Why Your Next Computer May Legally Demand Your Age — and Possibly an ID
Age verification rules that once targeted only adult websites and social media apps are now reaching deeper into the technology stack. Starting in 2027, new U.S. state laws will require operating systems themselves — Windows, macOS, Android, ChromeOS, and potentially others — to collect a user’s age during device setup and pass that information to apps. While the current laws emphasize self-declaration rather than mandatory government ID uploads, privacy advocates warn that real-world compliance pressures could push companies toward stricter checks, including identification documents. The result is a quiet but significant shift: the computer or phone you buy next year may treat your age as a required piece of setup data.
The most immediate driver is California’s Digital Age Assurance Act (AB 1043). Signed into law in October 2025 and taking effect January 1, 2027, the statute requires operating system providers to present an interface at account setup that asks for the user’s birth date, age, or both. The system then generates a standardized age-bracket signal — under 13, 13 to under 16, 16 to under 18, or 18 and older — and makes it available to app developers through a real-time application programming interface. Developers who receive the signal are “deemed to have actual knowledge” of the user’s age range. That knowledge triggers obligations under existing rules such as the federal Children’s Online Privacy Protection Act (COPPA) and various state privacy laws. Dating apps, social platforms, games, and other services may restrict features or content accordingly.
California lawmakers deliberately avoided requiring government IDs. Supporters, including data privacy attorney Nichole Rocha of Children Now, emphasize that the design prioritizes privacy: simple attestation is sufficient, and parents who set up devices for children are expected to enter accurate information. Penalties for noncompliance are meaningful — up to $2,500 per affected child for negligent violations and $7,500 for intentional ones — yet the law shields companies that make a good-faith effort from liability for erroneous signals. For devices already in use before 2027, providers have until July 1, 2027, to offer a way for users to supply age data.
Colorado followed with its own measure (SB26-051), signed in June 2026 and effective July 1, 2028. The Colorado law is similar in structure but includes an explicit exemption for open-source operating systems distributed under licenses that allow unrestricted copying, redistribution, and modification. California later moved toward a comparable carve-out through amendments, responding to intense pushback from the Linux and free-software communities. Without such exemptions, the original broad language risked placing liability on maintainers of distributions that lack centralized account systems or commercial distribution models.
These state laws do not exist in isolation. A federal proposal known as the Parents Decide Act (H.R. 8250), introduced in April 2026 by Representatives Josh Gottheimer and Elise Stefanik, would impose nationwide requirements. It directs operating system providers to collect a user’s date of birth before account setup or use of the system. For anyone under 18, a parent or legal guardian must verify the age. Providers must also create a mechanism allowing app developers to access the necessary age information. The Federal Trade Commission would write the detailed rules within 180 days of enactment, including standards for verifying parental status and securing the collected data. Those regulations could open the door to stronger verification methods.
In practice, the distinction between “age assurance” and full identity verification may blur. On paper, California accepts self-declaration. In reality, companies face fines if minors bypass the system and access restricted content. Aaron Mackey of the Electronic Frontier Foundation has argued that liability pressure will encourage more invasive approaches — credit-card checks, facial scans, or government ID uploads — similar to those already used by adult websites. Major vendors are already building the technical infrastructure. Google offers a Play Age Signals API, Apple has a Declared Age Range API, and Microsoft has indicated Windows will support comparable functionality. Even Linux components such as systemd have added age fields to user accounts in anticipation of the requirements.
The move from website-level checks to the operating system is deliberate. Adult platforms have long complained that they alone bear the cost and privacy burden of age gates. Shifting the obligation upstream means the device itself becomes the gatekeeper. Apps no longer need to collect documents independently; they simply query the OS. California’s current law stops short of requiring browsers to pass the age signal to websites, though follow-on legislation has been discussed. Browser makers, meanwhile, continue developing Digital Credentials APIs that could eventually link government IDs stored in digital wallets to online services.
Privacy implications are substantial. Collecting and sharing age data at the system level reduces the anonymity that has long characterized general-purpose computing. Because major operating system makers rarely maintain separate versions for different states, California’s rules are likely to influence devices sold far beyond its borders. Open-source developers have voiced particular alarm. Community-driven projects prioritize minimal data collection and user freedom; mandates that require age tracking create both technical and legal headaches. Some projects have stated they will not implement such features even if it limits distribution in regulated markets. Exemptions in Colorado and proposed changes in California offer partial relief, yet the federal bill contains no such carve-out.
Supporters frame the laws as a practical response to the difficulty of protecting minors in an environment filled with social media, algorithmic recommendations, and generative AI. Self-reported ages on individual sites have proven easy to circumvent. Placing the check at the device level, they argue, creates a more consistent baseline and gives parents clearer tools. Critics counter that the approach expands surveillance infrastructure, creates attractive targets for data breaches, and risks chilling legitimate use by adults and teenagers alike. Birth dates, once collected and shared across apps, cannot be changed if compromised.
**Why Your Next Computer May Legally Demand Your Age — and Possibly an ID**
Age verification rules that once targeted only adult websites and social media apps are now reaching deeper into the technology stack. Starting in 2027, new U.S. state laws will require operating systems themselves — Windows, macOS, Android, ChromeOS, and potentially others — to collect a user’s age during device setup and pass that information to apps. While the current laws emphasize self-declaration rather than mandatory government ID uploads, privacy advocates warn that real-world compliance pressures could push companies toward stricter checks, including identification documents. The result is a quiet but significant shift: the computer or phone you buy next year may treat your age as a required piece of setup data.
The most immediate driver is California’s Digital Age Assurance Act (AB 1043). Signed into law in October 2025 and taking effect January 1, 2027, the statute requires operating system providers to present an interface at account setup that asks for the user’s birth date, age, or both. The system then generates a standardized age-bracket signal — under 13, 13 to under 16, 16 to under 18, or 18 and older — and makes it available to app developers through a real-time application programming interface. Developers who receive the signal are “deemed to have actual knowledge” of the user’s age range. That knowledge triggers obligations under existing rules such as the federal Children’s Online Privacy Protection Act (COPPA) and various state privacy laws. Dating apps, social platforms, games, and other services may restrict features or content accordingly.
California lawmakers deliberately avoided requiring government IDs. Supporters, including data privacy attorney Nichole Rocha of Children Now, emphasize that the design prioritizes privacy: simple attestation is sufficient, and parents who set up devices for children are expected to enter accurate information. Penalties for noncompliance are meaningful — up to $2,500 per affected child for negligent violations and $7,500 for intentional ones — yet the law shields companies that make a good-faith effort from liability for erroneous signals. For devices already in use before 2027, providers have until July 1, 2027, to offer a way for users to supply age data.
Colorado followed with its own measure (SB26-051), signed in June 2026 and effective July 1, 2028. The Colorado law is similar in structure but includes an explicit exemption for open-source operating systems distributed under licenses that allow unrestricted copying, redistribution, and modification. California later moved toward a comparable carve-out through amendments, responding to intense pushback from the Linux and free-software communities. Without such exemptions, the original broad language risked placing liability on maintainers of distributions that lack centralized account systems or commercial distribution models.
These state laws do not exist in isolation. A federal proposal known as the Parents Decide Act (H.R. 8250), introduced in April 2026 by Representatives Josh Gottheimer and Elise Stefanik, would impose nationwide requirements. It directs operating system providers to collect a user’s date of birth before account setup or use of the system. For anyone under 18, a parent or legal guardian must verify the age. Providers must also create a mechanism allowing app developers to access the necessary age information. The Federal Trade Commission would write the detailed rules within 180 days of enactment, including standards for verifying parental status and securing the collected data. Those regulations could open the door to stronger verification methods.
In practice, the distinction between “age assurance” and full identity verification may blur. On paper, California accepts self-declaration. In reality, companies face fines if minors bypass the system and access restricted content. Aaron Mackey of the Electronic Frontier Foundation has argued that liability pressure will encourage more invasive approaches — credit-card checks, facial scans, or government ID uploads — similar to those already used by adult websites. Major vendors are already building the technical infrastructure. Google offers a Play Age Signals API, Apple has a Declared Age Range API, and Microsoft has indicated Windows will support comparable functionality. Even Linux components such as systemd have added age fields to user accounts in anticipation of the requirements.
The move from website-level checks to the operating system is deliberate. Adult platforms have long complained that they alone bear the cost and privacy burden of age gates. Shifting the obligation upstream means the device itself becomes the gatekeeper. Apps no longer need to collect documents independently; they simply query the OS. California’s current law stops short of requiring browsers to pass the age signal to websites, though follow-on legislation has been discussed. Browser makers, meanwhile, continue developing Digital Credentials APIs that could eventually link government IDs stored in digital wallets to online services.
Privacy implications are substantial. Collecting and sharing age data at the system level reduces the anonymity that has long characterized general-purpose computing. Because major operating system makers rarely maintain separate versions for different states, California’s rules are likely to influence devices sold far beyond its borders. Open-source developers have voiced particular alarm. Community-driven projects prioritize minimal data collection and user freedom; mandates that require age tracking create both technical and legal headaches. Some projects have stated they will not implement such features even if it limits distribution in regulated markets. Exemptions in Colorado and proposed changes in California offer partial relief, yet the federal bill contains no such carve-out.
Supporters frame the laws as a practical response to the difficulty of protecting minors in an environment filled with social media, algorithmic recommendations, and generative AI. Self-reported ages on individual sites have proven easy to circumvent. Placing the check at the device level, they argue, creates a more consistent baseline and gives parents clearer tools. Critics counter that the approach expands surveillance infrastructure, creates attractive targets for data breaches, and risks chilling legitimate use by adults and teenagers alike. Birth dates, once collected and shared across apps, cannot be changed if compromised.
As of early August 2026, only California and Colorado have enacted operating-system-level requirements, with California’s rules arriving first. Other states continue to debate similar bills, and federal legislation remains in the early stages. Implementation details will matter enormously. Whether companies stick to simple attestation or adopt stronger verification methods will determine how intrusive the new setup screens feel. For users buying a new computer or phone in the coming years, age will no longer be an optional detail during initial configuration. It will be part of the legal architecture of the device itself — a quiet but consequential change in how personal computing intersects with child-safety regulation.As of early August 2026, only California and Colorado have enacted operating-system-level requirements, with California’s rules arriving first. Other states continue to debate similar bills, and federal legislation remains in the early stages. Implementation details will matter enormously. Whether companies stick to simple attestation or adopt stronger verification methods will determine how intrusive the new setup screens feel. For users buying a new computer or phone in the coming years, age will no longer be an optional detail during initial configuration. It will be part of the legal architecture of the device itself — a quiet but consequential change in how personal computing intersects with child-safety regulation.