In a rare show of bipartisan unanimity, California lawmakers have passed a bill that exempts open-source software including Linux from the state’s controversial age-verification law. The California Age-Appropriate Design Code Act (CAADCA), signed in 2022, was designed to protect minors online, but its broad language threatened to sweep in operating systems and developer tools that children might use for school or play.
The new exemption, which passed unanimously in the state legislature, carves out software distributed under standard open-source licenses like the GNU General Public License (GPL), MIT, BSD, and Apache. This means that Linux distributions, programming languages, and other open-source tools will not be required to implement age verification or the law’s other child-safety mandates. The bill now heads to Governor Gavin Newsom’s desk for signature.
Why Open Source Needed an Exemption
The CAADCA, modeled on the UK’s Age Appropriate Design Code, applies to any online service “likely to be accessed by children” under 18. That vague language could easily include educational software, developer tools, and even entire operating systems. Linux, for instance, powers countless school computer labs and coding clubs. Under the original law, a volunteer-run open-source project would have had to implement age verification—an impossible ask for a community of unpaid contributors scattered across the globe.
Open-source software is built differently from commercial products. There’s no central corporation to take responsibility, no HR department to handle compliance, and no legal team to parse the fine print. When a law demands age gates and data minimization, it assumes a business entity that can be held accountable. Open-source projects simply don’t fit that mold.
The Unanimous Vote
The exemption passed without a single dissenting vote in the California legislature. This kind of unanimity is rare, especially on a tech policy issue that touches on child safety. Lawmakers from both parties recognized that the law had overreached in a way that could stifle innovation and education without actually making children safer.
Not Just Linux: The Broad Scope
Although the press has called it the “Linux exemption,” the bill actually covers all software distributed under recognized open-source licenses. That includes the GPL, which governs Linux itself, as well as the MIT, BSD, and Apache licenses used by countless other projects. So a programming language like Python, a web server like Apache, or a database like PostgreSQL all fall under the same carve-out.
This distinction matters. The exemption isn’t about protecting a specific piece of software; it’s about recognizing that open-source development is a fundamentally different beast from commercial software. When code is freely shared and modified by a global community, imposing age-verification requirements would be like demanding a library card to check out a book that’s already in the public domain.
The Practical Impossibility
Consider the typical open-source project. It might have a mailing list, a code repository, and a handful of maintainers who volunteer their time. There is no “business” in the traditional sense. How would such a project verify the age of every person who downloads its code? How would it conduct a Data Protection Impact Assessment, as the CAADCA requires? The answer is that it couldn’t—not without shutting down entirely.
A Win for the ‘Open Source Is Infrastructure’ Argument
This exemption is a victory for the idea that open-source software is akin to public infrastructure. Just as we don’t require age verification to use a public library or a city park, we shouldn’t require it for tools that form the backbone of the digital world. Linux runs on everything from smartphones to supercomputers, and much of the internet’s infrastructure relies on open-source components. Treating these as commercial services would be a category error.
What About Child Safety?
The exemption does not gut the CAADCA. Commercial services that are actually directed at children—think social media platforms, gaming networks, or streaming sites—remain fully subject to the law. The exemption only applies to the software itself, not to services built on top of it. If a company uses open-source code to build a social network, that network still has to comply with age-verification and privacy rules.
Child safety advocates might worry that a loophole could emerge, but the law’s scope is narrow. It’s about the distribution of code, not the operation of a service. A child-directed app distributed under an open-source license would still be subject to the CAADCA if it’s offered as a service. The exemption simply recognizes that open-source code is a tool, not a destination.
The Legal Backdrop
The exemption also comes amid ongoing litigation. The NetChoice v. Bonta case, which challenges the CAADCA’s constitutionality, is still winding through the courts. A federal judge already blocked parts of the law in 2023, ruling that age-verification requirements likely violate the First Amendment. By carving out open-source software, California lawmakers may be trying to salvage the law by narrowing its scope.
Code is speech—a principle established in cases like Bernstein v. USDOJ and Universal City Studios v. Corley. Requiring age verification before distributing code is a prior restraint, which courts view with suspicion. The exemption sidesteps that constitutional minefield for open-source projects, while leaving the rest of the law to face its legal challenges.
What Happens Next
Governor Newsom has not yet signed the bill. If he does, the exemption will take effect immediately, offering relief to open-source developers across the state. The move could also influence other states considering similar child-safety laws, signaling that open-source software needs special consideration.
For now, the open-source community is breathing a sigh of relief. The unanimous vote sends a clear message: open source is not a commercial service, and it shouldn’t be regulated like one.
California’s unanimous exemption of open-source software from its age-verification law is a commonsense fix that recognizes the unique nature of collaborative, community-driven development. It protects innovation and education without compromising child safety, since commercial services remain fully regulated. As other states grapple with how to protect minors online, this move offers a model for how to craft legislation that doesn’t inadvertently crush the digital commons.
Summary
- California lawmakers unanimously passed an exemption to the CAADCA for open-source software under GPL, MIT, BSD, and Apache licenses.
- The exemption addresses the practical impossibility of age verification for volunteer-run projects and the First Amendment issues of restricting code distribution.
- It does not apply to commercial services built on open-source code; those still must comply with the law.
- The bill awaits Governor Gavin Newsom’s signature, and its passage may influence other states’ child-safety legislation.
FAQ
Q: Does the exemption apply only to Linux?nA: No, it covers all software distributed under standard open-source licenses like GPL, MIT, BSD, and Apache. Linux is just the most famous example.
Q: Will this let social media platforms avoid age verification?nA: No. The exemption applies to the software itself, not to services that use it. A social media platform is still subject to CAADCA even if its code is open source.
Q: Why was the exemption needed?nA: Open-source projects often have no central business entity, making compliance with age-verification mandates impossible. The law’s broad language could have swept in educational tools and operating systems used by children.
Q: Is the CAADCA still in effect?nA: Yes, but parts of it are blocked by a federal court ruling in NetChoice v. Bonta. The exemption narrows the law’s scope while the litigation continues.
Q: What happens next?nA: The bill goes to Governor Gavin Newsom. If signed, the exemption takes effect, and open-source developers in California will no longer face age-verification requirements.

Leave a Reply