Android’s openness has long allowed software to reach phones without passing through Google Play. Google is adding a new gate to that route: ordinary distribution on certified devices will tie an app to a verified developer identity. The company says the change is meant to make repeat malware campaigns harder without closing Android to outside stores.
Sideloaded packages will gain an accountable owner
The new system focuses on who stands behind an application rather than reviewing every app’s content. A developer distributing outside Google Play will register an account, verify personal or organizational details and connect each Android package name to that account.
Google’s June fraud and scams advisory says verification can include a legal name, address and identification. The policy applies to apps installed on certified Android devices even when the app comes from outside the Play Store. Google frames that accountability as a response to criminals who create new identities and packages after earlier malware is removed.
Registration uses the app’s signing key
Package names identify Android apps, but names alone can be copied in a database. The verification process asks a developer to prove control by submitting an APK signed with the private key used for that software. That cryptographic link connects the registered package to the party capable of producing authentic updates.
The Android Developers program page lists two main steps: verify identity and register package names. Professional developers distributing widely can use a full-distribution account. Play developers may already have much of the required information on file, while off-Play developers can use the Android Developer Console.
Registration at the package level is important because Android treats the package name and signing certificate as durable identifiers. A download site may change, and an app may appear in several stores, but a correctly signed update still traces back to the same developer-controlled key. Google can therefore evaluate whether the installer is presenting software registered by the identity that demonstrated control of the package.
Enforcement begins in selected regions
Google is staging the rollout rather than switching every certified phone at once. Current documentation says apps from participating stores in selected regions must be registered by a verified developer beginning September 30, 2026. Broader expansion is expected after the initial phase.
The regional start matters because the announcement describes a platform direction, not an immediate worldwide block. Developers need time to verify organizations, obtain D-U-N-S numbers when required and register package names. Store operators also need tools that can check verification status without breaking legitimate installation workflows.
The restriction is aimed specifically at certified Android devices, the phones and tablets that ship with Google’s licensed services and pass the company’s compatibility requirements. It does not turn the Android operating system itself into a closed platform. Device makers using uncertified builds can make different choices, although most mainstream consumer hardware falls inside the certified ecosystem where Google’s enforcement will matter.
Hobby projects receive a limited route
Google created a free limited-distribution account for students, hobbyists and developers who share software with a small group. Apps under that route can be installed on up to 20 devices explicitly authorized by end users. The limit distinguishes private testing and personal projects from broad commercial distribution.
The company is also preparing an advanced installation flow for power users who choose to install software from an unverified developer. That exception preserves a deliberate escape hatch while placing ordinary users and common distribution channels behind verification. It does not remove the new identity requirement from the mainstream off-store ecosystem.
Those distinctions will determine how open Android feels in practice. A warning-filled expert flow may technically preserve unverified sideloading while making it rare. A workable hobbyist account and clear package-transfer rules could protect experimentation without giving large anonymous distributors the same freedom.
Verification addresses identity, not app safety
A verified developer can still write insecure or deceptive software. Identity checks do not replace permission controls, malware scanning, app review or careful installation decisions. They create a traceable party and raise the cost of returning under disposable accounts after enforcement.
The system also creates privacy and access questions for developers who distribute lawful software outside major stores. Google will hold verified personal or organizational information, and package ownership disputes will require a reliable appeal process. Independent developers in countries with difficult documentation systems may face more friction than established companies.
Transitions could be particularly sensitive for older apps whose original developer disappeared, organizations that changed legal names or projects that moved between maintainers. A signing key can prove technical control, but it does not always settle who has the legal right to claim a package. Transparent transfer, recovery and dispute procedures will be as important as the initial identity check.
The policy is therefore a significant redesign of sideloading rather than its elimination. Android will continue to accept apps from outside Google Play, but ordinary broad distribution will no longer be anonymous on certified devices. The coming rollout will test whether identity accountability can reduce scam software without turning a historically open channel into one usable only by large publishers.
This article was produced with the assistance of AI and reviewed by Morning Overview editors prior to publication.
More from Morning Overview