Google to Enforce Developer Identity Checks on Sept. 30, 2026 in Four Markets
Google has announced a firm deadline of September 30, 2026, to begin enforcing developer identity verification on certified Android devices in four launch countries. On that day, phones that ship with Google services and Play Protect in Brazil, Indonesia, Singapore and Thailand will prevent standard installations of apps whose makers have not completed identity registration with Google. The restriction applies not only to apps distributed through Google Play but also to titles offered by a range of manufacturer-operated stores, including those run by Samsung, Xiaomi, OPPO, vivo, Honor and Transsion.
“Certified” devices in this context are phones that include Google’s services and Play Protect; by one tally from the F-Droid project, that covers more than 95% of Android handsets outside China. For the majority of end users, Google says the change should be invisible: installs from developers who have completed verification will proceed as before. The new friction targets apps published by creators who decline or fail to register - a group that disproportionately includes independent and free-software projects that have historically distributed without involving Google.
The verification check happens locally on the device. Starting in June 2026, Google will roll out a new system component called the Android Developer Verifier to phones running Android 8 and newer; this service will validate that an app is associated with a verified developer identity before allowing the normal install flow to continue. After the September 30 cutoff in the four initial markets, any app lacking registration will be blocked from the ordinary installation path.
There are still ways to get an unregistered app onto a phone, but they are deliberately more cumbersome. Users can sideload packages via the Android Debug Bridge (ADB) or use Google’s “advanced flow,” a high-friction sideloading procedure introduced earlier that requires enabling developer options, rebooting the device, waiting 24 hours and reauthenticating before the unverified app can be installed. Google plans to make that advanced flow available globally in August.
Google opened developer registration to everyone in March, and it says the system already covers nearly all installs on Google Play and a substantial majority of installs that originate outside Google’s storefront. The registration process asks a developer to supply a legal name, physical address and contact information, and in some cases to upload a government-issued ID. To prove control of each listed app, developers must submit an APK signed with their private key.
To help organizations and third-party stores handle the process at scale, Google is adding APIs for bulk registration and for checking package-name ownership, with OAuth-based delegation so an alternative app store can perform parts of the workflow on behalf of a developer. Two endpoints - the Android Developer ID Status API and the Android Developer Console API - are scheduled to become available in July.
Google will also provide a limited, free distribution path intended for students and hobbyists. That option enters early access in July and will roll out globally in August; it permits sharing apps with up to 20 devices without requiring a government ID or any fees. The full developer account, by contrast, carries a one-time registration fee of $25.
Google frames the policy as an anti-malware measure. The company argues that sideloaded apps host a disproportionate amount of malicious software compared with Google Play, and that many scams involve tricking victims into installing a harmful APK on the spot. Requiring an identity and inserting a 24-hour delay are meant to disrupt those attack patterns. Google says it selected Brazil, Indonesia, Singapore and Thailand for the initial rollout because they suffer heavy incidence of app-based scams, often tied to repeat offenders.
The plan, unveiled in August 2025, has provoked strong criticism from parts of the Android ecosystem. The F-Droid app repository warns the requirement could effectively kill its operation: F-Droid builds and signs packages on behalf of many pseudonymous contributors who are unwilling to supply legal identity information. A coalition called Keep Android Open, backed by more than 70 organizations across 23 countries, has urged Google to exempt apps distributed outside Play from identity checks.
Google’s concessions - the availability of the advanced flow and the 20-device free accounts - address concerns that sideloading will be eliminated entirely, but they do not resolve a broader objection: that a single company would control the smooth installation path for almost every Android handset outside China. Three key issues remain unresolved before Google plans a worldwide rollout in 2027: whether there will be a clear appeals process for developers incorrectly flagged or blocked; what data Google will retain in its identity registry and for how long; and whether there will be any accommodation for repositories such as F-Droid that cannot meet per-app ownership verification without fundamentally altering how they operate.