Bryan Lunduke keeps a public list at github.com/BryanLunduke/DoesItAgeVerify. The repository tracks, by operating system, whether the OS has implemented age verification in the user account creation flow, the app store rating system, or the system-level content controls. The list is short on “no” answers, but it is not empty. The distros and OSes that have refused so far are a mix of small projects, legacy systems, and one major holdout. The reasons are different in each case, but the pattern is consistent: a small team can say no faster than a large one.
I want to walk through who is saying no, what the practical differences are for users, and what the trajectory looks like. The current picture is not encouraging for anyone who wants their OS to be a neutral tool rather than a child-safety enforcement agent.
What “refusing” actually means
Lunduke’s list categorizes operating systems by their stance on age verification. There are three categories.
- Implemented. The OS requires age verification at account creation, or has built-in age-gated features tied to identity verification. Windows 11, macOS Sequoia, iPadOS 18, and most modern Android builds fall here.
- Refusing. The OS has explicitly rejected age verification, either by community policy decision, by absence of the technical infrastructure, or by active resistance from the maintainers.
- No signal. The OS is too small, too old, or too inactive to have an official position. The category is not “supportive”, it is “we have not been asked.”
- Legacy. The OS pre-dates the age-verification concept entirely. BeOS, Commodore 64, MS-DOS, and Ubuntu 4.10 are all in this category. Their inclusion on the “refusing” list is a joke that makes a serious point: the modern push for age verification is new, and an OS does not have to be hostile to user freedom to be exempt from it.
The “refusing” category is the interesting one. It includes Ubuntu 4.10 (Warty Warthog, the original 2004 release that Lunduke added to the list as a deliberately absurd inclusion), BeOS, Commodore 64, and a small handful of current Linux distributions. The current distros are mostly smaller, philosophically aligned projects, not the ones most desktop users are running. The mainstream distros (Fedora, Ubuntu, Debian, Mint, Pop_OS, Manjaro, openSUSE) are all in the “no signal” or “implemented via downstream” category.
The asymmetry is the point. The distros that can say no are the ones with a small enough user base that no major regulatory body has come knocking. The distros that get noticed are the ones that have already been asked.
Why most distros are not on the list
The “no signal” category covers most active distributions. Fedora, Debian, Ubuntu, Mint, Manjaro, Pop_OS, and openSUSE all fall here. The reason is structural. None of them run their own application store with mandatory age gates. None of them operate a system-level identity service that connects to a third-party verifier. The OS is just the OS. Age verification, where it exists, is implemented by the application (a browser, a social media app, a game launcher) on top of the OS.
This is the model that regulators are now actively trying to break. The EU’s age-verification app prototype, the UK Ofcom guidance, and the Australian eSafety Commissioner’s 2026 white paper all argue that age verification should happen at the OS layer, before any application can run, so that no app can dodge the gate. The OS would become the enforcement point. The application would inherit whatever age range the OS has attested to.
Distros that are silent today are not silent because they support age verification. They are silent because no one has asked them to implement it yet. The moment a major regulator issues an OS-level mandate, the distros with significant European or Australian user bases will be in the same position Microsoft and Apple are in now. The technical implementation is not the hard part. The hard part is the maintainers’ willingness to require identity verification from every user who installs the OS.
The small-distro resistance
The distributions that have refused age verification, like Artix, Void, and Chimera, share three characteristics. They are small. They are philosophically committed to user freedom as a core value. And they do not have a corporate sponsor who would be exposed to regulatory pressure.
Artix Linux has roughly 8,000 active users, by the maintainers’ own 2025 estimate. Void Linux has a similar number. Chimera Linux is even smaller. These are not projects that ship on laptops in Best Buy. They are projects that ship on the machines of people who know how to install an operating system from a USB drive. Regulators do not have a clear path to compel compliance from a project that has no corporate entity, no employees, and no presence in any jurisdiction the regulator can reach.
The result is a two-tier internet. People who install Windows 11 or macOS Sequoia get age verification built into the system. People who install Artix or Void do not. The two groups will be using the same applications, the same websites, the same networks. The only difference is whether the application can rely on the OS to have already verified the user’s age. For most applications, the answer will be “the OS did not verify, so I need to do it myself”, which means the application-level verification becomes the de facto standard, and the OS-level refusal is symbolic.
What the trajectory looks like
Lunduke’s “DoesItAgeVerify” list will keep growing in the “implemented” column for the next 12 to 18 months. The EU’s age-verification app is scheduled for member-state adoption by mid-2027. The UK Ofcom is pushing OS-level integration as part of the Online Safety Act’s 2026 amendments. The Australian eSafety Commissioner has signalled that the under-16 social media ban will be expanded to age-gated app stores in 2027. Each of these mandates targets the OS layer directly. Microsoft, Apple, and Google will comply, because they have to. The distros that can refuse will refuse. The vast middle ground, the mainstream Linux desktop, will be pulled in by user demand and by the application layer refusing to operate without OS-level attestation.
If you care about which path your machine takes, the choice today is the same as it was 20 years ago. You can use the OS that does what Microsoft, Apple, and Google tell it to do. Or you can use one of the small, philosophically committed, regulator-proof projects that will refuse on principle. The latter group is shrinking, not growing. The reasons are not technical.
Trade-offs
Refusing age verification is not a free choice. The cost is that the OS becomes increasingly disconnected from the rest of the regulated internet.
In our case, refusing to implement OS-level age verification means every application on the OS has to do its own verification. A user on Artix who wants to use a regulated social network will be age-gated by the application, not the OS. The privacy cost of that application-level verification is the same as the privacy cost of OS-level verification, but the user has had to give up the OS-level convenience (a single OS-managed identity) to get it. The user has the symbolic victory of using an OS that refuses, but the practical privacy posture is no better than the user of a complying OS.
Your math will be different if you live in a jurisdiction where the OS-level mandates have not yet landed, where the application-level verification is still voluntary, and where the small distros that refuse are still easy to install. In most of Europe, Australia, and the UK, that window is closing.
The migration from “OS is a neutral tool” to “OS is an identity provider” is happening in stages, and the first country to mandate OS-level verification is also the first country where the small distros that refuse become functionally invisible to the regulated applications. The user can still install them, but the applications will not run, or will run with the verification turned off in defiance of the regulator.
If you want to use a small distro that refuses, the choice is still available, and the install path is the same USB-drive routine it has been for 20 years. If you want to use the regulated internet, the OS you use will be the one that complies. These two paths are diverging, and the gap will widen with every regulatory revision.
Bottom line
The operating systems refusing age verification are mostly the small distros that have no commercial exposure and no user base large enough to attract regulator attention. The mainstream Linux desktop is silent today, not because it opposes verification, but because no one has asked. When the regulators do ask, the answers will follow the same pattern as Microsoft, Apple, and Google: implementation, reluctantly, because the alternative is exclusion from a regulated market.
The OS-level refusal is a statement of values, not a practical privacy protection. The privacy cost of age verification, when it lands, will live at the application layer, not the OS layer. Choosing a small distro that refuses gets you the statement. It does not, by itself, get you a private experience.
If I could send a message back to the version of me that thought installing a small distro would solve the age verification problem, I would say three things.
- The OS refusal is symbolic, not technical. The application will still verify you. The OS layer just refuses to do it for the application.
- The list of refusing distros is shrinking, not growing. Every year, more distros get a corporate sponsor, a regulated user base, or a maintainer who would like to keep their day job.
- The real choice is not “OS that verifies” vs “OS that does not.” It is “do you want a single OS-managed identity, or do you want every application to maintain its own?” The refusing distros give you the second. Most users do not actually want it.