Skip to Content

The Hidden Danger in California's Child Safety Law That Has Nothing to Do With Kids

The Hidden Danger in California's Child Safety Law That Has Nothing to Do With Kids

Your Operating System Is About to Become Your ID And Nobody's Talking About It

Everyone agrees the internet needs to be safer for children.

That's not the debate. The debate is whether the solution being quietly baked into your operating system: your phone, your laptop, your Linux gaming rig is actually about protecting kids, or whether it's about something far bigger: who controls identity online.

In October 2025, California Governor Gavin Newsom signed AB 1043, the Digital Age Assurance Act, into law. It passed the state Assembly and Senate unanimously. On the surface, it sounds reasonable. On closer inspection, it is one of the most significant shifts in how identity works on the internet in a generation.

Here is what you need to know before January 1, 2027, when it takes effect.


What the Law Actually Does

California's Digital Age Assurance Act does not just ask websites to check whether their users are adults. It moves that responsibility up the stack entirely, to the operating system itself.

Under AB 1043, every operating system provider  anyone who "develops, licenses, or controls" the OS software on a computer, phone, or general-purpose computing device  must collect a user's age at account setup. The law then requires the OS to categorize every user into one of four brackets: under 13, ages 13 to 15, ages 16 to 17, or 18 and older. Whenever an app developer requests it, the OS must beam that age-bracket signal to them in real time via a standardized API.

The law is not limited to iOS or Android. It covers Windows, macOS, and yes, Linux distributions and Valve's SteamOS as well.

Penalties for developers who mishandle these signals run up to $2,500 per affected child for negligent violations and $7,500 for intentional ones. And once a developer receives the signal, they are legally deemed to have "actual knowledge" of the user's age range, triggering a cascade of obligations under COPPA, the CCPA, and California's Age-Appropriate Design Code Act.


Why This Is Bigger Than Child Safety

The stated goal is straightforward: stop making every app reinvent its own age-gate, and instead let the device do it once. There is a real problem this is trying to solve. Age verification fragmented across thousands of apps is inefficient, inconsistent, and frequently bypassed.

But here is where it gets interesting.

Today, most of the world's computing runs on operating systems controlled by two companies: Apple and Google. If age verification becomes a mandatory OS-level function, these companies effectively become the default identity infrastructure for the global internet. Every app developer, from a solo indie developer to a Fortune 500 company, would be legally required to trust Apple or Google's interpretation of who a user is.

That is not a neutral technical plumbing change. It is a consolidation of identity power at a scale that has never existed before.

Developers lose the ability to choose how they verify users. Competitors who want to build alternative identity systems or platforms face a structural disadvantage. And both Apple and Google, who already control app distribution, would now control identity signals within that same ecosystem. The law even includes nondiscrimination provisions to prevent anticompetitive misuse, which suggests lawmakers were at least aware of the risk. But writing rules against a problem and preventing it are not the same thing.

The Electronic Frontier Foundation has put it plainly: these systems create barriers to information access for both adults and minors, particularly in households where multiple family members of different ages share a single device.


The Privacy Architecture Nobody Asked For

Centralizing age signals at the OS level introduces a risk that goes beyond any single law or any single country.

Once operating systems can reliably verify and transmit identity attributes like age, that infrastructure exists. It can be used for its stated purpose today. It can be extended for other purposes tomorrow, in other jurisdictions, under other governments.

China and Russia have already demonstrated willingness to require OS-level content restrictions. A technical layer built for age signals is a technical layer that can carry other signals. That is not a hypothetical. It is how infrastructure works.

Proton, the Swiss privacy company behind ProtonMail, has noted this directly: "Systems built for age verification could become a foundation for wider forms of control."

There are also practical failures baked into the design itself. In multi-device households, the age signal reflects whoever set up the account, not whoever is actually using the device at any given moment. An adult registers a family laptop. The OS sends an adult signal. Every app sees an adult. Children using the same machine bypass the protections the law was designed to create. Meanwhile, an adult who shares a device set up by a minor gets treated as one.

The law also does not require photo ID or biometric verification. Users simply self-report their age at setup. If the goal is child protection, self-reported age from the person who sets up the device is a surprisingly fragile foundation for a nationwide identity infrastructure.


Who Is Watching the Watchmen?

The deeper question underneath all of this is governance.

If Apple decides that a 17-year-old should be restricted from a news app, or that a 16-year-old's age signal should block access to a legal service, there is no clear mechanism for appeal. The operating system is the arbiter. The developer is bound to follow its signal. The user is downstream of a decision made by corporate infrastructure they cannot inspect or challenge.

This is not a hypothetical power. It is the power being handed, by law, to the two companies that already dominate the mobile computing market.

Comprehensive privacy legislation, as the EFF and others have argued, is a more durable path to protecting children online. Laws that restrict data collection, prohibit predatory design, and enforce baseline privacy protections for everyone would benefit children without requiring every adult to register their identity with an operating system.

Protecting children online is a legitimate and urgent goal. The question is not whether to act. The question is whether this particular architecture serves the goal it claims to serve, or whether it quietly serves several other interests at the same time.

The internet's next chapter is being written in legislation most people have never heard of. AB 1043 is one of those laws.

Read it carefully.


Bill Title: Age verification signals: software applications and online services.

Sponsorship: Slight Partisan Bill (Democrat 8-3)

Status: (Passed) 2025-10-13 - Chaptered by Secretary of State - Chapter 675, Statutes of 2025. [AB1043 Detail]
https://legiscan.com/CA/text/AB1043/id/3269704 


🔗 Share this post: https://llmadvocates.com/blog/age-verification-operating-system

About LLM Advocates

LLM Advocates is a specialized law firm registered with the Punjab & Haryana High Court, focusing on cyber law, AI governance, data privacy, and technology-related legal services. Our advocates hold LLM degrees in Cyber Law and are ISO 42001:2023 Certified Lead Auditors.

Meet Our Advocates →
Bot Avatar

LLMbot

Online