
bill analysis
AB 1856 has passed the California Legislature and is headed to Governor Gavin Newsom’s desk for signature.
Supporters are framing the bill as a narrow “clarification” to California’s Digital Age Assurance Act (DAAA). But once you read the text, it becomes clear that AB 1856 is not a cleanup bill. It is a structural expansion of California’s age‑assurance architecture; one that hardens OS‑level age signaling, expands cross‑platform enforcement, and entrenches a persistent identity layer for minors across apps, websites, and devices.
Under the PKO Digital Safety & Identity Architecture Framework, AB 1856 is an automatic OPPOSE because it builds and strengthens the very infrastructure that will later be used to justify more intrusive age verification, digital identity binding, and cross‑platform surveillance.
With the bill now awaiting Governor Newsom’s signature, parents, advocates, and lawmakers need to understand exactly what AB 1856 does and why it fails every major PKO safeguard.
PKO has four red lines; any one is enough to oppose a bill. AB 1856 triggers all four.
AB 1856 requires OS providers to collect and maintain a persistent age attribute tied to the “primary user of a device.”
You cannot build this without identity binding, even if the bill claims “minimum necessary information.”
This is identity infrastructure.
The bill requires:
OS → App Store → Developer age‑signal transmission
Developer → App Store → OS requests
“Actual knowledge” that applies across all platforms, including websites
Cross‑platform enforcement is identity propagation. It requires shared identifiers, shared permissions, and shared enforcement logic.
To enforce age‑based obligations, the system must classify the user as a minor and treat that classification as authoritative.
Device and app behavior changes based on identity classification.
That is identity‑conditioned access.
AB 1856 forces:
OS providers
App stores
Developers
Websites
Cross‑platform access points
…to participate in a shared age‑signal ecosystem.
This is not a “simple clarification.” It is a multi‑vendor identity system.
Even without the auto‑oppose triggers, AB 1856 fails the PKO framework.
Here’s the breakdown.
Identity verification for minors? YES — OS‑level age collection is required.
Identity verification for parents? Not directly — but OS‑level account setup implies adult identity binding.
Persistent identity tokens for minors? YES — the age attribute is persistent and device‑bound.
Identity bound to device use? YES — enforcement depends on the OS‑level age classification.
Permissions propagated across devices/platforms? YES — “actual knowledge” applies across all platforms.
Category 1 score: 5 out of 5 (all negative for PKO)
New data flows between devices/vendors? YES — OS → App Store → Developer → Website.
New data retention obligations? YES — persistent age attribute at OS level.
New data aggregation points? YES — OS and app stores become centralized chokepoints.
Surveillance creep risk? YES — architecture can be repurposed beyond “age assurance.”
Third‑party vendor involvement? YES — Apple, Google, Microsoft, app stores, developers.
Category 2 score: 5 out of 5
Device‑level enforcement required? YES — OS must collect and transmit age signals.
Cross‑device enforcement required? YES — signals apply across apps, websites, and platforms.
Interoperability between manufacturers/platforms? YES — mandated OS/app‑store/developer coordination.
Control shifted from parents to vendors? YES — parents have no role; OS and app stores control the architecture.
Category 3 score: 4 out of 4
Protects minors without identity binding? NO — identity binding is required.
Avoids persistent child identifiers? NO — persistent age attribute is required.
Avoids identity‑conditioned access? NO — enforcement depends on identity classification.
Avoids surveillance expansion? NO — architecture enables expansion.
Category 4 score: 0 out of 4
Score: 4 / 18 → 22% → OPPOSE Auto‑Oppose Triggers: YES (all four)
AB 1856 is not a technical cleanup bill. It is a statewide identity architecture bill disguised as an age‑signal bill.
Under the PKO framework, it fails because it:
requires identity binding
requires cross‑platform enforcement
requires identity‑conditioned access
expands surveillance architecture
shifts control from parents to OS/app‑store vendors
entrenches a persistent age‑identity ecosystem