Security1 distinct publisher2 min readPublished
Windows, macOS, iOS and Android will collect an age at setup under the Digital Age Assurance Act. The bracket they return to an app on request becomes stored minor data the moment a developer writes it to the user record.
The Watch · Security desk
Compiled by The WatchSomething wrong?How this is made
The bracket has to be fetched. The operating system holds it, and the developer asks the OS provider or the app store for it when someone downloads and launches the app, which is the moment the developer becomes legally aware of who is on the other end [5]. Three of the four brackets describe minors [1], so for most apps the return value works as a minor flag with two thresholds inside it.
Retention is the unsettled part. Malwarebytes describes the signal as non-identifying [4] and sets out no retention or deletion duty for the developer that receives it [17]. Two implementations follow. One queries at launch, branches on the answer, and writes nothing. The other stores the bracket on the user record, and from then on the app holds an age-of-minority attribute tied to an account, available in a breach and discoverable in litigation.
The two compliance dates sit six months apart [2], so a California user base spends the first half of 2027 mixed: some devices can answer the query, some cannot yet [2]. Treating a missing bracket as 18+ defeats what the state says it is after, which is keeping children out of apps built for adults [6]. Treating it as under 13 locks out adults. Somebody picks a default, and that default is policy written as an if-statement.
Platform coverage is the other variable. GrapheneOS settled its position in March: it will not implement age verification, and it will give up device sales in affected regions if that is the price [10]. Fedora is reported to be going ahead with age assurance regardless, which is reporting rather than confirmation [13]. The pending exemption covers software under licenses including GPL, MIT, BSD and Apache [8], so the set of platforms able to answer a query will be narrower than the set your users run.
The EFF's objection is that California has outsourced censorship to developers instead of dealing with privacy [7]. The pull for age signals is visible next door: AB1709 would restrict addictive social media features for under-16s [14], Meta has agreed to time limits on children's social network use as part of a court settlement [15], and measures of that kind need some form of age assurance to function [16]. Three states now have age-bracket laws enacted and New York has a bill in progress [3], and Colorado's arrived with its own open-source carve-out after the Linux hardware maker System76 lobbied for one [11]. The reporting does not describe Colorado's boundaries, so the four ranges belong in configuration rather than in a constant.
Ranked by verification strength, evidence, and original report placement.
California's Digital Age Assurance Act, signed into law in October 2025, requires Windows, macOS, iOS and Android to start collecting a user's age at first setup in California from January 1, 2027.
Operating systems set up in California before January 1, 2027 will need to collect the user's age by July 1, 2027.
Operating systems will categorise people into four age brackets: under 13, 13-15, 16-17, and 18+.
Operating systems will be able to send a non-identifying age signal to app developers.
Developers must request the age signal from the operating system provider or app store when someone downloads and launches an app, which makes them legally aware of the person's age bracket.
California's stated aim is to stop children from doing things that could hurt them, such as downloading apps containing mature content meant only for adults.
Distinct publishers with included, body-backed reporting in this cluster.
1 article · September 3, 2026
Follow any of these and your For You feed starts watching them — no settings page required.
security
Chatbot Logs Are Entering Discovery. OpenAI's User-Content Disclosures Quadrupled.1 distinct publisher
invest
Meta has 12 months to make its age-guessing AI survive an outside audit1 distinct publisher
invest
Nvidia stops eating memory costs: AI server prices up more than 15% on early-2027 shipments1 distinct publisher
security
Nine in ten toll scams reach victims by text or email in Malwarebytes' 91-day sample1 distinct publisher
Evidence-backed comparisons of source perspectives and observed adoption signals. Read the methodology
Which Builder, Operator, and Investor concerns the observed source mix emphasized—not a truth score.
Evidence, demonstrated adoption, hype gap, incentives, and confidence are assessed independently, each on its own current evidence. How these are measured.
One security-vendor blog, no statute in sight
Everything load-carrying in this story — the two deadlines, the four brackets, the unanimous AB1856 vote — arrives from a single consumer-security blog with no statute text, no bill links and no comment from Microsoft, Apple or Google. These are checkable public-record facts, which is why the score isn't lower; the trouble is that nobody in our coverage has checked them, and the softest items come pre-hedged with "reportedly".
A mandate with sixteen months to run and one observed refusal
No operating system in this story has shipped an age prompt, because none has to yet. The only behaviour anyone has actually watched is a project opting out: GrapheneOS saying in March it would trade device sales for not verifying ages. Fedora's reported intention to comply anyway is the sole pull in the other direction, and it is second-hand.
Calm reporting, forward-leaning inference
Malwarebytes itself under-sells rather than over-sells: a birthdate box is coming, here is an open-source alternative. The stretch is on our side of the line. Calling the bracket stored minor data assumes a developer writes it down, and this reporting establishes no retention duty, no deletion duty and no observed developer behaviour either way. The mechanic is real; the consequence is still an inference.
Three interested parties in the story, one more publishing it
Every actor here is playing their own book and it is all visible: the EFF campaigning against age verification, System76 lobbying Colorado into an open-source carve-out, GrapheneOS converting non-compliance into brand. Then the piece closes a privacy-law explainer with an invitation to download Malwarebytes. Buffy Wicks writing both the mandate and its exemption is authorship rather than conflict, but it is worth saying out loud.
Solid on Sacramento, vaguer with every state line crossed
Named bills, named licences and named dates make the California core dependable enough to plan against. Confidence drains as the piece travels — unnamed Illinois legislation, a New York bill "in the works", a hedged Fedora plan — and the whole thing rests on one publisher describing a compliance mechanic that no shipping product has yet demonstrated.