TL;DR: California lawmakers removed provisions from AB 1856 that would have expanded the state's age-gating system to browsers and websites. The July 1 amendment also keeps an exemption for open-source operating systems. That is a real retreat. It does not erase AB 1043, the law requiring covered operating systems and app stores to collect age information and pass age-bracket signals to online services beginning in 2027.

The Browser Mandate Is Out

California came close to turning browsers into age-verification checkpoints. AB 1856 originally expanded the state's Digital Age Assurance Act beyond operating systems and app stores, reaching browsers and websites. The Electronic Frontier Foundation opposed that version because it would have pushed age checks deeper into ordinary internet access.[1]

The Senate amended AB 1856 on July 1. The current bill history lists Assemblymember Buffy Wicks as the author and shows the measure moving through the Senate after passing the Assembly. The revised text removes the browser and website expansion that drove EFF's opposition.[2]

EFF announced on July 15 that it had removed its opposition after the change. Its position is narrow, not celebratory. The group wrote that “no one should have to provide or verify their age to access the internet.”[1] California stopped this bill from spreading the mandate further. It did not dismantle the system already signed into law.

The Operating-System Age Gate Remains

AB 1043 still requires covered operating-system providers with account setup features to ask an account holder for a user's birth date or age. It then divides users into age brackets and makes those signals available through a secure interface to covered services. For new devices, the requirements begin January 1, 2027. Existing devices must be brought into the system before July 1, 2027.[2]

That changes the privacy bargain at the device level. Before opening an app or visiting a service, a person may have to disclose age information to the software controlling the device. A service receiving the signal is treated as having actual knowledge of the user's age range. The law allows the California attorney general to seek civil penalties of up to $2,500 per affected child for a negligent violation and up to $7,500 for an intentional violation.[2]

EFF argues that no available age-verification option perfectly protects private information, keeps services accessible, and handles sensitive data safely. It also warns that imposing liability based on age signals can push developers toward blocking lawful material rather than accepting legal risk.[3]

This is the same structural problem covered in our age-verification surveillance infrastructure explainer: a rule sold as child protection creates an identity layer that adults must pass through too. Privacy-preserving designs such as the system discussed in our Google Longfellow coverage may reduce disclosure, but they do not answer the first question. Why should routine access require an age credential at all?

Open Source Keeps Its Exemption

AB 1856 also preserves a carve-out for people and organizations distributing software under terms that permit recipients to copy, redistribute, and modify it. EFF reads that language as exempting open-source operating systems from the age-signal requirements.[2][4]

That exemption matters because a volunteer developer cannot operate the same identity infrastructure as a major device company. EFF warned in March that the burden falls especially hard on developers outside large, well-funded companies and can strengthen the dominance of major operating-system vendors.[3]

The carve-out prevents one obvious casualty. It does not protect everyone using a mainstream phone, tablet, or computer covered by the law. Those users still face an age request at account setup and an age-bracket signal that can follow them into covered services.[2]

What to Watch

AB 1856 is still moving through the California Senate. Watch the bill text, not the sales pitch. A later amendment could restore broader coverage or alter the open-source exemption. The legislature's official page records each version and action.[2]

The bigger deadline is January 1, 2027, when the underlying requirements start applying to new devices.[2] Watch how covered operating-system providers ask for age, what they retain, how account holders correct mistakes, and which services request the resulting signal. California pulled back from putting the checkpoint in every browser. It left the checkpoint at the device door.

Sources

  1. Electronic Frontier Foundation: “California Steps Back from Dangerous Expansion of Its Age-Gating Law” (July 15, 2026)
  2. California Legislative Information: AB 1856 bill text, history, and status (2025-2026 session)
  3. Electronic Frontier Foundation: “A.B. 1043's Internet Age Gates Hurt Everyone” (March 12, 2026)
  4. Electronic Frontier Foundation: “One Step Forward, Two Steps Back: CA's AB 1856 Exempts Open Source But Expands Age-Gating” (May 29, 2026)