SocietyIssue #70 ·

How Child Safety Laws Are Building an Internet ID System

Child protection is real, but should the fix mean embedding everyone's identity into the operating system?

How Child Safety Laws Are Building an Internet ID System

Opening

Dear reader, there was a small commotion in the Linux community last week. A field called birthDate was added to systemd, the core system manager used by most Linux distributions — a field that stores a user’s date of birth at the operating system level.

Lennart Poettering, the creator of systemd, explained that “it’s just an optional field — not a policy engine, not an API for apps.” But if you trace why this small field was added, a much bigger picture emerges. It exists to respond to age verification laws1 passed in California, Colorado, Brazil, and elsewhere.

But look closely at these laws, and they’re not simply child protection policy. They’re laws that mandate infrastructure for the operating system to broadcast a user’s age to every app in real time. And behind them, there’s an unexpected beneficiary.

A World Where the OS Checks Your Age

In October 2025, California Governor Gavin Newsom signed AB-1043 (the Digital Age Assurance Act), which takes effect on January 1, 2027. Here’s the core of what the law does.

Every operating system provider must collect the user’s date of birth or age during account setup. Based on this information, when an app developer requests it, the provider must relay the user’s age bracket (under 13, 13-15, 16-17, or 18 and over) through a real-time API.

This is where the definition of “operating system provider” matters. According to the law’s text, it means “any person that develops, licenses, or controls operating system software for a computer, mobile device, or other general-purpose computing device.” This covers not just Windows, macOS, iOS, and Android, but also Linux distributions and Valve’s SteamOS.

This is a different order of magnitude from verifying age when accessing a specific adult site. From the moment you power on a device, your age information gets embedded in the operating system, becoming a permanent identity-verification infrastructure that every installed app can query.

This isn’t just a California story. Similar laws are already in effect in Utah (SB-142) and Louisiana (HB-570), and Colorado’s version (SB26-051) passed the Senate 28-7 and is now under House review. New York (S8102A) goes even further, banning self-reporting and requiring biometric or government ID verification. Similar bills are pending in Illinois, Ohio, Georgia, and South Carolina, and at the federal level, KOSA and ASAA are moving forward.

The common template behind these laws is the “Digital Age Assurance Act” drafted by ICMEC (the International Centre for Missing & Exploited Children). But there’s a striking pattern here: these laws impose obligations on app stores and operating systems, while imposing no new obligations on the social media platforms that actually expose children to content directly.