t yet clear: its Arch-based system components are open source, but Valve distributes the image alongside the proprietary Steam client. GrapheneOS, which in March said it would refuse to comply with age-verification mandates, is distributed under open-source MIT and Apache licenses and now falls outside the law’s scope entirely, though Brazil’s Digital ECA still applies to it. Windows、macOS、iOS 和 Android 仍完全在监管范围内,自 2027 年 1 月 1 日起,这些系统必须在账户设置时收集年龄信息。对于 1 月 1 日之前设置的设备,截止日期则推迟至 2027 年 7 月 1 日。SteamOS 是否在监管范围内尚不明确:其基于 Arch 的系统组件是开源的,但 Valve 在分发系统镜像时捆绑了专有的 Steam 客户端。GrapheneOS(曾在 3 月表示拒绝遵守年龄验证规定)采用开源的 MIT 和 Apache 许可分发,现已完全脱离该法律的管辖范围,尽管它仍受巴西《数字 ECA》的约束。
Assemblymember Buffy Wicks, who wrote both the Digital Age Assurance Act and the AB 1856 amendment, introduced the exemption back in February following criticism from Linux developers and the Electronic Frontier Foundation. 同时起草了《数字时代保障法》和 AB 1856 修订案的众议员巴菲·威克斯(Buffy Wicks),在收到 Linux 开发者和电子前沿基金会(EFF)的批评后,于今年 2 月提出了这项豁免条款。