All news
regulationproductlegal

Illinois Law Forces OS-Level Age Checks by 2028

16 Aug 2026

Illinois has become the latest state to force operating systems into the business of age verification—and this time, there's no carve-out for open source developers.

Governor JB Pritzker signed HB5511, the Children's Online Social Media Safety Act, into law after it passed the House 82-27 and the Senate 57-0. The bill requires operating system providers to build an age verification interface by January 1, 2028, with applications required to start requesting age signals by July 1, 2028.

What the law requires

HB5511 sorts users into four age brackets: under 13, 13-15, 16-17, and 18 and up. Once a user is flagged as a minor, apps must automatically enable a set of safety defaults:

  • Restricted content feeds
  • Profiles hidden from adult strangers
  • Blocked messages from adults
  • Masked precise location
  • Disabled notifications between 10 PM and 7 AM

Parents can override these default settings for their children, and minors over 16 can override them for themselves. Non-compliance carries fines of up to $50,000 per violation.

The open source gap

Illinois isn't alone in pursuing OS-level age signals—Colorado's SB26-051 and California's AB-1043 use similar frameworks. But both of those states carved out exemptions for open source software: Colorado's bill was amended to exempt operating systems and developers distributing software under open source terms, and California's AB-1043 was amended via AB-1856 to exclude open source OS providers.

Illinois's HB5511 includes no such exemption. That gap means open source OS and app developers operating in Illinois could face compliance burdens their counterparts in Colorado and California don't. Sources differ on how this will play out in practice—the report doesn't specify exactly how the missing exemption will affect open source projects operationally, or what technical mechanism will be used for age verification at the OS level.

What's still unclear

Several operational details remain undefined: how age verification will technically work at the OS level, what data gets collected or shared, how enforcement will function beyond the per-violation fine, and whether the law reaches app developers or OS providers based outside Illinois or the US. There's also no detail on the verification method itself—whether it involves ID checks, biometric estimation, or parental attestation.

Why founders should care

If you're building an app or OS-level product, this law likely means budgeting for age-verification infrastructure well before the 2028 deadlines—especially if Illinois users are part of your base. Founders working with open source components should probably pay close attention: Illinois's lack of an exemption could plausibly mean higher compliance costs than in states with more founder-friendly carve-outs.

More broadly, the pattern across Illinois, Colorado, and California suggests OS-level age-signal requirements may be becoming a durable regulatory trend rather than a one-off. Founders planning product architecture over the next two to three years should likely treat this as a multi-state compliance surface to monitor, not a single-state anomaly. Given that exemption rules already diverge between states, teams operating nationally may need state-by-state compliance tracking rather than assuming a uniform standard will emerge.

On the upside, the law creates a plausible window of opportunity: startups building age-verification tooling, or safety-setting frameworks matching the law's required features (restricted feeds, message blocking, location masking), may find growing demand as the 2028 deadlines approach across multiple states.

Sources