Policy work now sits squarely in the path of everyday software development, from how code is licensed to whether a contributor can run their own research. Tech Report is publishing its latest Transparency Center data alongside a review of the 2026 state legislative session and a look at upcoming policy fronts.
Request counts and what they actually measure
The H1 2026 numbers show a jump in government takedown requests: 98 across all of 2025, then 708 in the first six months of 2026. Almost all of that gap comes from reporting changes rather than a shift in moderation activity.
GitHub had already broadened its scope in the H1 2025 update to capture every government takedown request received — whether it cites local law, a Terms of Service violation, or simply asks for content removal. Internal tracking was also changed to count all requests, duplicates included when they concern the same content. The result is a measure of how much government reporting activity arrives, not of how much content comes down. Removals under local law or for ToS violations stay rare, and material judged unlawful in a given jurisdiction is still published in the government takedowns repository.
State legislation: the 2026 session in review
GitHub's state-level involvement reached a new high this session. Its developer-facing write-ups covered age assurance — methods for verifying a user's age to provide age-appropriate experiences — and content provenance, the practice of tracking and surfacing whether AI generated or altered a piece of content. Publishing those updates helps developers anticipate legislation touching their tools and projects, and also records where engagement from the open source community shifted a bill's direction.
Provenance and AI transparency in California
The California AI Transparency Act (SB 1000, previously SB 942) aims to let people trace digital content back to its origin. Draft language would have obligated providers to revoke licenses in some situations — impossible to reconcile with the irrevocable terms of widely used open source licenses. The bill moved to a narrower notice-and-response model that removes that conflict. The final package is materially better for open source, though questions about implementation remain. SB 1000 was enrolled on August 30, 2026 and awaits Governor Gavin Newsom's signature by September 30, 2026.
A companion bill, AB 2713, was meant to refine how the Act's provenance requirements apply in practice, especially to platforms. The underlying law, AB 853, defines "large online platform," "file-sharing platform," and "GenAI hosting platform" broadly enough to plausibly cover developer infrastructure such as code repositories. Those definitions don't match regulatory intent, and extending them to code hosting would introduce legal uncertainty and implementation problems for open source infrastructure without addressing the risks the Act targets. Governor Newsom's signing message last year invited 2026 follow-up legislation on technical feasibility; GitHub backed AB 2713 on a support-if-amended basis, asking for the definitions to be tightened. The amendments did not advance this session, leaving the issue for next year.
Age assurance and youth safety bills
Age assurance drew heavy attention. Consumer-facing rules can catch open source operating systems, developer tools, and other infrastructure in their scope when definitions are drawn too wide, even though that infrastructure behaves very differently. In California, involvement with the Digital Age Assurance Act (AB 1043) centered on keeping age assurance obligations off open source operating systems and non-consumer developer services. Colorado's changes to the Age Attestation on Computing Devices law (SB 26) resolved central worries about open source software and developer infrastructure — a demonstration of what coordinated open source engagement can deliver. Illinois signed the Children's Social Media Safety Act (HB 5511) into law with substantial issues left open. Work with policymakers and stakeholders on amendments continues.
Developers hold technical context that policymakers need when rules touch the software ecosystem. Getting that expertise in front of lawmakers early produces more informed and more workable policy.
What's next on the policy calendar
The DMCA Section 1201 triennial rulemaking is the next major proceeding. It weighs temporary exemptions that let developers and researchers circumvent technological protections for specified lawful activities. This cycle's petitions include ones relevant to developers: FOSS license-compliance investigations, scholarly text and data mining, and renewal of the good-faith security research exemption that GitHub has backed in earlier cycles.
Separately, debates over young people's access to AI tools are taking shape. The distinction policymakers need to draw is between consumer-facing conversational services and tools for learning, creating, and building software.
Open source and open source AI stay at the center of the broader agenda. As governments weigh AI-related concerns — cybersecurity, safety, global competition — developers and the open source community should be in the room. That means explaining how open source development actually works, assembling a wider coalition of open source stakeholders, and building channels for developer input. The goal is collaborative work on emerging challenges and policy that sustains a vibrant, well-resourced open source ecosystem while preserving the transparency, research, collaboration, and innovation that openness enables.



