Your Computer May Soon Ask for Your Age Before You Log In
Key Takeaways
- California, Colorado, and Illinois have passed laws requiring operating systems to collect users' ages during device setup and share an age bracket with apps — with California's law taking effect January 1, 2027.
- California's Digital Age Assurance Act (AB 1043) currently requires only a self-declared age, but the EFF's Aaron Mackey expects OS providers to demand more invasive verification in practice, including facial scans or government IDs, to avoid legal liability.
- Because tech companies rarely build separate OS versions for different states, the EFF expects a single national age verification system to roll out to all users — including those outside the US.
- California's amended law exempts Linux and open-source operating systems; Illinois's does not.
- A proposed federal Parents Decide Act would require date-of-birth collection at OS level nationwide, with the FTC setting verification standards that could include government ID checks.
For the past several years, age verification laws in the US have targeted websites — particularly adult content platforms. That approach is now shifting to something more fundamental. California, Colorado, and Illinois have passed laws that move the verification requirement to the operating system itself, requiring that Windows, macOS, Android, and ChromeOS ask users for their age during device setup and share an age bracket with every app running on the device.
California's Digital Age Assurance Act (AB 1043) takes effect on January 1st, 2027, and serves as the model the other states followed. Under the law, an OS must collect an age during setup and relay one of four age brackets to apps — under 13, 13–16, 16–18, or over 18.
App developers receiving that signal are legally deemed to have actual knowledge of the user's age range, creating compliance obligations under existing laws like COPPA, which governs how online services handle data from users under 13. Dating apps, gaming platforms, and social media would all be affected. Colorado's equivalent takes effect July 1st, 2028; Illinois's on January 1st, 2028.
The effect is structural. Rather than each app or website independently verifying a user's age — with all the friction and privacy risk that entails — the operating system becomes a central clearinghouse for age data, sharing it outward to every application that asks. That is a meaningful architectural shift, and one that goes well beyond any individual platform's age gate.
Self-Declared Age on Paper, Facial Scan in Practice
California's law, as written, accepts a self-declared age during setup — no ID, no verification. The attorney representing Children Now, the California organization that backed the law, describes this as intentional: the bill was designed to protect privacy by avoiding the government ID uploads required by other states. Her argument is that parents set up devices for their children and will enter accurate ages.
The EFF isn’t convinced that’s how it plays out in practice. Aaron Mackey, the EFF's deputy legal director, told PCMag that "while the law on paper doesn't require strict age verification, I think in practice compliance will look a lot more like age verification." The reason is liability.
If a minor enters a false age and accesses restricted content, the OS provider faces legal consequences — which gives Apple, Google, and Microsoft a strong incentive to require more than a typed number.
Microsoft has already confirmed its system will support verified ages requiring a facial scan or government document. The self-declaration option may exist on paper while the practical path through setup pushes users toward biometric or ID-based verification.
The California law's reach also extends well beyond California. Because Apple, Google, and Microsoft do not build separate operating systems for different states, the EFF expects a single national system to be implemented — one that would apply to every user of those operating systems, including people outside the US entirely. A law passed in Sacramento effectively sets the verification standard for billions of devices worldwide.
The Federal Push and the Open-Source Exception
On the federal level, the proposed Parents Decide Act would require OS providers to collect users' dates of birth nationwide if it passes, with the FTC setting verification standards that could include government identification checks.
The Kids Online Safety Act, introduced in the Senate in 2025, would require a formal study on the most feasible methods of OS-level age verification. Neither has passed, but both are advancing, and the EFF considers the legislative direction a serious trend rather than an isolated state experiment.
The open-source community has pushed back with some success. California's amended law, updated in September 2026, now exempts operating systems distributed under open-source license terms — a change the EFF described as a genuine win. Colorado's law similarly exempts Linux distributions. Illinois's law doesn’t, applying the same requirements to open-source operating systems as to closed-source ones.
GrapheneOS, a privacy-focused Android fork, has already stated publicly that it intends to remain usable without collecting personal information, adding that if its devices cannot be sold in a region due to local regulations, "so be it." That position may prove untenable in Illinois, and in any federal regime that follows.
What This Means Beyond Child Safety
The stated purpose of these laws is child protection — ensuring minors cannot access age-restricted apps or services without a parent's involvement. The mechanism chosen to deliver that protection is a persistent age signal embedded in the operating system, shared with every app on the device, and in practice likely backed by biometric or identity document verification at setup.
Aaron Mackey put the broader concern directly: "The open internet as we know it allows people to access information anonymously, privately, and securely. It's in danger from lawmakers who have good intentions but are writing broad laws." An OS that knows your age and is legally required to share it with every app it runs is infrastructure that can be pointed at other questions.
The age bracket the OS shares today is determined by what current laws require. What future laws might require it to share is a question the architecture being built right now will be used to answer.
Be part of the resistance, quietly.
Get Mysterium VPN

Gintarė is a cybersecurity writer at Mysterium VPN, where she explores online privacy, VPN technology, and the latest digital threats in editorial pieces. With hands-on experience researching and writing about data protection and digital freedom, Gintarė makes complex security topics accessible and actionable.
