Google announced a major change to how Android apps are installed on certified devices. The company will begin verifying the identity of developers who distribute apps outside the Play Store. The change will not ban sideloading or third-party app stores. It will add an identity check that aims to reduce malware and fraud on Android devices.
What Google will require and when it will start
Google will invite developers to an early access program beginning in October 2025. The company plans to open verification for all developers in March 2026. By September 2026, the requirement will apply to apps installed on certified Android devices in Brazil, Indonesia, Singapore, and Thailand. Google will continue to expand the rules set globally into 2027. These measures apply to certified Android devices that ship with Google services.

Why Google is making this change
Google says that apps installed from internet sideloading sources carry far more malware risk than apps from the Play Store. The company points to internal data that shows a much higher incidence of harmful apps coming from outside sources. By tying installs to verified developer identities, Google aims to make it harder for bad actors to distribute apps while keeping the platform open to legitimate developers.
How this affects developers and their privacy choices
Developers will need to provide their legal name, address, email, and phone number to register as a verified developer. Google notes that student and hobbyist creators can use a separate account type that fits noncommercial needs. Some independent developers may choose to register a business for privacy reasons. The verification step may change how some small developers publish apps, but Google says it will not prevent distribution outside the Play Store.
What consumers and app stores should expect
Certified Android devices will enforce the rule set as the verification rollout reaches each region. That means users on those devices will see apps only if the developer is registered or verified when the new requirement is active. Alternative app stores and direct sideloads remain legal, but the identity layer will increase accountability and traceability for distributed apps. Device makers and store operators that are Play Protect certified will work with the new checks.
Tradeoffs and practical issues to watch
The change aims to reduce scams and malware. At the same time, it raises questions for developers who prefer anonymity. It also creates extra steps for small teams and hobbyists. Google will provide a separate pathway for noncommercial creators, but the details will matter. Accessory makers, carrier partners, and enterprise IT teams should also test how the verification flow interacts with device management and distribution policies.
How to prepare if you are a developer
Plan to verify your account once the early access invites begin. Gather accurate legal and contact information ahead of time. If you prefer privacy, consider formal business registration and business contact channels to separate personal data. Test sideload installation flows on certified devices as Google opens verification for broader developer access in March 2026. Seek clear guidance for MagSafe or accessory compatibility if you publish hardware companion apps.

Regulatory and industry context
The move follows a larger global push for safer app ecosystems. Regulators in the European Union and courts in other jurisdictions have pressed big platforms to open markets and to add safety controls at the same time. Google continues to allow alternative stores and sideloading in response to legal rulings while adding what it calls reasonable security steps. The verification requirement is part of that balancing act between openness and user safety.