What's documented
S.5090, the Digital Age Assurance Act of 2026, was introduced July 22 by Sen. Andy Kim (D-NJ), with Sens. Adam Schiff (D-CA), Cynthia Lummis (R-WY), and John Barrasso (R-WY) signed on. It's sitting in the Senate Commerce, Science, and Transportation Committee, hasn't had a vote, and — even if passed today — wouldn't take effect until 18 months after enactment. Its stated purpose is straightforward: stop children from accessing age-inappropriate content and being tracked and advertised to online, without forcing anyone to hand over a government ID or submit to facial scanning.
The mechanism it uses to do that is what matters here. We read the bill's full text directly. Section 3(a)(1)(A)(i) requires every "operating system provider" to make each user "establish an account with the provider through a process that requires the user to indicate the date of birth and age of the user" before the operating system can be used on a "covered device" at all. Existing accounts get pulled in too, with a narrow carve-out only if the provider already has the user's age on file for another legal reason. The OS then sorts the user into an age bracket and can pass that signal to apps and websites.
Two definitions decide how far this reaches, and we checked both against the text. A "covered device" is "a computer, mobile device, or other general purpose computing device that has the capability to run an operating system" — no carve-out by size or purpose. An "operating system provider" is "a person that develops, licenses, or controls the operating system software" — no revenue threshold, no user-count threshold, no exemption for noncommercial or open-source projects. We searched the full bill text for "open source," "open-source," "noncommercial," "nonprofit," and "small business." None of those words appear anywhere in it.
To be fair to what the bill doesn't do: Section 10 explicitly bars requiring a government-issued ID, biometric data, or facial-age-estimation to satisfy this — a self-reported birth date is enough on paper, and the bill doesn't touch FERPA or COPPA. This isn't a surveillance-ID mandate. It's an account mandate.
Where this idea actually comes from
S.5090 isn't a first draft. It nationalizes a template already moving through states. California's own Digital Age Assurance Act (AB-1043) — same name, nearly identical mechanism — was signed by Gov. Newsom in October 2025 and takes effect January 1, 2027; it uses the same broad "any general purpose computing device" language that pulls in Linux distributions and SteamOS, not just Windows and Android — a scope narrow enough to trigger its own backlash: the bill's author introduced a follow-up amendment, AB 1856, specifically carving out open-source operating systems, which passed the Assembly 68-1 in May 2026 and was in the Senate as of July 1. California's legislature, in other words, already recognized this exact gap and moved to close it. S.5090, introduced weeks later, does not. Colorado's SB26-051 passed its state senate in March 2026 with similar terms. Brazil's Digital ECA took effect March 17, 2026, with fines up to roughly $9.5 million per violation for operating systems that don't comply. S.5090 would take that same account-and-age-declare mechanism and put it under federal law and FTC enforcement.
The organization that already said no
BL:UF has covered what an account-less operating system is actually for: Samuel Tunick, the traveler now facing federal charges after GrapheneOS's duress-wipe feature erased his phone at the Atlanta airport rather than unlocking it for Customs and Border Protection. That feature, and the fact that GrapheneOS holds no account and no data trail by design, is the whole reason it existed for him to use.
How many people that actually affects is itself a number nobody can state precisely — including GrapheneOS. The project's own account put it plainly in April 2026: "We know we have at least around 400k users based on update downloads." That's a floor, not a count, and GrapheneOS says so itself: with no telemetry and no unique identifiers sent to its servers, the only way to approximate usage at all is by counting how many devices check in for software updates — which measures devices, not people, misses anyone who updates late or sideloads updates directly, and can't be corrected in either direction. It's the same design principle the account mandate would eliminate, showing up as a limit on what even its own developers can say about their own user base.
On March 20, 2026 — responding to California's, Colorado's, and Brazil's laws, four months before S.5090 was even introduced — GrapheneOS posted its position publicly: "GrapheneOS will remain usable by anyone around the world without requiring personal information, identification or an account." And on what happens if a region requires otherwise: "If GrapheneOS devices can't be sold in a region due to their regulations, so be it."
To be precise about what that statement does and doesn't cover: GrapheneOS has not, as of this writing, commented on S.5090 by name — it's a newer bill than their March statement. But the requirement S.5090 would impose federally is functionally the same one California already imposed at the state level, the one GrapheneOS was already responding to. Their stated answer to "build an account system or leave" has already been "we'll leave," not "we'll build it."
The unresolved legal question
GrapheneOS Foundation, which develops the OS, is not a U.S. company. It's incorporated as a federal nonprofit corporation under Canada's Not-for-profit Corporations Act. That raises a real, unsettled question this bill doesn't answer: how far federal enforcement — run through the FTC under this bill — actually reaches over a foreign, nonprofit software developer that doesn't sell ads or user data and has no U.S. corporate presence.
It isn't a clean exemption either way. Section 5 of the FTC Act generally doesn't reach organizations with no genuine profit motive — but courts have repeatedly declined to treat nonprofit status alone as immunity, especially where the organization takes donations, which GrapheneOS does. (GrapheneOS itself is explicit that it doesn't sell devices or endorse any company that does — hardware sold with GrapheneOS pre-installed comes from unaffiliated third parties.) Nothing about this has been tested against a case like GrapheneOS specifically. It's an open question, not a settled one.
What this piece is not saying
This isn't saying Sens. Kim, Schiff, Lummis, or Barrasso intend to shut down privacy-focused operating systems — their stated goal is keeping kids away from harmful content and ad-tracking, and the bill's self-report/no-ID design reflects real privacy-consciousness on that front. It isn't saying S.5090 is close to becoming law — it's one committee vote from dying, like most bills, and carries an 18-month delay even if it passes. It isn't saying GrapheneOS will definitely be pulled from the U.S. market — that's their own stated fallback position, not a fact about what will happen. And it isn't resolving whether the FTC could actually enforce this against a Canadian nonprofit — nobody has answered that yet, including this piece.
What can I do
This bill is sitting in Senate Commerce Committee right now — that's the actual point of leverage, before it either dies quietly or moves to a floor vote. Committee Chair Ted Cruz and Ranking Member Maria Cantwell control whether it gets a hearing or a markup; cosponsor Sen. Cynthia Lummis also sits on that committee. You can find the full committee roster and contact information and weigh in directly with your own senator if they're on it, or with your state's senators regardless.
You can also track S.5090 directly on Congress.gov for any committee action, amendments, or scheduled votes — this is exactly the stage where public comment to a committee office still changes what happens next, not after a floor vote when the outcome's already set.
Don't take our read of the bill's text on faith, either: LegisPlain has a full plain-English breakdown of S.5090 — what it does, who benefits, who gets hurt, and the same red flags this piece raises — so you can check the source material yourself.
The Receipts
GrapheneOS — Wikipedia, citing GrapheneOS's own April 2026 "at least around 400k users" estimate and its update-log methodology
California moves to exempt Linux from its upcoming age-verification law after backlash — Tom's Hardware, on AB 1856's open-source carve-out
One Step Forward, Two Steps Back: CA's AB 1856 Exempts Open Source But Expands Age-Gating — Electronic Frontier Foundation
S.5090 — Digital Age Assurance Act of 2026, full bill text — GovTrack (fetched and read directly)
S.5090 — Congress.gov bill page — status, cosponsors, committee referral
Senators Kim, Schiff, Lummis, Barrasso Introduce Bill to Protect Children Online — Sen. Andy Kim's office
GrapheneOS refuses to comply with new age verification laws for operating systems — Tom's Hardware
GrapheneOS Won't Implement Age Verification — Privacy Guides
California introduces age verification law for all operating systems, including Linux and SteamOS — Tom's Hardware
California Digital Age Assurance Act — background on AB-1043
Who Owns GrapheneOS? Foundation, Governance & Funding — on its Canadian nonprofit status
He Gave Border Agents a Passcode. It Wiped His Phone Instead of Unlocking It. — BL:UF's prior coverage of the Tunick case



