Last updated: 23 September 2026. This is a living page. I update it as laws pass, take effect, get enjoined, or die in committee. Every claim here is sourced to a bill page, an enacted statute, or a court docket — not to a summary of a summary. Where I could not verify something, I say so rather than quietly dropping it.
I started this tracker because I kept getting the same question in different forms: is the thing I read about real, and does it apply to me? The honest answer is that it depends on which of about forty overlapping laws you mean, and most coverage does not distinguish between a bill filed, a bill passed, a law in effect, and a law currently blocked by a federal judge. Those are four very different things and only one of them changes what happens when you pick up your phone.
So: the whole board, in one place.
What changed in this update (23 September): Both California bills are law. Governor Newsom signed AB 1856 (age verification signals, Chapter 184) and AB 1709 (addictive features for under-16s, Chapter 183) on 10 September, as part of a thirteen-bill child-safety package. Neither arrived by silence. That changes three things on this page:
- California now has an open-source exemption. AB 1856 excludes from "operating system provider" anyone who distributes an OS "under license terms that permit a recipient to copy, redistribute, and modify the software." Details and the comparison with Colorado's wording are in the open-source section below.
- AB 1709's age check runs through the AB 1043 OS signal, as this page has argued since August. It is now enacted text rather than a bill.
- The 30 September deadline no longer applies to either of them. It still applies to other bills on the Governor's desk, including AB 2561, which would stop an operating system or app from silently reverting your privacy settings after an update.
In Washington, nothing moved. I checked both bills against their official status records on 23 September. S. 5090 has had no action since it was referred to Senate Commerce on 22 July. KOSA still has no committee report filed, seven weeks after Commerce ordered it reported on 5 August. The Meta MDL case management conference set for 21 September is past, and I have not yet seen a reliable account of what happened at it, so the rows below mark it as pending rather than guessing.
Previous update (10 September): Both California bills are now on the Governor's desk. AB 1856 was enrolled on 1 September and presented on 4 September at 4 p.m.; AB 1709 was enrolled on 4 September and presented on 9 September at 1 p.m. The deadline is 30 September, it is a fixed constitutional date, and presentation timing does not move it. Silence enacts them.
Bigger, and much less visible: Utah quietly switched off the enforcement of its own app store law, and I had it wrong on this page. H.B. 498, signed 18 March 2026, struck the deceptive-trade-practice hook and deleted the Division of Consumer Protection from the enforcement section. The Act is operative and has no government enforcer at all — the only remedy is a private suit by a minor or their parent, and not until 6 May 2027. Both federal lawsuits challenging it were dismissed by stipulation in April, before any court ruled. I have corrected the Utah dates and the enforcement description below.
Also corrected: this page previously dated Utah's private right of action to 31 December 2026. The statute says 6 May 2027. And Meta's age-assurance deadline is now exact rather than approximate — 27 August 2027, derived from a defined Effective Date — along with false-positive rate caps I had not reported before.
The one thing to understand first
Age verification is not a website problem any more. It has been moving down the stack for five years, and each layer down is harder to route around than the one above it.
![]()
When the check lived on the website, you could choose not to visit the website. When it moved to the app store, you could sideload. Now it is moving into the operating system — and in Illinois, into any internet-enabled device including your laptop.
That last step is the one worth paying attention to, because an age attribute that lives in the OS and is queryable by any application is a new thing in the world. It is a persistent, always-on identity primitive that did not exist before. Once it exists, the question stops being "should we have this" and becomes "what else should it return."
Where the laws are
![]()
A note on the counts, because published figures disagree and I would rather explain the disagreement than pick a number and look authoritative. Sources put the harmful-content total anywhere from 25 to 27 depending on whether they count laws enacted or laws in force, and depending on whether they have caught up with the two 2026 additions. My count is 27 enacted, listed below with dates. If you see 25 somewhere, that source is probably counting states with laws already in force as of early 2026 and has not added West Virginia or Iowa.
Tier 1 — the operating system and device laws
Three states have enacted these. They are the reason this page exists.
| State | Law | Signed | Effective | Open source exempt? |
|---|---|---|---|---|
| California | AB 1043, Digital Age Assurance Act | 13 Oct 2025 | 1 Jan 2027 | Yes — added by AB 1856 (Ch. 184, signed 10 Sep 2026), see below |
| Illinois | HB 5511, P.A. 104-0664 | 31 Jul 2026 | 1 Jan 2028 | No |
| Colorado | SB26-051, Age Attestation on Computing Devices | 3 Jun 2026 | 1 Jul 2028 | Yes |
California AB 1043 requires operating system providers to present an interface at account or device setup collecting the user's birth date or age, then expose an age signal to apps and app stores through a real-time API. Every new phone and tablet sold in California will classify its user by age range at first boot. Penalties run up to $7,500 per affected child.
Colorado SB26-051 does the same thing, with a longer runway and a materially better exemptions section. Passed the Senate 28–7 and the House 40–23. Devices set up before 1 July 2028 need a retrofit interface before 1 January 2029.
Illinois P.A. 104-0664 is the newest, the broadest, and the one almost nobody covered properly — including me, until this week. It passed the Illinois Senate 57–0 and cleared House concurrence 113–0. Not one recorded no vote at the end.
Its scope is worth reading slowly. "Covered manufacturer" means a manufacturer of an internet-enabled device, an operating system provider, or an application store — three categories, not one. "Operating system provider" is defined as "a commercial or non-profit entity that controls the Internet-enabled device's operating system." The words non-profit are in the statute. And "internet-enabled device" is defined to include personal laptops and desktop computers, not just phones.
Read those three definitions together and the law reaches a non-profit foundation distributing a free operating system for a laptop. That is not a strained reading. That is the plain text.
To be fair to Illinois, parts of the drafting are genuinely more careful than Colorado's. The signal is shared only on separate prior user consent for a specific operator. Signals must be encrypted. An operator may request a signal no more than once a year. And "deemed actual knowledge" is scoped to the specific device rather than following you across every platform, which is how Colorado wrote it. Those are real privacy improvements and I will not pretend otherwise.
The problem is who it applies to, and what it does not exempt.
The open-source question
This is the part of the story that matters most if you run Linux, GrapheneOS, LineageOS, or anything else you compiled yourself.
![]()
Colorado wrote an exemption, and it is smarter than it has been reported. Section 6-30-105(3)(e) of the enacted act exempts:
an operating system provider or developer that distributes an operating system or application under license terms that permit a recipient to copy, redistribute, and modify the software without any platform-imposed technical or contractual restrictions imposed by the provider or developer on installing all modified versions.
Almost every write-up of this clause stops after "copy, redistribute, and modify" and calls it a Linux exemption. The rest of the sentence is the whole sentence. This is not a test of what licence you use — it is a test of whether the people shipping the software let you install your own modified build. It is an anti-lockdown provision. A signed, unlockable bootloader fails it regardless of how many GPL components are inside.
I have seen the claim circulating that this exemption covers BSD but excludes GPL code, on the theory that copyleft counts as a "restriction." Having read the enacted text, I do not think that holds — the restriction the statute cares about is one imposed on installing modified versions, which is precisely what GPLv3's anti-tivoization language exists to guarantee. That analysis was published in April and the language moved afterwards. I would not assert it either way on air without a court or an AG opinion, but I would not repeat the GPL claim as settled either.
Colorado also excludes free public code repositories from the definition of "covered application," and excludes code repository providers and containerised software distribution from "covered application store." GitHub, GitLab, Docker and Podman-style distribution stay out of scope.
Update, 23 September: AB 1856 is law. Signed 10 September 2026 as Chapter 184. The enacted definition reads: "'Operating system provider' does not mean a person or entity that distributes an operating system or application under license terms that permit a recipient to copy, redistribute, and modify the software." A second exclusion takes software components that are not "offered to consumers as a stand-alone executable application through a covered application store" out of the definition of an application. That covers libraries and packages pulled in by apt, dnf or pacman.
Put that wording next to Colorado's and the difference is plain. Colorado's test adds "without any platform-imposed technical or contractual restrictions … on installing all modified versions," which makes it an anti-lockdown test. California's stops at the licence. On a plain reading, California is asking what licence you ship under, and Colorado is asking whether users can actually run their modified build. Which projects fall on which side of each line, GrapheneOS included, has not been tested in court or addressed in any AG guidance I have found. I am treating it as an open question and I will not call it settled on air.
Two limits on the carve-out. It amends AB 1043 and does not replace it, so every commercial OS is still in scope from 1 January 2027. And it leaves the actual-knowledge clause described below untouched: a developer that receives the signal is deemed to know your age range, "even if the developer willfully disregards the signal."
Earlier update, 10 September: AB 1856 made it to the Governor's desk. AB 1856, authored by the same legislator who wrote AB 1043, would add the same style of carve-out. It came off the Senate Appropriations suspense file on 13 August with a 7-0 do-pass, and then on 21 August the Senate read it a third time, amended it on the floor, and ordered it back to second reading — a reset that cost days it did not have. It cleared anyway: the Senate passed it 26 August, 39-0, the Assembly concurred in the Senate amendments on 27 August, 69-0, it was enrolled on 1 September and presented to the Governor on 4 September at 4 p.m.
Two things I said here before are now out of date and I am correcting them rather than quietly deleting them. First, I wrote that the 21 August floor amendment text had not been published and that nobody outside the building knew what it said. It has since been published — leginfo now carries both the 21 August Senate amendment and the 1 September enrolled version. I have not yet read the amended text against the open-source carve-out question, so I am not going to characterise what changed until I have. That is the next thing I do on this bill. Second, the old framing here treated 31 August as the cliff. The cliff now is 30 September, the Governor's deadline.
The distinction that still matters, and that a lot of coverage still misses: AB 1043 is already law; AB 1856 only amends it. If AB 1856 had died, AB 1043 would still take effect on 1 January 2027 — with no open-source exemption at all.
A correction to what this page said about AB 1856 and the web. I previously wrote that the plan to extend age-gating to browsers and websites was dropped. That is half right, and the wrong half. The 1 July amendment did strike the browser as a transport — the definitions of "browser," "browser provider" and "internet website operator" are gone, and your browser will not be handing your age to every site you visit. But the same amendment rewrote the actual-knowledge clause so that a developer receiving an OS signal is deemed to know your age range "across all platforms of an application, including an internet website owned, maintained, or controlled by a developer" — and it holds "even if the developer willfully disregards the signal." The web did not leave the bill. It changed vehicles. Once an app on your phone has your age band, that knowledge follows you to that company's website, on your laptop, in a different session, with no prompt and no check. The EFF removed its opposition after the open-source exemption was added and the browser transport was dropped, while maintaining that AB 1043 itself is unconstitutional.
Illinois shipped with nothing. I read the enrolled text end to end. The only exemptions in the Act are for entities whose primary purpose is news media, and for broadband internet access providers. There is no licence-based carve-out, no repository carve-out, no container carve-out. Colorado has all three. Illinois has none, and its definitions explicitly reach non-profits and laptops.
Neither federal bill — S. 5090 nor H.R. 8250 — contains an open-source exemption in any published summary I have found. I have not been able to confirm that against the full bill text, so treat that as absence of evidence rather than confirmed absence.
The Linux plumbing, and where it actually stands. This comes up every time, so: the data layer shipped and the API layer did not. systemd merged a birthDate field into its JSON user records on 18 March 2026 — a full date, not a bracket, readable by any process that can query userdb and writable only by an administrator. The pull request explicitly cites AB 1043, Colorado SB26-051 and Brazil's Lei 15.211 as motivation. But the application-facing interface that would let an app actually ask has now been proposed twice and closed twice. Aaron Rainbolt's org.freedesktop.AgeVerification1 specification was closed after community pushback. David Edmundson's xdg-desktop-portal draft, PR #1922, was closed by a maintainer on 13 April 2026 without merging. No desktop environment has shipped a backend, and as of today there is no active proposal.
I am flagging this because the widely shared version of the story — "age verification is already in your Linux box" — is half right, and the wrong half matters. The storage is there. Nothing queries it. Correction worth making in public: my own working tracker carried PR #1922 as open and under review for two days, because I trusted a third-party compliance status page that still lists a pull request closed in April as active. Check the pull request, not the tracker. Including mine.
California AB 1709 — the bill everyone is describing wrong, including me
If you have read anything about AB 1709, you have read that California is about to ban under-16s from social media and make every adult in the state show government ID or submit to a face scan to use an algorithmic feed. I have seen that description from advocacy groups I respect, from think tanks, and from most of the press. I repeated a version of it myself.
I have now read the operative text — most recently amended in the Senate on 28 August 2026. It does not say that.
Update, 23 September. Signed 10 September 2026, Chapter 183. Everything below about how the bill works still stands. It is now describing a statute.
Update, 10 September. AB 1709 is no longer a pending bill and is no longer waiting in the wings either. On 31 August the Senate read it a third time and passed it 39-0, and the Assembly concurred in the Senate amendments the same day 78-0. It was enrolled on 4 September and presented to the Governor on 9 September at 1 p.m. He has until 30 September 2026 to sign or veto it. If he does nothing, it becomes law anyway — and that is the most likely way a bill of this kind arrives, without a signing statement or a press release.
Update, 2 September. I flagged that vote as single-sourced rather than tidy it away, and it has now resolved — so here is the answer. Leginfo's votes database caught up overnight and confirms the Senate tally at 39-0, with a named roster of thirty-nine and one senator not voting: Cabaldon. The Assembly concurrence, which had no tally at all when I wrote this, is 78-0. Both figures are now double-sourced and I am stating them flatly.
The sister-bill discrepancy resolved too, and it is worth a sentence because it went the other way. AB 1856's history prints 39; its votes page prints 40, with forty names. The two rosters differ by exactly one member — Cabaldon again, who voted aye on 1856 and did not vote on 1709. Forty is right and the history line is simply wrong. When a legislature's own records disagree, the roster is the document that can be counted.
It is not an account ban. Section 22683(a)(1) reads: "A covered platform shall not provide an addictive feature to a user who is under 16 years of age." And then (a)(2), immediately after: "This subdivision does not prohibit a covered platform from permitting a user who is under 16 years of age to create or maintain an account on the covered platform if that user is not provided with any addictive feature." A fifteen-year-old can have an Instagram account under this bill. They just cannot be given a personalised feed or autoplay.
It does not ask for your ID. Here is the entire verification mechanism, Section 22684(a)(1): "Before providing an addictive feature to a user, a covered platform shall verify the age of a user pursuant to the Digital Age Assurance Act." That is AB 1043 — the operating-system signal described at the top of this page. If that fails, subsection (a)(2) sends the platform to Health and Safety Code 27001(a)(1)(B), which is SB 976's "reasonably determined the user is not a minor... pursuant to regulations promulgated by the Attorney General."
That is the whole list. There is no third option. The words "government-issued identification" and "biometric" do not appear anywhere in the bill.
Why this is worse, not better
It would be comfortable to treat this as good news. It is not, and the reason is the whole thesis of this page.
A law that says "check ID at the door" is a law you can challenge. There is a specific burden, on a specific person, at a specific moment, and courts have been striking those down — that is what the injunction column further down this page is full of.
AB 1709 does not contain a mechanism to challenge. It imports one. It points at AB 1043, which is already law and takes effect on 1 January 2027, and at an Attorney General rulemaking that has not happened yet. The bill's authors did not have to defend an age check, because the bill does not create an age check. It creates demand for one that is being built somewhere else, by someone else, on a different timetable.
Watch what this means in practice. There is no prompt. There is no upload. There is no moment where you are asked for anything. Your operating system already knows your age band because you typed a birthday at device setup, and the platform simply asks it. The absence of friction is not the absence of surveillance. It is what surveillance looks like once it is finished being built.
The same pattern is on this page three times now: California relocating its website reach into a knowledge clause instead of a gate, Alliance Defending Freedom writing in its own committee filing that age estimation replaces age verification precisely because verification gets enjoined, and now AB 1709 declining to specify a mechanism at all. Three different drafting shops. No coordination. One conclusion: stop writing gates.
The other things in AB 1709
- Penalties are the largest of any bill on this page. Up to $50,000 per affected minor for a knowing violation and $25,000 for a negligent one, enforced by the Attorney General or a local prosecutor. No private right of action. For comparison, AB 1856 runs $2,500 and $7,500.
- "Addictive feature" got much narrower on 13 August. It is now a closed list: an addictive feed, autoplay, and anything the Attorney General later adds by regulation. The earlier draft covered notifications, endless scroll, "functional equivalents," and any feature that learns from your behaviour to prolong engagement. All of that was struck.
- The bill explicitly blesses consuming the OS signal. A feed does not become an "addictive feed" merely because it uses "device communications or signals concerning whether the user is a minor." AB 1709 and AB 1856 are designed to interlock.
- The oversight body was quietly defanged in the same amendment. The e-Safety Advisory Commission went from advising the Attorney General on "implementation and enforcement" to being "purely advisory" and "not binding upon, and shall not be imputed to, any agency or department of the state." Struck from its annual report: compliance rates among covered entities, and enforcement actions taken. And struck from its membership rules: a specific bar on commissioners having "a financial interest in an entity that is subject to regulation by the commission," replaced with generic Political Reform Act coverage. It gained a better-specified membership and a weaker mandate in the same pass. I have not seen this reported anywhere.
Status: ✅ Enacted. Passed the Senate 31 August, 39-0; Assembly concurred the same day, 78-0; enrolled 4 September; presented 9 September; signed by the Governor 10 September 2026 (Chapter 183).
Every deadline that matters
![]()
| Date | What happens |
|---|---|
| 13 Aug 2026 | California Senate Appropriations released AB 1856 from suspense, 7-0 do-pass. Read second time the same day |
| 21 Aug 2026 | AB 1856 read a third time, amended on the Senate floor, and ordered back to second reading. The amendment text has since been published, along with the 1 Sept enrolled version — I have not yet read it against the open-source carve-out question |
| 31 Aug 2026 | ✅ Happened. AB 1709 passed the Senate 39-0 and the Assembly concurred the same day, 78-0 — both tallies now confirmed against the roster. AB 1856 had already cleared on 26-27 Aug. The Legislature went into final recess on adjournment that night |
| 1 Sept 2026 | ✅ AB 1856 enrolled. Presented to the Governor on 4 Sept at 4 p.m. |
| 10 Sept 2026 | ✅ Happened. Governor Newsom signed AB 1856 (Ch. 184) and AB 1709 (Ch. 183), together with eleven other child-safety bills |
| 30 Sept 2026 | Governor's deadline for the bills still on his desk. AB 1709 and AB 1856 are no longer among them. Still pending: AB 2561 (no silent reverting of privacy settings by an OS or app) |
| 26 Aug 2026 | ✅ The Meta trial ended in a consent judgment, entered by Judge Gonzalez Rogers. See below |
| 14 Sept 2026 | Joint case management statement due in the Meta MDL. The conference itself was reset — see 21 Sept |
| 21 Sept 2026, 2 p.m. | Further case management conference in the Meta MDL, reset on 8 September from 14 Sept and moved to in person in Oakland, Courtroom 1, with audio-only Zoom retained. Update, 23 Sept: the date has passed, and I have not yet seen a reliable account of what happened. Pending until I can read the minute entry |
| 27 Aug 2027 | Meta's age-assurance framework deadline. Now exact, not approximate: the consent judgment defines the Effective Date as the first business day after entry, the judgment was entered 26 Aug 2026, so the Effective Date is 27 Aug 2026 and the framework is due one year later |
| ~27 Feb 2027 | Meta's "Compliance Date" under the consent judgment — six months after the Effective Date |
| 14 Aug 2026 | Last day for California fiscal committees to report bills |
| 28 Aug 2026 | Missouri harmful-content AV statute takes effect. Covers sites where more than a third of content is harmful to minors. $10,000/day, up to $250,000 if a minor gets through. The AG rule has been live since Dec 2025 — see Tier 3 |
| 31 Aug 2026 | Last day for either California house to pass bills |
| Pending, no date | Utah SB 73 VPN provisions. Correction, now settled. I previously gave 3 Sep 2026. That date is dead: on 27 Aug 2026 the parties jointly stipulated to extend the non-enforcement period, and on 28 Aug Judge Barlow entered a docket text order acknowledging their agreement "to extend and continue the period of forbearance" (ECF 65, 66). No replacement date is public — the stipulation is not in the docket. The real trigger is Judge Barlow's ruling on the preliminary injunction, argued 30 Jul 2026, still outstanding. Update, 10 Sept: the old forbearance lapsed on 3 September with no public replacement date; the court's docket mirror has not refreshed in six days; and Utah's consumer protection division has described the arrangement as running until its rule takes effect or the judge rules, whichever comes first — which may mean there is no date to find |
| 1 Sept 2026 | Fifth Circuit hears NetChoice v. Murrill (26-30016), En Banc Courtroom, New Orleans — Louisiana's appeal of the permanent injunction against its social-media minor-consent law |
| 10 Sept 2026 | ✅ Happened. Georgia's blue-ribbon study committee met in Augusta, 10:00 a.m. – 2:30 p.m. The agenda was never published — the notice was generated on 12 August and said "To be announced" for twenty-nine days, right through the morning of the meeting |
| 6 Oct 2026 | Georgia's study committee meets again, in Savannah. No venue and no time published yet |
| 29 Sept 2026, 2 p.m. | Meta MDL motion-to-strike hearing |
| 28 Oct 2026, 2pm | Fourth Circuit hears NetChoice v. Jones (26-1252) — Virginia. The court has now denied a stay pending appeal twice |
| Ongoing | The 29-state Meta trial ended on 26 Aug in the consent judgment above, so there is no verdict coming. What is still live in the MDL: the joint case management statement (14 Sept), the conference (21 Sept) and the motion-to-strike hearing (29 Sept) |
| 1 Jan 2027 | California AB 1043 (OS age signals); California SB 976; Alabama app store law; South Carolina HB 4591; New Hampshire HB 1460 |
| 6 May 2027 | 🔴 Corrected. Utah App Store Accountability Act — the private right of action begins. This page previously gave 31 December 2026, which was wrong. § 13-76-401 reads: "Beginning May 6, 2027, only a minor, or the parent of that minor, who has been harmed by a violation … may bring a civil action." Remedy is the greater of actual damages or $1,000 per violation, plus reasonable attorney fees and litigation costs. There is no Attorney General enforcement and no other enforcer |
| 6 May 2027 | Utah app store law — full compliance deadline |
| 1 Jul 2027 | Minnesota HF 4138; California AB 1043 transition period ends |
| 1 Jan 2028 | Illinois P.A. 104-0664 — manufacturer interface deadline |
| 1 Jul 2028 | Colorado SB26-051 takes effect; Illinois operator signal requests begin; Illinois retrofit deadline |
| 1 Jan 2029 | Colorado retrofit deadline for devices set up before July 2028 |
Tier 2 — app store laws
Four states, and they are all technically live — but read the Utah note below before you treat that as four working laws. The detail most coverage misses: they apply to all apps available to residents of the state, not just apps aimed at children. A flashlight app has compliance obligations.
| State | Law | Effective |
|---|---|---|
| Texas | SB 2420 | 1 Jan 2026 — enforceable now |
| Utah* | App Store Accountability Act | Provider duties live; no enforcer until 6 May 2027 — see below |
| Louisiana | App Store Accountability Act | 1 Jul 2026 |
| Alabama | HB 161 | 1 Jan 2027 |
*Utah is the asterisk, and it is the most interesting thing on this page. In March, Utah amended its own app store law with H.B. 498 and, in the process, disarmed it. The enforcement section, § 13-76-401, previously made a violation a deceptive trade practice under Utah's consumer protection act — the hook that let the state act. H.B. 498 struck that cross-reference, and struck the definition of "Division" (the Division of Consumer Protection) with it. The phrase "Attorney General" does not appear anywhere in the enrolled bill. Section 13-76-301, the Division's rulemaking authority, was repealed outright. The bill took effect on 18 March 2026, on the Governor's signature, because it cleared both chambers by more than two thirds.
What is left is a private action and nothing else, and it does not start yet:
Beginning May 6, 2027, only a minor, or the parent of that minor, who has been harmed by a violation of Subsection 13-76-201(2) may bring a civil action against an app store provider.
Damages are the greater of actual damages or $1,000 per violation, plus reasonable attorney fees and litigation costs.
Then the litigation evaporated. CCIA v. Brown and M.M. v. Brown, the two federal challenges in the District of Utah, were both terminated on 21 April 2026 by stipulation under Rule 41(a)(1)(A)(ii). No court ever ruled on a preliminary injunction. I have now read both stipulations — four pages and two pages — and they give the same reason in identical words:
The parties stipulate and agree that the App Store Accountability Act, as recently amended by H.B. 498 (2026) (the "Act") does not authorize government enforcement of any of its provisions; rather, it creates only a private cause of action. Accordingly, Defendants do not have the authority, and will not seek, to enforce the Act directly or as an asserted basis for liability under any other statute or authority, including the common law.
That last clause is worth pausing on. Utah's officials did not merely decline to enforce the Act — they disclaimed the authority to use it as a basis for liability under any other statute, or at common law. The plaintiffs did not win. They went home because there was no longer anyone to sue.
So Utah has an app store age verification law that is on the books, unchallenged, and — until May 2027 — enforceable by nobody. I want to flag how nearly I missed it. Nothing in the normal vocabulary of this beat looks for an enforcement mechanism being deleted. Laws get passed, enjoined, or struck down; those are the three things a tracker watches for. A legislature quietly removing its own hook looks, from the outside, exactly like nothing happening at all.
Apple and Google have both built for this. Apple's Declared Age Range API returns an age category — under 13, 13–16, 16–18, 18+ — along with signals about how that age was assured, without exposing a birth date. Google Play's Age Signals API is in beta doing the same job.
I want to be straight about this: the Declared Age Range design is the least-bad engineering in this entire space. Bands instead of birth dates, with assurance metadata. If you have to build the thing, that is roughly how you would build it. The problem is not the current field list. The problem is that once the OS knows your age band and every app can query it, nothing about the architecture stops a future statute from widening what the API returns. Good version-one design does not constrain version three.
Tier 3 — harmful-content laws, 27 states
These are the "upload your ID to visit an adult site" laws, generally scoped to sites where a third or more of the content is sexual material harmful to minors. The Supreme Court upheld the Texas version in Free Speech Coalition v. Paxton in June 2025 under intermediate scrutiny, which is why the count has climbed so fast since.
Enacted 2023: Arkansas, Louisiana, Mississippi, Montana, North Carolina, Texas, Utah, Virginia
Enacted 2024: Alabama, Idaho, Indiana, Kansas, Kentucky, Nebraska, Oklahoma
Enacted 2025: Arizona, Florida, Georgia, Missouri, North Dakota, Ohio, South Carolina, South Dakota, Tennessee, Wyoming
Enacted 2026: West Virginia (HB 4412, effective 12 June), Iowa (HF 864, signed 4 June, effective 1 July), Missouri (expanded, effective 28 August)
One clarification on Missouri, because it trips people up. The statute above takes effect on 28 August, but Missouri has been gated since 1 December 2025 under a separate rule promulgated by the Attorney General under the Merchandising Practices Act — Pornhub shut off access to the state within hours of that rule taking effect. If you read that Missouri "gets age verification this month," that is the second instrument, not the first.
Eight more states have pending bills, including Ohio HB 84, Michigan SB 191 and Pennsylvania SB 603.
The courts stopped being a brake
For three years the pattern was predictable: a legislature passes an age-verification law, NetChoice or the CCIA sues, a district judge enjoins it, and the thing sits in appellate limbo. That pattern broke twice this month, in opposite directions, and neither break has much to do with the First Amendment.
A New Mexico court ordered age verification with no age-verification statute behind it. On 6 August, Judge Bryan Biedscheid of the First Judicial District entered final judgment against Meta in State of New Mexico v. Meta Platforms. A March jury had already found 75,000 violations of the state's Unfair Practices Act and imposed the maximum penalty, $375 million. The bench phase added $567 million, held that Meta's platforms constitute a public nuisance, and rejected the Section 230 defence as to products Meta knowingly designed. Total: $942 million, plus five years of court-supervised reforms that include "more rigorous age verification for New Mexico users" and semiannual compliance reports filed with the court.
The same ruling shows where the judicial ceiling sits, and this part did not make the headlines. The court expressly declined to order hard age verification. Its stated reason was the vintage of the enabling statute — New Mexico's Child's Online Privacy Act dates to 1998 — and the conclusion that it cannot order Meta to make children submit personal data or be passively tracked, even for age-verification purposes. Judge Biedscheid called age assurance tools "unproven technology." The judge who fined Meta $942 million is also the judge who refused to make Meta scan children's IDs. Attorney General Raúl Torrez has said he will take the gap to the legislature next session.
Sourcing note added 1 September 2026. I want to be straight about how solid the numbers above are, because I have since tried to verify them against the record and could not. What is independently corroborated is the case itself — State of New Mexico v. Meta Platforms, D-101-CV-2023-02838, Judge Bryan Biedscheid — and a jury verdict dated 24 March 2026, cited by the D.C. Court of Appeals in In re Meta Platforms (No. 26-OA-0001, 16 July 2026). But that citation describes it specifically as a "jury verdict on liability" and says nothing about money.
The 75,000 violations, the $375M, the $567M, the $942M total and the five-year reform list all trace to a briefing deck the New Mexico Department of Justice handed legislators on 25 August, not to a court record I can reach. Searching the available federal corpus for that judgment returns nothing. New Mexico's own state-court lookup is behind a CAPTCHA, so I cannot close the loop either way — this is unverified, not disproven.
One more thing, and it cuts against the section above: the line about the court declining to order hard age verification comes from a footnote on that same DOJ slide, which reads "The Court stopped short of mandating hard age-verification, citing judicial restraint." That is a litigant characterising a judge's reasoning, on a slide whose main body lists rigorous age verification as an ordered reform. The slide contradicts itself. Until I can read the judgment, treat this whole passage as New Mexico DOJ's account of its own win.
The Ninth Circuit then removed the shield that made all of this survivable. On 10 August a panel dismissed Meta's and TikTok's appeals as premature in the consolidated social media addiction litigation. In a 24-page opinion, Judge Jacqueline Nguyen held that Section 230 provides a defence against liability, not blanket immunity from being sued. That distinction is why more than 3,000 federal cases are still alive.
And on 12 August, 29 states put it to trial. On 26 August it ended — not in a verdict, but in a consent judgment.
Jury selection began in Oakland before Judge Yvonne Gonzalez Rogers, with Colorado, Kentucky, California and New Jersey leading on the design and consumer-protection claims. I wrote here that her decision was expected in October. It did not take that long. The docket records the jury trial as completed on 26 August 2026, with a total time in court that day of forty-nine minutes, and on the same day Judge Gonzalez Rogers entered a consent judgment between Meta and the state attorneys general.
The settlement covers 51 jurisdictions — 47 states plus the District of Columbia, Puerto Rico, American Samoa and the Northern Mariana Islands. Florida, New Mexico and Texas are not in it. The money is roughly $12.2 billion guaranteed and up to about $17.1 billion. I am rounding deliberately: the guaranteed schedule is itemised in the agreement, but the ceiling is arithmetic derived from it rather than a figure the document states, and I would rather round than quote a precise number the record does not contain.
The part that belongs on this page is not the money. It is section II.A.1: "Within one (1) year of the Effective Date, Meta will adopt an age assurance framework." I have now read the settlement agreement itself rather than the reporting, and the date is exact rather than approximate. "Effective Date" is defined at section Y as "the first business day after which the Court in the MDL Action has entered the Consent Judgment." The judgment was entered on Wednesday 26 August 2026, so the Effective Date is Thursday 27 August 2026 and the framework is due 27 August 2027.
There is also a "Compliance Date" six months after the Effective Date, around 27 February 2027. The agreement runs ten years and names ISO 27566, the international age-assurance standard, as its reference point.
And then there are the caps, which are the most interesting regulatory instrument on this entire page — and which I have seen described incorrectly, including in my own notes before I opened the document.
The agreement defines a "U18 False Positive Rate" as "the percentage of actual users with an age from 13 through 17 years old, who are incorrectly identified or predicted by Meta to be 18 years or older." Read that carefully. It is not a measure of adults being wrongly caught by the filter. It is the opposite: it measures teenagers getting through as adults. It is a leak rate.
Meta has agreed to ceilings on that leak rate, and — this is the part that matters — there are two different standards depending on whose technology is used.
For third-party age assurance tools that Meta licenses in, within one year of the Effective Date: 10% for 16-17 year olds and 3% for 13-15 year olds.
For Meta's own proprietary methods, the standard is looser and phased:
(A) Year 1: Within one year of the Effective Date: 14% for minors aged 16-17 and 7% for minors aged 13-15.
(B) Year 2: Within two years of the Effective Date, 10% for minors aged 16-17 and 5% for minors aged 13-15.
So Meta's in-house technology is permitted to be worse than bought-in technology, and is given two years to reach the standard third-party tools have to meet in one. For thirteen-to-fifteen year olds the gap is more than double.
Now hold that against every law on this page. They all mandate that a check happen. Not one of them says a word about whether the check works. A statute requiring "commercially reasonable" verification is indifferent between a system that is right 99% of the time and one that leaks one teenager in seven. This settlement is the only instrument in American age assurance that puts a number on the error rate and makes somebody accountable to it — and it was written by lawyers settling a damages case, not by a legislature.
It is also, quietly, an admission. A 14% leak rate for sixteen and seventeen year olds is the negotiated starting position, from the company with more identity signal than almost anyone on earth. That is what the state of the art looks like when someone is finally obliged to measure it.
Read that against everything above. Every tier on this page is a legislature telling a company to check ages, and every one of them can be challenged — Louisiana's was enjoined as to ten named platforms, Arkansas and Ohio have been through the courts, NetChoice has a case in nearly every circuit. This one cannot be. There is no statute here to strike down. Meta agreed to it. The United States is getting age assurance on its largest social platform through a document that no First Amendment challenge can reach, because there is no defendant who wants to challenge it.
And it does not stop at Meta. The agreement names Snap, TikTok and YouTube as Core Industry Members and ties a second phase to industry-wide adoption. It also distinguishes commercially available age-assurance methods, which get a presumption of compliance, from proprietary ones, which do not — a quiet but consequential nudge toward third-party age checking as the default. None of the three has announced anything yet. I am watching all of them.
The layer below all of it — a Texas court switched off a domain
Every tier above is a rule about what a company has to do. This one is different. It is a rule about whether a name resolves at all.
On 4 June 2026, Judge Maya Guerra Gamble of Travis County signed a writ of attachment in State of Texas v. Kick Online Entertainment, filed four days later. It directs Verisign — the American company that operates the .com registry — to place motherless.com on "a registry lock, hold, or similar status until replevied by Defendant." Fourteen days after signing, the domain dropped out of the .com zone file. Not blocked in Texas. Gone, for everyone on earth.
The chain that got there is mundane, which is the point. Texas sued Kick Online Entertainment, a Luxembourg company, in April 2024 under HB 1181. Kick never appeared. Civil penalties were entered by default on 30 September 2024, followed by a permanent injunction requiring age verification. Kick ignored that too. Unable to reach the company, Texas reached its property instead — through the one custodian in the chain that is unambiguously American.
What Verisign applied was serverHold, plus server-level prohibitions on deleting, transferring or updating the name. A registrar lock can be lifted by the registrar. A registry lock can only be lifted by Verisign. Without an entry in the zone file, a domain does not resolve for anybody, anywhere.
Three things in the order deserve to be read slowly.
One — foreignness became the justification rather than the obstacle. Among the court's stated grounds that the writ is "appropriate and justified" is the finding that "Defendant is not a resident of this state and is a foreign corporation." The state's inability to reach a company became the reason to take its property.
Two — the bond runs one way. Kick can recover the domain by posting $9,140,000, conditioned on implementing age verification that conforms with Texas Civil Practice and Remedies Code chapter 129B and affirming that it will satisfy the 2024 penalties. Texas posted nothing: the order provides that "the State of Texas is not required to post a bond prior to the issuance of the Writ of Attachment."
Three — it pre-authorises itself. The order closes with the line that "as many writs as the State deems necessary shall issue." The number of future seizures is set by the attorney general, not by a judge weighing each one. Nothing in the order confines the tool to pornography, or even to age verification.
I want to be precise about sourcing, because this is the most consequential item on this page and the order is a scanned PDF with no text layer. The language quoted above is as published by Reclaim the Net, which obtained and posted a copy of the order, and it matches Tech Times' independent reading of the same document. I have not been able to machine-read the scan myself. Treat the quotes as reliable but second-hand until someone has read it line by line.
Two caveats that cut against the alarm, and they belong right here. This is a trial court order and it binds nobody outside this case. And no court has heard the other side, because Kick never showed up — the whole framework rests on an uncontested default.
Here is why this sits on a privacy page and not a domain-industry one. Every other tier on this list is defeated, degraded, or at least complicated by the tools I usually recommend. A VPN changes where you appear to be. It cannot conjure a zone-file entry that no longer exists. This is the first rung of the age-verification stack that personal tooling does not reach at all, and the honest response to it is not a better VPN. It is an argument about who gets to hold that switch, and that argument happens at ICANN and in appellate courts rather than in your settings menu.
The VPN front
This one goes directly at the toolkit, so I want to be precise about it.
Utah SB 73 is the only enacted US law targeting VPN use around age gates. It does not ban using a VPN. What it does is make you a Utah user for liability purposes even when you connect through one, and it prohibits covered platforms from providing instructions, assistance, or encouragement about using a VPN to bypass verification. That second part is a speech restriction on privacy education wearing a child-safety hat.
The VPN provisions are not yet enforced, and as of 1 September the date I and everyone else were quoting is dead. Utah's Department of Commerce and Aylo agreed on 27 April to hold off until 3 September 2026 — but on 27 August the parties filed a joint stipulation to extend that, and on 28 August Judge David Barlow entered a docket text order acknowledging "the parties' agreement to extend and continue the period of forbearance." (ECF 65 and 66.)
There is no new date. The stipulation itself is not in the public docket, and the words September, expire and expiration appear nowhere in the docket text — against 42 occurrences of preliminary injunction in the same corpus, so that is a real absence rather than a search that missed. The honest position is that the freeze continues indefinitely until Judge Barlow rules. He heard argument on the preliminary injunction on 30 July 2026 and has not ruled.
Worth noticing what the extension implies: the stipulation is bilateral. Aylo agreed not to change its Utah geofencing either. Neither side wanted the cliff. Anyone telling you Utah is currently enforcing a VPN ban is wrong, and anyone telling you enforcement starts on 3 September is now also wrong. Aylo's argument is worth understanding: if Utah residents can reach a site through a VPN from anywhere, then verifying "Utah users" means verifying everyone on earth. A state law becomes a global standard by accident.
The strangest development of the month: the pornography industry is now lobbying for OS-level age verification. Aylo, which owns Pornhub, sent an open letter to more than 300 lawmakers, governors and attorneys general calling site-level age verification laws "performative, ineffective, and unenforceable" — and then asking those same lawmakers to "mandate operating system providers like Apple, Microsoft and Google" to render every phone, tablet and computer child-safe by default. It points to its UK arrangement as the model, and it advertises, as a selling point, that under that scheme "VPNs do not work to circumvent these blocks."
Sit with that for a second. A pornography company is marketing VPN-proof blocking as a feature.
The rebuttal came from the age-verification vendors, which tells you how scrambled these coalitions have become. The Age Verification Providers Association called device-only checks "a false choice," argued for a layered model on a proximity principle — you check at the door of the casino, not at the entrance to the shopping centre — and warned that routing everything through three operating system vendors "creates a single point of failure, concentrated market power and, some may also fear, even more data harvesting opportunities, while excusing adult platforms completely from their duty of care."
The map most people carry into this fight — privacy advocates on one side, the state on the other — does not describe what is happening. On the specific question of OS-level mandates, Aylo is aligned with a bipartisan Senate quartet, and the people making the market-concentration argument are the ID-checking vendors whose business model depends on the answer.
Michigan has a filed bill that goes further — it would reach the promotion or sale of circumvention tools — but it has no hearing scheduled.
Wisconsin is the interesting one, and I had it wrong in an earlier draft of my own notes. The VPN provision was struck from the bill in February 2026 after sustained public pressure, and Governor Evers then vetoed the whole age verification bill on 3 April 2026, making him the first US governor to do so. That reads like a clean win for privacy.
It is not a clean win, and this is the single most important paragraph on this page.
In the same veto message, Evers objected that the bill made every user hand over identification while doing nothing to stop operators selling that data to brokers or the government — and he proposed device-based age verification as the better alternative. The governor who killed the ID-upload bill on privacy grounds endorsed the operating-system model. That is where mainstream privacy politics currently sits. If your argument against OS-level age gates assumes the people pushing them are acting in bad faith, that argument does not survive contact with the Evers veto. The people pushing this genuinely believe it is the privacy-protective option, and the strongest version of the counter-argument has to engage with that rather than around it.
And the practical point for anyone who reaches for a VPN by reflex: a VPN changes where your traffic appears to come from. It does not change what your device broadcasts about you. Against an OS-level age signal, it does nothing at all.
Federal
Nothing has passed. A great deal is moving.
| Bill | What it does | Status |
|---|---|---|
| S. 5090 Digital Age Assurance Act | Nationalises the California OS-level model. Four brackets, ZK proofs named in statute, data-broker ban, antitrust teeth against app store self-preferencing. Its official title also reaches browser providers and covered websites, which California dropped from AB 1856 | Referred to Senate Commerce 22 Jul 2026. No action since (checked 23 Sept) |
| H.R. 8250 Parents Decide Act | Same architecture, blunter. DOB at OS setup, parent verification for under-18s | House Energy & Commerce |
| KOSA (S. 1748) | Duty of care for platforms | Ordered reported by Senate Commerce by voice vote, 5 Aug 2026. Still no committee report filed as of 23 Sept, and no floor time scheduled |
| SCREEN Act (S. 737) | Federal AV mandate for explicit content | Voted 15–13 to advance on 5 Aug — failed for lack of quorum. Not dead, lost on attendance |
| KIDS Act (H.R. 7757) | Broad package including AV for explicit sites | Passed House 267–117, 29 Jun 2026. Awaiting Senate |
| GUARD Act (S. 3062) | AV for "AI companions" | Pending |
S. 5090 deserves credit where it is due. It is bipartisan — Kim and Schiff alongside Lummis and Barrasso — and it is the best-designed bill in this space: age brackets rather than birth dates, verifiable credentials and zero-knowledge proofs named in the statutory text, a ban on selling bracket data or feeding it to brokers, and per se Sherman Act treatment for platforms that impose stricter age requirements on third-party apps than their own.
And there is a gap between the press release and the statute that I think is worth naming. The release says the bill keeps government IDs and face scans "out of the equation." The statutory language says only that the Act shall not be interpreted as requiring those methods. It does not prohibit them. Registration is self-attested at setup, but a "clear and convincing information" trigger lets a developer override the signal and escalate to the OS provider for verification — and the bill does not specify how that verification happens. That undefined escalation path is the door through which ID checks walk back in.
There is also a horse-trade in the background worth watching: reporting indicates the White House and Senate negotiators have discussed bundling a federal age verification mandate with three-year preemption of state AI regulation. If that lands, the patchwork ends and a single national floor for identity-linked internet access replaces it — traded for something entirely unrelated to children.
What I am watching next
- Settled on 10 September: AB 1856 and AB 1709 were both signed. What I am watching now is implementation. The Attorney General rulemaking AB 1709 points to has not started. AB 1043's signal obligations begin 1 January 2027. And the first real test of California's open-source carve-out will be the first time someone argues about whether a particular project qualifies.
- The rest of the Governor's desk, to 30 September. In particular AB 2561, which would bar an operating system or app from silently undoing your privacy settings after an update.
- Whether the Sixth Circuit's mandate issues in NetChoice v. Yost. Ohio won at the panel, but the mandate was stayed on 17 August and has not issued, so the win is frozen. A correction to my own arithmetic: I had been working to a cert deadline of roughly 16 September, counting ninety days from the June opinion. That was wrong — NetChoice petitioned for rehearing en banc on 16 July and was denied on 5 August, and the clock runs from the denial. The real date is later, in the autumn. I am not going to publish a specific one until I have worked it properly.
- Two things I could not stand up this week, listed so you know they are open rather than settled. First, Virginia's HB 757 and SB 237 — the App Store Accountability bills carried over to 2027. I thought I had the bill text and I did not; the records I pulled turned out to be joint resolutions from 1996 and 2002, so everything I might have said about Virginia's enforcement design is withdrawn until I read the actual bills. Second, the new forbearance date in Aylo v. Utah. The old one lapsed on 3 September, the docket order acknowledging the extension states no date, the two dates circulating publicly contradict each other, and the court's mirror has not refreshed in six days. Utah's consumer protection division has described the arrangement as running until its rule takes effect or the judge rules, whichever comes first — which may mean there is no date to find.
- Judge Barlow's ruling in Aylo v. Utah, undated. The most consequential pending decision on this page for anyone using a VPN.
- October — Judge Gonzalez Rogers rules. If she orders age restrictions nationwide, every tier on this page is suddenly downstream of one courtroom.
- Whether Texas files a second domain writ. The order authorises as many as the attorney general wants. The second one is what tells you this is a programme rather than a one-off.
- Whether any state copies Colorado's exemption language. It exists, it is drafted, it has passed a legislature. That makes it handable to any other statehouse.
- Whether S. 5090 or H.R. 8250 gets a hearing before the calendar runs out.
What this page is not
It is not legal advice, and it is not complete. There are roughly forty overlapping statutes here plus an active litigation docket in at least eight circuits, and I am one person with a microphone. If you find something wrong — a date, a vote count, a bill number, a state I have miscoloured on the map — tell me and I will fix it and note the correction. I would rather be corrected in public than be confidently wrong in a place people are using as a reference.
The reason I keep this updated rather than writing one post and moving on is that the shape of the thing only becomes visible over time. Any single law looks like a narrow response to a real problem. All of them together look like an architecture. That architecture is being built right now, in public, with bipartisan support and near-unanimous votes, and the window to shape it is measured in months.
— Simon
Sources & further reading
Enacted state laws
- Illinois HB 5511 — bill status and history, Illinois General Assembly
- Illinois HB 5511 — full enrolled text
- Colorado SB26-051 — bill page, Colorado General Assembly
- Colorado SB26-051 — Final Act text (PDF)
- Iowa HF 864 — signed by Gov. Reynolds
- Missouri AG age-verification rule now in force — note the date, 1 December 2025
- New Mexico DOJ — court orders Meta to pay $942 million and overhaul protections for children
- New Mexico courts — final findings of fact, conclusions of law and judgment (PDF)
The registry writ
- Texas Attorney General — court order locking motherless.com
- The order itself, as published by Reclaim the Net (scanned PDF)
- Reclaim the Net — Texas locked a foreign company's domain over missing digital ID checks
- Tech Times — Texas civil court compelled Verisign to lock a .com domain
- Texas HB 1181, Civil Practice and Remedies Code chapter 129B (PDF)
The Oakland trial and the Ninth Circuit
- Reuters — Meta and 29 states head to court
- Axios — Meta and others lose appeal to drop thousands of addiction lawsuits
- Ninth Circuit docket, In re Social Media Adolescent Addiction
The Linux stack
- systemd PR #40954 — birthDate in user records (merged 18 March 2026)
- xdg-desktop-portal PR #1922 — closed 13 April 2026 without merging
California, AB 1043 and AB 1856
- Governor Newsom signs child safety chatbot and social media laws, 10 September 2026 — Office of the Governor
- California's 2026 legislative session wraps — Kelley Drye (includes the enacted AB 1856 summary and the bills still pending)
- California lawmakers unanimously pass Linux exemption — Tom's Hardware
- Senate Appropriations hearing results, 3 August 2026 (PDF)
- 2026 Senate legislative deadlines (PDF)
- California Steps Back From Dangerous Expansion of its Age-Gating Law — EFF
- One Step Forward, Two Steps Back: CA's AB 1856 Exempts Open Source But Expands Age-Gating — EFF
- California moves to exempt Linux from its upcoming age-verification law — Tom's Hardware
Open source
- Colorado Adds Open-Source Exemption to Age-Attestation Bill — Linuxiac
- "Open Source Exemption" to Colorado's Age Verification Law Would Not Include GPL — Lunduke
- California's Age Verification Law May End Up Exempting Most Linux Distributions — Phoronix
- GrapheneOS refuses to comply with new age verification laws — Tom's Hardware
- GrapheneOS Won't Implement Age Verification — Privacy Guides
Federal
- S. 5090 Digital Age Assurance Act of 2026 — Congress.gov
- S. 5090 — official bill status record (govinfo), checked 23 Sept 2026
- S. 1748 KOSA — official bill status record (govinfo), checked 23 Sept 2026
- The Senate Should Reject KOSA's Privacy Risks — EFF
- The SCREEN Act Threatens Privacy Far Beyond Adult Websites — EFF
- Senate Commerce approves KOSA and children's AI safety bills — IAPP
- White House negotiating federal preemption of state AI laws — The Hill
VPNs and Wisconsin
- Wisconsin Governor Vetoes Age Verification Bill, Citing Privacy Risks — ID Tech Wire
- EFF to Wisconsin Legislature: VPN Bans Are Still a Terrible Idea — EFF
- Aylo sues Utah over VPN age verification provisions — Deseret News
- VPNs Are Not a Solution to Age-Gating Mandates — EFF
Litigation