California’s Digital Age Assurance Act (DAAA) will require covered operating-system providers to collect a user’s age during device setup and transmit a non-identifying age-bracket signal to application developers. The mandate begins January 1, 2027 for devices newly configured in California, with devices configured before that date coming into scope on July 1, 2027.
California legislators have passed AB 1856, pending the governor’s decision, to exempt qualifying open-source operating-system providers. The measure has prompted privacy and implementation concerns, including from the Electronic Frontier Foundation and open-source projects; Colorado has enacted related age-attestation requirements with open-source exemptions, while Illinois and New York are considering comparable legislation.

See the reporting duties and controls this puts on the clock.
9 events from the most recent confirmed update back to the earliest known activity.
California signed the Digital Age Assurance Act (DAAA) into law. The law requires operating-system providers to collect a user’s age during initial setup and permits them to provide developers with a non-identifying age-bracket signal.
Fedora was reported to be planning age-assurance implementation despite potential open-source exemptions.
New York has an age-assurance bill under consideration.
California lawmakers passed AB1856, which would amend the DAAA to exempt qualifying open-source operating-system providers. No California lawmaker voted against the bill, which was awaiting the governor’s decision.
Illinois passed legislation imposing age-assurance requirements.
Colorado legislators added exemptions for open-source software to SB26-051 after lobbying by Linux hardware maker System76.
Colorado enacted SB26-051, establishing age-assurance requirements similar to California’s DAAA.
GrapheneOS said it would not implement age verification and might stop selling devices in jurisdictions that impose such requirements.
California Assemblymember Buffy Wicks introduced the original Digital Age Assurance Act, establishing proposed operating-system-level age-assurance requirements.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See what this changes for your reporting obligations and which controls it puts on the clock.
6 references tracked. Mallory keeps watching after this page renders.
malware.news
Open sourcemalwarebytes.com
Open sourceeff.org
Open sourceleginfo.legislature.ca.gov
Open sourceleg.colorado.gov
Open sourceleginfo.legislature.ca.gov
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.