Starting September 30, apps from developers who have not been verified by Google can no longer be installed or updated through participating app stores on certified Android devices in Brazil, Indonesia, Singapore and Thailand. It is the first enforcement date in a program that Google says will reach every certified Android device worldwide in 2027 and later.
Google’s line is that the rule targets anonymous malware distributors. Critics answer that it also reaches hobbyists and open-source stores that have never asked anyone’s permission.
What starts on September 30, and where
The requirement was set out in a March 30, 2026 post on the Android Developers Blog by Matthew Forsythe, Director of Product Management for Android App Safety, whose timeline lists September 30, 2026 as the date registration begins in the four countries, with a global rollout in 2027 and later. In the post, Forsythe said analysis showed “over 90 times more malware from sideloaded sources than on Google Play,” the statistic Google uses to justify the change.
The wording tightened in June. As Help Net Security quoted him, Forsythe wrote that “only apps registered by verified developers can be installed and updated on certified Android devices from September 30, 2026.” Google’s developer verification page names the participating stores as Google Play, HONOR App Market, OPPO App Market, Galaxy Store, Palm Store, V-Appstore and GetApps, and says the protections apply to certified devices running Android 7 or later.
The runway was long. The March timeline put the launch of the Android Developer Verifier system service in April 2026, early access to limited distribution accounts in June, and the global launch of those accounts and the advanced sideloading flow in August, all before enforcement began. Google also shipped two developer tools, an Android Developer ID Status API to check whether a package name is already registered and an Android Developer Console API to register names from inside build environments, as its June update describes.
Registration, fees and the free tier
Most working developers will not notice. Google says its Play Console automatically registers eligible apps from developers who have completed identity verification, and the same June 18 update reports that more than 99 percent of Google Play apps are already registered. Developers distributing only outside Play register through the Android Developer Console, while those on both channels use Play Console, per Google’s verification page. The exposed group is developers who distribute outside Google Play, or whose apps Play never registered, and who have not completed verification.
For them the rules depend on the account type. Google’s help page describes a one-time $25 fee for a full distribution account, with government ID verification and, for organizations, a D-U-N-S number. A limited distribution account for students and hobbyists is free, needs no government ID and permits distribution to up to 20 devices.
What an unverified developer can still do
The requirement closes the ordinary route and leaves two narrow ones. Google’s March post says unregistered apps can still be sideloaded with the Android Debug Bridge, the developer command-line tool, or through a new advanced flow for experienced users. The Hacker News described that advanced flow as requiring developer mode, a 24-hour wait and reauthentication, which Google presents as protection against coercion scams, and which critics call a deliberate obstacle.
The practical effect falls unevenly across the four countries’ developers: a Brazilian studio that already ships on Google Play is untouched, while a Thai hobbyist who shares a build through a direct download link now faces either a free account capped at 20 devices or the $25 full registration with identity checks. So an unverified developer in the four countries does not vanish from Android, but the apps lose the reach of the stores, and users who want them must go through friction that most people will not attempt.
The objection from open-source stores
F-Droid, the open-source app repository, has said the requirement “would end its project,” according to The Hacker News, because its contributors are often pseudonymous and cannot supply government identification without giving up that model. A “Keep Android Open” campaign, which the outlet says is backed by more than 70 organizations across 23 countries, argues that Google would control installation decisions on about 95 percent of Android devices outside China.
Google’s answer is that the free limited account and the advanced flow keep an exit open for hobbyists and power users. The Hacker News lists what remains unresolved: whether there will be an appeals process for developers flagged by mistake, how long Google will retain the identity data it collects, and whether any alternative path exists for repositories such as F-Droid. None of those was answered in the Google pages read for this article, and September 30 arrives with them still open. The device-level view is the counterweight: the rule applies only to certified Android devices, the ones that ship with Google’s services, and Google’s own timeline extends it to all of them in 2027 and later.
This article was produced with the assistance of AI and reviewed by Morning Overview editors prior to publication.
More from Morning Overview
- Card skimmers hidden on gas pumps and ATMs are draining accounts, and here’s the tell
- Doctors warn a silent liver disease now affects one in three American adults
- Hackers are hijacking outdated home routers, and the FBI named the models to check
- Older Teslas are wearing out in ways early owners never saw coming