Back to School Sale: save 78% Claim offer
California's Under-16 Social Media Law Checks Your Phone, Not Your Location: What AB 1709 and AB 1856 Mean for VPN Users

California's Under-16 Social Media Law Checks Your Phone, Not Your Location: What AB 1709 and AB 1856 Mean for VPN Users

11 Sep, 2026 · Le VPN Research Team

On September 10, Governor Gavin Newsom signed thirteen child-safety bills in a single sitting. The one in every headline is AB 1709, which bars social media platforms from serving “addictive features” to anyone under 16 in California. The one almost nobody wrote about is AB 1856, and it is the bill that decides how a platform will know a user’s age in the first place.

That second question is where this story touches VPN users. The last three years have trained the internet to expect a sequence: a legislature passes an age-check law, websites start demanding a document or a face scan, and VPN demand spikes within hours. It happened in Utah in 2023, in France in June 2025, in the United Kingdom that July, and in Australia in December. So the reflex on Thursday night was predictable: California’s ban is coming, time to get a VPN.

California’s system does not work like that. Its age check asks for no document and takes no interest in where you are. It asks the phone. Here is what the two bills do, how the age signal is built, why a VPN changes none of its inputs, and what the law means for someone who already uses one.

What Did California Sign on September 10, 2026?

The Governor’s office lists thirteen bills signed that day in Marin County, from companion-chatbot rules for children (SB 1119, “Adam’s Law”) to a ban on chatbots in toys (SB 867). “Our children’s safety deserves to be at the center of every conversation about technology,” Newsom said in the release.

Two of the thirteen matter here.

AB 1709, by Assemblymember Josh Lowenthal of Long Beach, is titled “Covered platforms: age restriction: e-Safety Advisory Commission.” It is the under-16 rule, and it cleared both chambers on August 31.

AB 1856, by Assemblymember Buffy Wicks of Oakland, is titled “Age verification signals: software applications.” It amends the Digital Age Assurance Act, the law Wicks wrote last year (AB 1043, signed October 13, 2025) that turns a phone’s operating system into the source of truth about a user’s age. AB 1709 leans on that Act by name, which is why the two bills have to be read together.

What Does AB 1709 Ban?

The operative sentence, in the enrolled text, is short: “A covered platform shall not provide an addictive feature to a user who is under 16 years of age.”

An addictive feature is defined as any of the “psychologically exploitative features intended to maximize engagement that foreseeably lead to compulsive use,” and the bill names two: an addictive feed and autoplay. The Attorney General can add more by regulation. A covered platform is any site, service or app that “offers users or provides users with an addictive feature as a significant part of the service,” with commerce sites and cloud storage excluded.

On its face this is not a ban on accounts. A platform may keep serving a minor a version without the addictive features. The bill’s teeth appear when it does not: a platform that cannot or will not offer that version must “delete the account of a user under 16 years of age and any personal information associated with the user.” The Electronic Frontier Foundation, which asked Newsom to veto the bill, calls the result “a functional ban on social media use for people under the age of 16.” Newsom framed it differently on signing day, telling the Los Angeles Times that “this is about the features themselves. This is about actually addressing the problem, the scrolling, the algorithms.”

The penalties fall on the platform. A knowing violation costs up to $50,000 per affected minor; a negligent one up to $25,000. Only the Attorney General or a local prosecutor may bring the case, and the court “shall consider the size of the covered platform, the severity and duration of the violation” and its good-faith efforts to comply. The bill also creates a seven-member e-Safety Advisory Commission inside the Department of Justice, reporting to the Legislature every January.

The text sets no operative date of its own. Under California’s default rule for statutes passed in a regular session, that means January 1, 2027, which happens to be the day the age signal the bill depends on switches on.

How Will a Platform Know a User Is Under 16?

One sentence separates California from every other age-check law now in force: “Before providing an addictive feature to a user, a covered platform shall verify the age of a user pursuant to the Digital Age Assurance Act.”

Not by scanning an ID. Not by estimating age from a selfie. Not by reading an IP address. By asking the operating system.

The Assembly Privacy Committee’s analysis of AB 1856 lays out the mechanism the Act already contains. An operating system provider, meaning Apple, Google or Microsoft in practice, must present an interface at account setup “that requires an account holder to indicate the birth date, age, or both, of the user of that device.” From that entry the OS derives “age bracket data,” defined as “nonpersonally identifiable data derived from a user’s birth date or age,” in four bands: under 13, 13 to 16, 16 to 18, and 18 or over. When an app is downloaded and launched it must request the signal, which arrives “via a reasonably consistent real-time application programming interface.” A developer that receives the signal is “deemed to have actual knowledge of the user’s age range” and must treat it as the primary indicator of age unless it holds clear and convincing information to the contrary.

The committee is unusually candid about why California went this way. Documentary checks, it writes, require “users to transmit sensitive identity documents to potentially dozens of platforms, creating serious privacy and data security risks,” while biometric and behavioral methods “demand expansive data collection” and “perform unreliably at precisely the age boundaries that matter most.” The declared-at-setup bracket is the compromise: one entry, made once, by the adult who set the phone up, shared as a range rather than a date.

Teenager on a skateboard taking a selfie on Santa Monica pier, with social media icons and a Le VPN shield

AB 1856 tightens the plumbing. Per the Legislative Counsel’s digest, it deletes the definition that limited “user” to a child who is the primary user of a device; it applies the interface duty only “if an operating system operates on a device and has an account setup feature”; it requires the signal to reach both app stores and developers; and it adds a prohibition that did not exist before: “A person shall not request a signal with respect to a particular user from an operating system provider or a covered application store if not required to do so by this title or any other applicable law.” Distributors of open-source operating systems are carved out, after projects such as GrapheneOS said publicly that they would not build the interface. The schedule is unchanged: operating systems must supply signals from January 1, 2027, devices set up before that date get an interface by July 1, 2027, and developers must be requesting signals by the same July deadline.

Apple and Google are ahead of the statute. Apple’s Declared Age Range API, which shipped with iOS 26 in September 2025, returns “the age band or age category, depending on legal requirements in the region” along with how that age was established: self-declared, declared by a guardian, checked against a government ID, checked against a payment card. Google’s Play Age Signals API returns 0-12, 13-15, 16-17 or 18+ with a source tier from “self-declared” to “Government ID and selfie,” and Google announced on July 29, 2026 that it was opening the API to all Play developers globally.

One more clause matters for what follows. If a platform “is unable to verify the age of the user” through the Act, AB 1709 sends it to the age-determination method of the 2024 Protecting Our Kids from Social Media Addiction Act (SB 976), whose age-assurance provision is also operative on January 1, 2027, and whose methods the Attorney General sets by regulation. A desktop browser session with no OS signal is the obvious case. That fallback is the one place where a document or an estimate could enter the picture, and what it will require is not yet written.

Utah Asks Where You Are. California Asks How Old You Are.

VPNs got into the age-verification conversation because of a different kind of law. Utah’s SB 73, which we covered when the “takes effect September 3” headlines turned out to be wrong, is built on location. Its deemed-location provision says an individual “is considered to be accessing the website from this state if the individual is actually located in the state, regardless of whether the individual is using a virtual private network, proxy server, or other means to disguise or misrepresent the individual’s geographic location…” The website must then age-verify that visitor. The whole thing depends on knowing where you are. That is the one thing a VPN changes, which is why Utah’s proposed rule now has a section on “geolocation obfuscation” and why Aylo sued.

California’s two bills contain no comparable clause. AB 1709 does not mention location, IP addresses or VPNs. AB 1856 does not either. There are now three distinct models in US law, and they treat a VPN very differently:

ModelWho checksWhat is checkedDoes a VPN touch the input?Status
Website-level (Utah SB 73; UK Online Safety Act)The website you visitYour location, then your age, at the siteYes: it changes the apparent locationUtah: in force since May 6, 2026; enforcement against Aylo paused to October 22
App-store-level (Texas SB 2420; Utah SB 142)The app store, at account creationAge of every account holder; parental consent for minorsNo: tied to the accountTexas: in effect after a Fifth Circuit stay; the Supreme Court let enforcement continue on July 6, 2026
Device-level (California AB 1709 + Digital Age Assurance Act)The operating system, at device setupThe primary user's declared birth date, shared as a bracketNo: the signal is on-deviceOS duty from January 1, 2027

The line worth remembering: an age signal is a statement about who set the phone up. A VPN is a statement about where the phone appears to be. The two never meet.

Does a VPN Get Around California's Under-16 Rule?

No, and it is not built to.

A VPN does two things. It replaces the IP address that websites and apps see with the address of the VPN server, so the far end sees Paris or Frankfurt rather than your home connection. And it encrypts everything between your device and that server, so the coffee-shop router and your internet provider see an encrypted tunnel rather than your traffic. Both are useful. Neither reaches the age bracket stored against the Apple or Google account on the device, or the on-device API that hands that bracket to an app. A fifteen-year-old whose parent entered a 2011 birth date at setup carries the 13-to-16 bracket on a Los Angeles Wi-Fi network and on a VPN server in Amsterdam alike.

Location does enter in one place, and it is worth being precise about where. AB 1709 protects users in California, and its text does not prescribe how a platform decides that a user is one. In practice the vendors have tied their state-specific behavior to the account, not the network of the moment: Apple applied Texas’s requirements to “new Apple Accounts in Texas” from January 1, 2026, and Google to Texas accounts created after May 28, 2026. An account set up in California with a minor’s birth date will be treated as a Californian minor’s account wherever the phone connects from.

Two caveats, because the tidy version above hides them. The fallback route exists, and until the Attorney General writes the SB 976 regulations nobody can say what a platform that receives no signal will ask for. And every model in the table above, including California’s, depends on the truth of what was entered at setup: a device configured with an adult’s birth date carries an adult’s bracket, and the committee analysis concedes that simply asking for a birth date, while it burdens nobody, does not verify anything a minor is unwilling to answer honestly. California’s bet is that the person entering the date at setup is a parent, not the child.

What no model in the table does is penalize the user. Nothing in AB 1709 or AB 1856 fines a person for using a VPN, for any purpose. That was true of Utah’s law as well, despite the headlines, and it is true here. Our 2026 guide to where VPNs are legal covers the handful of countries where the answer is different.

What Happened in the UK, Australia and France When Age Checks Arrived?

California is late to this. The three jurisdictions that went first each tested a different design, and each produced numbers.

The United Kingdom chose the website model. From July 25, 2025 the Online Safety Act required sites hosting adult and other age-restricted content to run “highly effective age assurance,” meaning photo ID matching, facial age estimation or similar, at the site. Top10VPN’s demand tracker recorded UK VPN demand 1,327% above its prior 28-day average on July 25, 1,712% above on July 26 and 1,987% above on July 27. A year later, Ofcom’s first statutory report on age assurance, published in mid-July 2026, counted more than 69 million age checks across a sample of 32 services in the second half of 2025, a 23-fold increase on the six months before, and said the share of children encountering a highly effective check had risen from 25% to 43% between July 2025 and January 2026. The checks work; the checks also send people to VPNs. Both are true, and the UK’s VPN market has looked different since.

Australia chose a platform obligation without a mandated method. Its under-16 minimum age took effect on December 10, 2025, requiring platforms to take “reasonable steps” to keep under-16s off, with fines up to A$49.5 million and no penalty for children or parents. On January 16, 2026, eSafety reported that platforms had removed access to 4.7 million under-16 accounts by mid-December; Meta says it alone had removed access to more than 750,000 Facebook and Instagram accounts by June 30, 2026. Top10VPN logged a 103% demand spike on December 7. Newsom’s verdict on the Australian approach, per the Los Angeles Times, was that young people are “all figuring out a way to game that system,” which is the argument for targeting features rather than accounts.

France chose an under-15 ban, and its highest court struck it down. On August 14, 2026, the Conseil constitutionnel’s decision 2026-911 DC censured Article 1 of the law that would have barred under-15s from social networks from September 1. The ban was a disproportionate restriction on freedom of expression, the court held, and it violated privacy because the law “implies, by itself, that every person, even an adult, prove their age” without the legislature setting the conditions and limits for doing so. The government now aims to rewrite the text by spring 2027. France had already seen what site-level checks do to VPN demand: Top10VPN measured demand 570% above normal on June 5, 2025, when age verification arrived on adult sites. EFF pointed to the French ruling in the statement it published the day California signed.

The pattern holds across all three. The VPN surge follows laws that make the website check a document. California’s design avoids the document, which is the same objection the French court raised, and it avoids location, which is what makes a VPN relevant in Utah. Whether that also avoids the surge is a question for January 2027, not September 2026.

When Does Any of This Start?

  • September 10, 2026: AB 1709 and AB 1856 signed.
  • October 22, 2026: Utah's non-enforcement period against Aylo ends, unless the judge rules on the preliminary injunction first.
  • January 1, 2027: AB 1709 takes effect. Operating system providers must begin supplying age signals under the Digital Age Assurance Act. SB 976's age-assurance provision becomes operative.
  • July 1, 2027: Deadline for an age interface on devices set up before 2027, and for developers of apps updated since January 2026 to be requesting signals.
  • Spring 2027: The French government's target for a rewritten under-15 law.
  • Court dates: none yet. NetChoice's reaction to the signing, "the state cannot simply describe speech as addictive and then claim a right to regulate access to it," reads like a complaint in draft. The Ninth Circuit let most of SB 976 stand in September 2025; the Texas app-store law survived to the Supreme Court's refusal to intervene. Expect litigation, and expect the effective dates above to be the first thing it targets.

What This Means if You Use a VPN in California

For an adult, nothing changes. Your account carries an adult bracket; apps will read it from January and treat you as they do today. Your VPN keeps doing what you bought it for: keeping your IP address out of every site’s logs, encrypting your traffic on hotel and airport networks, and letting you reach your home services when you travel. If you are new to any of that, our guide to using a VPN in the United States is the place to start; Le VPN’s plans cover 10 devices at once and come with a 30-day money-back guarantee.

If you are a parent, the law’s protection for your child now rests on one entry: the birth date you type when you set up their phone. Enter your own and the device will tell every app it belongs to an adult. Enter theirs and the bracket follows the phone. That single field, not any app’s settings page, is where California’s rule begins. It is worth a broader look at how children’s devices are set up before January.

About the author

Le VPN News Desk

The Le VPN Research Team is the news desk of the Le VPN blog. It tracks internet shutdowns, censorship, new privacy laws, and cybersecurity incidents as they unfold, and turns them into clear, sourced reporting. Every article is built from primary sources, fact-checked against them, and reviewed under Le VPN's editorial rules before it is published.

Articles by Le VPN Research Team →

FAQ: California's Under-16 Law, Age Signals and VPNs

Set Up the School Year for 78% Less

Campus Wi-Fi, dorm streaming, research without borders - protect every device the family takes to school, for 3 years at $2.22 a month.

Claim offer

30-day money-back guarantee

VTNV Solutions Limited. © 2026 Le VPN. All rights reserved. Sitemap