Age Verification Laws and Your Business Devices

If you manage business devices, put age-signal support on your 2027 platform roadmap. California's requirements begin in January 2027, while Colorado's enacted requirements begin in July 2028. You do not need a new policy today, but you do need to know which vendors and account types could put your fleet in scope.

TL;DR: California and Colorado have enacted laws requiring certain operating-system and application-store providers to support age signals. The direct duties fall mainly on those providers and covered application developers, but businesses should watch how platform vendors implement the requirements before changing device-management policy.

This isn't a hypothetical. California's AB 1043 was signed in October 2025 and takes effect January 1, 2027. Colorado's SB 26-051 was signed in June 2026 and takes effect July 1, 2028. The laws are similar, but their scope, dates, and implementation details are not interchangeable.

What is the Digital Age Assurance Act?

The Digital Age Assurance Act (California AB 1043) requires covered operating-system providers to offer an interface at account setup for an account holder to indicate a user's birth date, age, or age range. It also requires a reasonably consistent, real-time API through which applications can request an age-range signal. The signal is an age bracket, not unrestricted access to the user's birth date.

Colorado's law is narrower in an important way: its operating-system provisions are tied to providers that operate or preinstall a covered application store. That distinction is one reason businesses should follow vendor implementation guidance instead of treating every computer as automatically subject to the same workflow.

What This Means for Businesses

For organizations with managed device fleets, the practical implications break down into a few categories.

MDM and Endpoint Management. Once platform vendors publish their implementations, mobile device management teams should determine whether new setup screens, account requirements, configuration profiles, or application controls affect their fleets. I would not build an MDM control around an API the vendors have not documented. I would ask the vendor now who owns the setting, what administrators can see, and how managed accounts behave.

Employee Privacy. If an employer-managed account or device participates in an age-signal system, the organization should understand what the platform stores, what applications receive, and whether administrators can see any of it. Do not assume that the API exposes a birth date: the enacted laws describe age-range signals and limit how recipients may use them.

Mixed Operating Systems. Organizations running Windows, macOS, and Linux workstations should expect different implementations across platforms. Do not write one fleet-wide procedure until each vendor publishes a supported design. Track the differences by platform and account type, then manage only the settings that actually exist.

BYOD Complications. Bring-your-own-device programs should pay particular attention to the boundary between a personal platform account and a managed work profile. Whether an employer can see or control an age signal will depend on the platform and MDM implementation, not merely on the presence of the law.

What You Should Be Doing Now

California's law takes effect in 2027 and Colorado's in 2028. My recommendation is to add this to the next device-management review, not launch a separate compliance project before the platforms are documented.

Start by inventorying which operating systems, application stores, account types, and versions are deployed across your organization. Ask platform and MDM vendors for their implementation plans. If a planned implementation will process employee age information, involve privacy or legal counsel in deciding how that data fits into your governance framework.

If you're in a regulated industry, this is worth putting on the radar for your next compliance review cycle rather than waiting for the OS updates to ship and reacting.

The Bigger Picture

Whether these laws achieve their stated goal of protecting children is a separate debate. What matters for IT leadership is that they create new infrastructure at the operating system level that will require management, monitoring, and policy decisions. The same way Microsoft 365 migrations create cleanup work that organizations don't anticipate, OS-level compliance requirements will generate follow-on work that's easier to handle with a plan than without one.

If you're thinking about how these changes affect your device management strategy, let's talk.

Share on LinkedIn

About Etherion Tech

Etherion Tech is an independent IT infrastructure and automation consultancy based in Tulsa, Oklahoma, with over 10 years of experience in systems administration, identity and access management, cloud migration, and process automation. Certifications include CompTIA Security+, Network+, A+, ITIL v4, Azure Fundamentals, and Linux Essentials.

More about the practice · Automation work · Get in touch