State Law Tracker
Laws We Are Violating
A running inventory of US state laws that require operating system providers to collect age data from users — plus adjacent laws that close evasion vectors and so reshape the same compliance landscape — along with Ageless Linux's status for each. Every entry used to read the same way.
Two of them no longer do. Colorado and California have both adopted exemptions for software distributed under licenses that let recipients copy, redistribute, and modify it. California's passed both houses on August 27, 2026 and is awaiting the Governor's signature. Illinois enacted the same age-signal architecture on July 31, 2026 with no exemption at all, which is the more instructive fact about where this is going.
Enacted Laws
States Where Ageless Linux Is Noncompliant
Jan 1, 2027
SCOTUS pending
May 6, 2026
Enforcement → Sep 3
Jul 1, 2027
Jan 1, 2027
Effective Jul 1, 2028
Effective Jan 1, 2028
Passed — Awaiting Signature
The Bill That Would Exempt Us
Passed the Assembly 68-1 (May 26), the Senate with zero no votes (Aug 26 — the daily history records 39-0, the roll call 40-0), and Assembly concurrence 69-0 (Aug 27). Sent to Engrossing and Enrolling Aug 27. Not signed. Gov. Newsom has until Sept 30, 2026 to act.
Note the limit of the carve-out: it amends the definition of "operating system provider" in subdivision (g) only. There is no equivalent exclusion in (e) for "covered application store" or in (f) for "developer." Contrary to widespread reporting, it does not cover code repositories or containers — that language is Colorado's, not California's.
Sign-by Sep 30, 2026
Active Bills
States Working on Becoming Noncompliant
2026
Apr 13, 2026
Jun 29, 2026
Withdrawn
States That Blinked
Apr 6, 2026
International
It's Not Just the United States
Mar 17, 2026
Analysis
Two Models, Same Problem
These laws follow two distinct models, but both create the same compliance moat for open-source operating systems (see Goldman, "Segregate-and-Suppress").
Model A: App Store Accountability (TX, UT, LA)
Focuses on app stores. Requires "commercially reasonable" age verification — which could mean government ID checks. Requires parental consent for minors. Texas was preliminarily enjoined as likely unconstitutional under the First Amendment, but the Fifth Circuit stayed that injunction, the law took effect June 4, 2026, and the Supreme Court declined to re-block it on July 6, 2026 without reaching the merits. Utah is the only state with a private right of action (individuals can sue, not just the AG).
Linux impact: Primarily affects app store operators. If
apt, Flathub, or Snap Store are "covered application stores,"
their maintainers have obligations. Individual distro maintainers face
less direct liability, but the definition is broad enough to sweep them in.
Model B: OS-Level Age Assurance (CA, CO, IL; MI withdrawn)
Focuses on operating system providers. Requires age collection at account setup, real-time API for age signals. California, Colorado, and Illinois accept self-declaration; the federal Parents Decide Act (H.R. 8250) adds parental verification for minors. This is the model that directly targets Linux distributions, because it requires the OS itself to collect and transmit age data.
Linux impact: Colorado and California have now carved free-software distributors out of the definition of "operating system provider." Illinois, enacting the same architecture eight weeks later, did not. The model does not exempt Linux; two of the three legislatures that adopted it chose to, one after direct lobbying by a hardware vendor and one after a year of public argument. That is a lobbying outcome, not a property of the statute, and it has to be won again in every jurisdiction.
Both Models Share One Feature
Apple and Google already comply. The 600+ volunteer Linux distributions cannot. The compliance cost is zero for trillion-dollar platform companies and prohibitive for community projects. Both models passed with overwhelming bipartisan support. Both were supported by the major platform companies.
This is not a coincidence. This is a compliance moat.
The EFF calls this pattern "a windfall for Big Tech and a death sentence for smaller platforms."
Enforcement Timeline
When Things Become Illegal
Ageless Linux compliance status across all jurisdictions, all dates:
NONCOMPLIANT
Penalty Comparison
Cost of Giving a Child a Computer
Private right of action
R$50M cap
Cost of one Ageless Linux device: $12-18
Maximum combined US penalty for one device given to one child:
$46,000
US penalty-to-cost ratio: 3,067:1
Brazil penalty for one violation: up to 522,222:1