Google begins blocking unverified Android apps in first four countries
Starting Wednesday, certified Android phones in Brazil, Indonesia, Singapore and Thailand will refuse to install apps from developers who haven't registered their identity with Google — a policy open-source advocates say could end projects like F-Droid.
Google's long-planned overhaul of how Android software reaches phones took effect on Wednesday, as the company began blocking installation of apps from developers who have not verified their identity with it, on certified Android devices in Brazil, Indonesia, Singapore and Thailand. The rule applies whether an app comes from the Google Play Store itself or from a rival marketplace such as Samsung's Galaxy Store or Xiaomi's GetApps, marking the first time Google has extended identity checks beyond its own storefront to the entire Android installation pathway.
The program, called Android Developer Verification, requires anyone distributing an app on a certified device to register a legal name, address and contact details with Google and, for most accounts, submit a government-issued identity document. A background system service, which Google has been rolling out to Android 8 and later devices worldwide since earlier this year, now checks on-device whether an app's developer is registered before letting an install proceed. Unregistered apps are not gone entirely: they can still be sideloaded through Android's developer-only ADB tool, or through an "advanced flow" that Google built for power users, which requires enabling developer mode and sitting through a 24-hour waiting period intended to blunt scam callers who pressure victims into installing malware on the spot.
The numbers behind the rollout
Google says the response from developers has been overwhelming: in a June blog post confirming Wednesday's deadline, the company said "millions of apps have been registered since the verification launched in March, covering nearly all installs on Google Play and a large majority of installs from outside of Google Play." Registration itself is not free for most developers. A standard, full-distribution account costs a one-time $25 fee and requires an ID check, mirroring the fee Apple has long charged for its developer program. Google added a carve-out after developer pushback: a free "limited distribution" tier, aimed at students, teachers and hobbyists, waives the ID requirement entirely but caps an app's reach to 20 explicitly authorized devices.
Seven app marketplaces are enforcing the check from Wednesday: Google Play, Samsung's Galaxy Store, Xiaomi's GetApps, Oppo's App Market, Vivo's V-Appstore, Honor's App Market and Transsion's Palm Store — collectively covering the overwhelming majority of Android phones sold outside China. Google has said the four-country enforcement is a deliberately staged first phase before the requirement goes global "in 2027 and beyond."
Why Google says it is doing this
Google frames the policy as a straightforward anti-malware measure. The company has repeatedly cited internal data showing that apps installed outside Google Play carry malware at dramatically higher rates than apps on its own store, and has pointed to a wave of scams in which callers walk victims through sideloading a malicious banking app in real time. Tying every installable app to a verified legal identity, Google argues, removes the anonymity that lets scammers re-upload malware under a new name after being caught once.
Who is affected, and who is fighting it
The policy's reach well beyond Google's own store is what has alarmed the free and open-source software community. F-Droid, the volunteer-run catalogue of open-source Android apps that has operated since 2010 partly by accepting contributions from pseudonymous developers who will not hand Google a passport scan, says the rule strikes at the core of how it works.
"If it were to be put into effect, the developer registration decree will end the F-Droid project and other free/open-source app distribution sources as we know them today," F-Droid wrote in a statement. "We believe it is about consolidating power and tightening control over a formerly open ecosystem."
That objection has since become the organizing principle of the Keep Android Open coalition that says it now counts more than 70 organizations across roughly two dozen countries, including privacy and digital-rights groups, custom-ROM makers and other alternative app repositories. The campaign has pressed Google for an exemption that would let vetted, institutional distributors vouch for pseudonymous contributors instead of requiring each individual developer to hand over a government ID — a request Google's limited-distribution and advanced-flow concessions do not fully address, since both still route every install decision through a single company's servers.
- Roughly 1 billion-plus certified Android devices worldwide are expected to eventually fall under the requirement once global rollout begins in 2027.
- Seven manufacturer app stores, not just Google Play, are enforcing the check from day one in the four launch markets.
- A $25 one-time fee applies to standard developer accounts; a free tier exists for hobbyists capped at 20 devices.
- Unverified apps remain installable only via ADB or a 24-hour "advanced flow," not through a normal one-tap install.
What happens next
Google has said it will use feedback from the four-country rollout to refine details before extending the requirement everywhere in 2027, including unresolved questions the company has not yet answered publicly: how developers can appeal a mistaken block, how long Google retains the identity records it collects, and whether a path will ever exist for repositories like F-Droid to distribute pseudonymous contributors' apps without individually unmasking them. Regulators are also watching; F-Droid and allied groups have separately argued the policy sits uneasily with the European Union's Digital Markets Act, which requires designated gatekeepers to permit third-party app distribution and sideloading rather than funnel every install back through the gatekeeper's own verification chokepoint, though the EU itself is not among the four markets enforcing the rule this week.
For the roughly billion Android users in Brazil, Indonesia, Singapore and Thailand, the immediate change on Wednesday is mostly invisible: the overwhelming majority of apps they already use, from banking apps to games, come from developers who registered months ago. The visible effect, if any, will land on a smaller population of sideloaders, alternative-store users and the open-source developers who write the software those users seek out — and on whether Google's staged approach becomes the template other platform owners follow, or a cautionary tale about how far a gatekeeper can extend its own security rules before regulators or users push back.
Android Developers Blog — Android developer verification: building a safer ecosystem together
The Hacker News — Google sets Sept. 30 deadline for Android developer verification
F-Droid — Google Developer Registration Decree
Help Net Security — Google sets timeline for Android developer verification enforcement
FTC opens investigation into OpenAI, Anthropic over AI agent safety risks

Pentagon data breach exposed Social Security numbers of 3.1 million current and former troops

Micron reports record $54 billion quarter as AI memory boom accelerates
