U.S. senators push for nationwide OS-based age verification law amid open-source backlash

Four U.S. senators have introduced the Digital Age Assurance Act, proposing that operating systems on phones and computers verify user ages to better protect minors, sparking debate over privacy and open-source compatibility.

Four U.S. senators have introduced federal legislation that would require operating systems on phones and computers to verify a user’s age before granting full access to apps and some online services, a move that would extend a model already being tested in California and Colorado. According to the senators’ announcement, the Digital Age Assurance Act is intended to shift age checks from individual apps to the device itself, with the aim of making compliance more consistent and reducing the need for repeated data entry across platforms.

The bill was introduced by Andy Kim, Adam Schiff, Cynthia Lummis and John Barrasso, who said the measure would let operating system providers collect age information and share only the relevant age signal with app developers. Their proposal also includes privacy language, including bans on the sale or transfer of children’s data and on targeted advertising to minors, according to Kim’s office. Supporters argue that current app-level birthdate prompts are too easy to fake and too uneven to protect children effectively.

California’s law, AB 1043, is already set to take effect on January 1, 2027, and would require operating system providers to collect age information during account set-up, categorise users into age brackets and make that information available to app developers through an application programming interface, or API. Tom’s Hardware reported that the law covers major desktop and mobile systems, including Windows, macOS, Android and iOS, and sets fines of $2,500 to $7,500 per child for violations. Colorado has taken a somewhat different path, placing more emphasis on parental consent mechanisms for minors.

The California approach has already drawn resistance from parts of the open-source community. Reports from Tom’s Hardware and Windows Central said lawmakers there are now considering an exemption for most open-source systems, after backlash over the practical difficulty of requiring decentralised projects such as Debian, Fedora and Ubuntu to collect user ages at set-up. That debate highlights a central weakness in device-level age verification: the policy is easier to define for tightly controlled platforms than for software that can be modified and redistributed by anyone.

For now, the federal measure remains a committee bill rather than enacted law, so nationwide requirements are not yet in force. But the overlap between the federal proposal and the California model suggests the debate is moving towards a broader question: whether age assurance should be treated as an app-by-app problem or as a function built into the operating system itself. That choice will shape not only compliance costs for Apple, Google, Microsoft and other platform owners, but also how much personal data families must hand over simply to use a device.

Disclaimer: This content is intended for informational purposes only. Readers are advised to exercise their own judgement, conduct due diligence, or consult a qualified expert before acting on any information provided.