US states adopt operating system age checks to enhance child safety and privacy

A wave of US states is implementing laws that require operating systems like Windows, macOS, Android, ChromeOS, and Linux to verify user age during device setup, signalling a shift towards integrated age checks at the device level and raising privacy and regulatory implications.

Age checks are no longer confined to social networks and adult sites. In the US, a new wave of state laws is pushing age verification down into the operating system itself, creating the prospect that Windows, macOS, Android, ChromeOS or even Linux could be asked to identify a user’s age during device setup before apps are allowed to respond accordingly. California’s Digital Age Assurance Act is due to take effect on 1 January 2027, while Colorado and Illinois have adopted similar measures with later start dates, placing the issue squarely in the mainstream of technology policy.

California’s law is the most consequential because it is the template others are following. Under AB 1043, the operating system must request an age or age bracket at setup and then pass a signal to applications showing whether the user is under 13, 13 to 16, 16 to 18 or over 18. The law does not force users to upload identity documents, and the California bill text instead allows a simple declaration at setup. But legal specialists and privacy campaigners say that, in practice, platforms may decide that stronger verification is the only reliable way to stop children from bypassing the system. The law also treats app makers as having actual knowledge of a user’s age band, which could matter for services governed by child-safety or privacy rules.

Colorado has adopted a similar framework through SB26-051, known as Age Attestation on Computing Devices. The measure requires an accessible age prompt during account setup and shares that information with applications in the covered app store ecosystem. Colorado’s legislation goes further than California’s in one important respect: it explicitly exempts operating systems distributed under open-source licences that allow copying, redistribution and modification. Fiscal documents released by the state also show that lawmakers expect the bill to affect app developers handling personal data, while creating some new administrative costs for state agencies that publish downloadable apps.

Illinois has passed its own version, the Children’s Online Social Media Safety Act, with an effective date of 1 January 2028. The Illinois measure, like California’s, reaches both closed and open-source software. At the federal level, meanwhile, the Parents Decide Act would require operating system providers to collect a date of birth at setup and would leave the Federal Trade Commission to write the rules for verifying a parent or legal guardian when a minor is involved. Separately, the Kids Online Safety Act would direct the Commerce Department to study the most technically feasible ways to verify age at the device or operating system level, showing that the debate has moved well beyond one state or one political bloc.

The technical mechanism is straightforward, even if the policy implications are not. In practice, the operating system would expose an age range through an application programming interface, or API, which apps could then query. Google already has a Play Age Signals API for Android apps, Apple has introduced a Declared Age Range API for iOS and macOS, and Microsoft has said Windows will offer a similar interface. That makes the policy easier to enforce at scale, but it also broadens the privacy stakes. Open-source developers have warned that they are being pushed towards collecting personal data they were designed to avoid, while privacy groups argue that the result could be a weaker model of software distribution in which even small projects face legal exposure if a user lies about their age.

The wider legal direction is what worries critics most. California has not extended its law to browsers or websites, but lawmakers there are already considering a separate bill that would do so, and browser vendors are experimenting with digital credentials that can carry identity information to a website. That leaves a clear possibility that age checks could move from apps to the device, then from the device to the browser and eventually into the infrastructure of the web itself. Supporters describe the approach as a privacy-preserving compromise because it starts with self-attestation rather than demanding an identity document. Opponents see the beginning of a surveillance layer built into everyday computing.

Disclaimer: This content is intended for informational purposes only. Readers are advised to exercise their own judgement, conduct due diligence, or consult a qualified expert before acting on any information provided.