Last updated: 9 August 2026. This is a living page. I update it as laws pass, take effect, get enjoined, or die in committee. Every claim here is sourced to a bill page, an enacted statute, or a court docket — not to a summary of a summary. Where I could not verify something, I say so rather than quietly dropping it.
I started this tracker because I kept getting the same question in different forms: is the thing I read about real, and does it apply to me? The honest answer is that it depends on which of about forty overlapping laws you mean, and most coverage does not distinguish between a bill filed, a bill passed, a law in effect, and a law currently blocked by a federal judge. Those are four very different things and only one of them changes what happens when you pick up your phone.
So: the whole board, in one place.
The one thing to understand first
Age verification is not a website problem any more. It has been moving down the stack for five years, and each layer down is harder to route around than the one above it.
![]()
When the check lived on the website, you could choose not to visit the website. When it moved to the app store, you could sideload. Now it is moving into the operating system — and in Illinois, into any internet-enabled device including your laptop.
That last step is the one worth paying attention to, because an age attribute that lives in the OS and is queryable by any application is a new thing in the world. It is a persistent, always-on identity primitive that did not exist before. Once it exists, the question stops being "should we have this" and becomes "what else should it return."
Where the laws are
![]()
A note on the counts, because published figures disagree and I would rather explain the disagreement than pick a number and look authoritative. Sources put the harmful-content total anywhere from 25 to 27 depending on whether they count laws enacted or laws in force, and depending on whether they have caught up with the two 2026 additions. My count is 27 enacted, listed below with dates. If you see 25 somewhere, that source is probably counting states with laws already in force as of early 2026 and has not added West Virginia or Iowa.
Tier 1 — the operating system and device laws
Three states have enacted these. They are the reason this page exists.
| State | Law | Signed | Effective | Open source exempt? |
|---|---|---|---|---|
| California | AB 1043, Digital Age Assurance Act | 13 Oct 2025 | 1 Jan 2027 | No — AB 1856 would add one, see below |
| Illinois | HB 5511, P.A. 104-0664 | 31 Jul 2026 | 1 Jan 2028 | No |
| Colorado | SB26-051, Age Attestation on Computing Devices | 3 Jun 2026 | 1 Jul 2028 | Yes |
California AB 1043 requires operating system providers to present an interface at account or device setup collecting the user's birth date or age, then expose an age signal to apps and app stores through a real-time API. Every new phone and tablet sold in California will classify its user by age range at first boot. Penalties run up to $7,500 per affected child.
Colorado SB26-051 does the same thing, with a longer runway and a materially better exemptions section. Passed the Senate 28–7 and the House 40–23. Devices set up before 1 July 2028 need a retrofit interface before 1 January 2029.
Illinois P.A. 104-0664 is the newest, the broadest, and the one almost nobody covered properly — including me, until this week. It passed the Illinois Senate 57–0 and cleared House concurrence 113–0. Not one recorded no vote at the end.
Its scope is worth reading slowly. "Covered manufacturer" means a manufacturer of an internet-enabled device, an operating system provider, or an application store — three categories, not one. "Operating system provider" is defined as "a commercial or non-profit entity that controls the Internet-enabled device's operating system." The words non-profit are in the statute. And "internet-enabled device" is defined to include personal laptops and desktop computers, not just phones.
Read those three definitions together and the law reaches a non-profit foundation distributing a free operating system for a laptop. That is not a strained reading. That is the plain text.
To be fair to Illinois, parts of the drafting are genuinely more careful than Colorado's. The signal is shared only on separate prior user consent for a specific operator. Signals must be encrypted. An operator may request a signal no more than once a year. And "deemed actual knowledge" is scoped to the specific device rather than following you across every platform, which is how Colorado wrote it. Those are real privacy improvements and I will not pretend otherwise.
The problem is who it applies to, and what it does not exempt.
The open-source question
This is the part of the story that matters most if you run Linux, GrapheneOS, LineageOS, or anything else you compiled yourself.
![]()
Colorado wrote an exemption, and it is smarter than it has been reported. Section 6-30-105(3)(e) of the enacted act exempts:
an operating system provider or developer that distributes an operating system or application under license terms that permit a recipient to copy, redistribute, and modify the software without any platform-imposed technical or contractual restrictions imposed by the provider or developer on installing all modified versions.
Almost every write-up of this clause stops after "copy, redistribute, and modify" and calls it a Linux exemption. The rest of the sentence is the whole sentence. This is not a test of what licence you use — it is a test of whether the people shipping the software let you install your own modified build. It is an anti-lockdown provision. A signed, unlockable bootloader fails it regardless of how many GPL components are inside.
I have seen the claim circulating that this exemption covers BSD but excludes GPL code, on the theory that copyleft counts as a "restriction." Having read the enacted text, I do not think that holds — the restriction the statute cares about is one imposed on installing modified versions, which is precisely what GPLv3's anti-tivoization language exists to guarantee. That analysis was published in April and the language moved afterwards. I would not assert it either way on air without a court or an AG opinion, but I would not repeat the GPL claim as settled either.
Colorado also excludes free public code repositories from the definition of "covered application," and excludes code repository providers and containerised software distribution from "covered application store." GitHub, GitLab, Docker and Podman-style distribution stay out of scope.
California is four days from a hard deadline as I write this. AB 1856, authored by the same legislator who wrote AB 1043, would add the same style of carve-out. It was placed on the Senate Appropriations suspense file on 3 August, the suspense hearing is 13 August, and the last day for either house to pass bills is 31 August. The suspense file is where California bills go to die quietly. If AB 1856 does not come off it, AB 1043 takes effect on 1 January 2027 with no open-source exemption at all. The EFF removed its opposition to AB 1856 after the open-source exemption was added and the plan to extend age-gating to browsers and websites was dropped — while maintaining that AB 1043 itself is unconstitutional.
Illinois shipped with nothing. I read the enrolled text end to end. The only exemptions in the Act are for entities whose primary purpose is news media, and for broadband internet access providers. There is no licence-based carve-out, no repository carve-out, no container carve-out. Colorado has all three. Illinois has none, and its definitions explicitly reach non-profits and laptops.
Neither federal bill — S. 5090 nor H.R. 8250 — contains an open-source exemption in any published summary I have found. I have not been able to confirm that against the full bill text, so treat that as absence of evidence rather than confirmed absence.
Every deadline that matters
![]()
| Date | What happens |
|---|---|
| 13 Aug 2026 | California Senate Appropriations suspense hearing — AB 1856 lives or dies |
| 14 Aug 2026 | Last day for California fiscal committees to report bills |
| 28 Aug 2026 | Missouri harmful-content AV law takes effect. Covers sites where more than a third of content is harmful to minors. $10,000/day, up to $250,000 if a minor gets through |
| 31 Aug 2026 | Last day for either California house to pass bills |
| 3 Sep 2026 | Utah SB 73 VPN provisions become enforceable |
| 1 Jan 2027 | California AB 1043 (OS age signals); California SB 976; Alabama app store law; South Carolina HB 4591; New Hampshire HB 1460 |
| 6 May 2027 | Utah app store law — full compliance deadline |
| 1 Jul 2027 | Minnesota HF 4138; California AB 1043 transition period ends |
| 1 Jan 2028 | Illinois P.A. 104-0664 — manufacturer interface deadline |
| 1 Jul 2028 | Colorado SB26-051 takes effect; Illinois operator signal requests begin; Illinois retrofit deadline |
| 1 Jan 2029 | Colorado retrofit deadline for devices set up before July 2028 |
Tier 2 — app store laws
Four states, and these are already live. The detail most coverage misses: they apply to all apps available to residents of the state, not just apps aimed at children. A flashlight app has compliance obligations.
| State | Law | Effective |
|---|---|---|
| Texas | SB 2420 | 1 Jan 2026 — enforceable now |
| Utah | App Store Accountability Act | Staged: provider duties 6 May 2026, full compliance 6 May 2027 |
| Louisiana | App Store Accountability Act | 1 Jul 2026 |
| Alabama | HB 161 | 1 Jan 2027 |
Apple and Google have both built for this. Apple's Declared Age Range API returns an age category — under 13, 13–16, 16–18, 18+ — along with signals about how that age was assured, without exposing a birth date. Google Play's Age Signals API is in beta doing the same job.
I want to be straight about this: the Declared Age Range design is the least-bad engineering in this entire space. Bands instead of birth dates, with assurance metadata. If you have to build the thing, that is roughly how you would build it. The problem is not the current field list. The problem is that once the OS knows your age band and every app can query it, nothing about the architecture stops a future statute from widening what the API returns. Good version-one design does not constrain version three.
Tier 3 — harmful-content laws, 27 states
These are the "upload your ID to visit an adult site" laws, generally scoped to sites where a third or more of the content is sexual material harmful to minors. The Supreme Court upheld the Texas version in Free Speech Coalition v. Paxton in June 2025 under intermediate scrutiny, which is why the count has climbed so fast since.
Enacted 2023: Arkansas, Louisiana, Mississippi, Montana, North Carolina, Texas, Utah, Virginia
Enacted 2024: Alabama, Idaho, Indiana, Kansas, Kentucky, Nebraska, Oklahoma
Enacted 2025: Arizona, Florida, Georgia, Missouri, North Dakota, Ohio, South Carolina, South Dakota, Tennessee, Wyoming
Enacted 2026: West Virginia (HB 4412, effective 12 June), Iowa (HF 864, signed 4 June, effective 1 July), Missouri (expanded, effective 28 August)
Eight more states have pending bills, including Ohio HB 84, Michigan SB 191 and Pennsylvania SB 603.
The VPN front
This one goes directly at the toolkit, so I want to be precise about it.
Utah SB 73 is the only enacted US law targeting VPN use around age gates. It does not ban using a VPN. What it does is make you a Utah user for liability purposes even when you connect through one, and it prohibits covered platforms from providing instructions, assistance, or encouragement about using a VPN to bypass verification. That second part is a speech restriction on privacy education wearing a child-safety hat.
The VPN provisions are not yet enforced. Utah's Department of Commerce and Aylo agreed on 27 April to defer enforcement until 3 September 2026 while the challenge proceeds. Anyone telling you Utah is currently enforcing a VPN ban is wrong. Aylo's argument is worth understanding: if Utah residents can reach a site through a VPN from anywhere, then verifying "Utah users" means verifying everyone on earth. A state law becomes a global standard by accident.
Michigan has a filed bill that goes further — it would reach the promotion or sale of circumvention tools — but it has no hearing scheduled.
Wisconsin is the interesting one, and I had it wrong in an earlier draft of my own notes. The VPN provision was struck from the bill in February 2026 after sustained public pressure, and Governor Evers then vetoed the whole age verification bill on 3 April 2026, making him the first US governor to do so. That reads like a clean win for privacy.
It is not a clean win, and this is the single most important paragraph on this page.
In the same veto message, Evers objected that the bill made every user hand over identification while doing nothing to stop operators selling that data to brokers or the government — and he proposed device-based age verification as the better alternative. The governor who killed the ID-upload bill on privacy grounds endorsed the operating-system model. That is where mainstream privacy politics currently sits. If your argument against OS-level age gates assumes the people pushing them are acting in bad faith, that argument does not survive contact with the Evers veto. The people pushing this genuinely believe it is the privacy-protective option, and the strongest version of the counter-argument has to engage with that rather than around it.
And the practical point for anyone who reaches for a VPN by reflex: a VPN changes where your traffic appears to come from. It does not change what your device broadcasts about you. Against an OS-level age signal, it does nothing at all.
Federal
Nothing has passed. A great deal is moving.
| Bill | What it does | Status |
|---|---|---|
| S. 5090 Digital Age Assurance Act | Nationalises the California OS-level model. Four brackets, ZK proofs named in statute, data-broker ban, antitrust teeth against app store self-preferencing | Senate Commerce, no hearing scheduled |
| H.R. 8250 Parents Decide Act | Same architecture, blunter. DOB at OS setup, parent verification for under-18s | House Energy & Commerce |
| KOSA | Duty of care for platforms | Out of Senate Commerce by unanimous voice vote, 5 Aug 2026 |
| SCREEN Act (S. 737) | Federal AV mandate for explicit content | Voted 15–13 to advance on 5 Aug — failed for lack of quorum. Not dead, lost on attendance |
| KIDS Act (H.R. 7757) | Broad package including AV for explicit sites | Passed House 267–117, 29 Jun 2026. Awaiting Senate |
| GUARD Act (S. 3062) | AV for "AI companions" | Pending |
S. 5090 deserves credit where it is due. It is bipartisan — Kim and Schiff alongside Lummis and Barrasso — and it is the best-designed bill in this space: age brackets rather than birth dates, verifiable credentials and zero-knowledge proofs named in the statutory text, a ban on selling bracket data or feeding it to brokers, and per se Sherman Act treatment for platforms that impose stricter age requirements on third-party apps than their own.
And there is a gap between the press release and the statute that I think is worth naming. The release says the bill keeps government IDs and face scans "out of the equation." The statutory language says only that the Act shall not be interpreted as requiring those methods. It does not prohibit them. Registration is self-attested at setup, but a "clear and convincing information" trigger lets a developer override the signal and escalate to the OS provider for verification — and the bill does not specify how that verification happens. That undefined escalation path is the door through which ID checks walk back in.
There is also a horse-trade in the background worth watching: reporting indicates the White House and Senate negotiators have discussed bundling a federal age verification mandate with three-year preemption of state AI regulation. If that lands, the patchwork ends and a single national floor for identity-linked internet access replaces it — traded for something entirely unrelated to children.
What I am watching next
- 13 August — AB 1856 on suspense in Sacramento. This is the live one.
- 28 August — Missouri goes live.
- 3 September — Utah's VPN provisions become enforceable, or the standstill extends.
- Whether any state copies Colorado's exemption language. It exists, it is drafted, it has passed a legislature. That makes it handable to any other statehouse.
- Whether S. 5090 or H.R. 8250 gets a hearing before the calendar runs out.
What this page is not
It is not legal advice, and it is not complete. There are roughly forty overlapping statutes here plus an active litigation docket in at least eight circuits, and I am one person with a microphone. If you find something wrong — a date, a vote count, a bill number, a state I have miscoloured on the map — tell me and I will fix it and note the correction. I would rather be corrected in public than be confidently wrong in a place people are using as a reference.
The reason I keep this updated rather than writing one post and moving on is that the shape of the thing only becomes visible over time. Any single law looks like a narrow response to a real problem. All of them together look like an architecture. That architecture is being built right now, in public, with bipartisan support and near-unanimous votes, and the window to shape it is measured in months.
— Simon
Sources & further reading
Enacted state laws
- Illinois HB 5511 — bill status and history, Illinois General Assembly
- Illinois HB 5511 — full enrolled text
- Colorado SB26-051 — bill page, Colorado General Assembly
- Colorado SB26-051 — Final Act text (PDF)
- Iowa HF 864 — signed by Gov. Reynolds
- Missouri AG age-verification rule now in force
California, AB 1043 and AB 1856
- Senate Appropriations hearing results, 3 August 2026 (PDF)
- 2026 Senate legislative deadlines (PDF)
- California Steps Back From Dangerous Expansion of its Age-Gating Law — EFF
- One Step Forward, Two Steps Back: CA's AB 1856 Exempts Open Source But Expands Age-Gating — EFF
- California moves to exempt Linux from its upcoming age-verification law — Tom's Hardware
Open source
- Colorado Adds Open-Source Exemption to Age-Attestation Bill — Linuxiac
- "Open Source Exemption" to Colorado's Age Verification Law Would Not Include GPL — Lunduke
- California's Age Verification Law May End Up Exempting Most Linux Distributions — Phoronix
- GrapheneOS refuses to comply with new age verification laws — Tom's Hardware
- GrapheneOS Won't Implement Age Verification — Privacy Guides
Federal
- S. 5090 Digital Age Assurance Act of 2026 — Congress.gov
- The Senate Should Reject KOSA's Privacy Risks — EFF
- The SCREEN Act Threatens Privacy Far Beyond Adult Websites — EFF
- Senate Commerce approves KOSA and children's AI safety bills — IAPP
- White House negotiating federal preemption of state AI laws — The Hill
VPNs and Wisconsin
- Wisconsin Governor Vetoes Age Verification Bill, Citing Privacy Risks — ID Tech Wire
- EFF to Wisconsin Legislature: VPN Bans Are Still a Terrible Idea — EFF
- Aylo sues Utah over VPN age verification provisions — Deseret News
- VPNs Are Not a Solution to Age-Gating Mandates — EFF
Litigation