- Starting in September 2026, app creators will need to register their real identity for their programs to be installable.
- The measure affects both the Play Store and third-party stores from manufacturers such as Xiaomi, Samsung, and Honor.
- Google justifies the change by stating that malware is 50 times more common in apps downloaded from outside the official store.
- Advanced users will be able to continue installing unverified APKs through an 'advanced flow' with 24-hour waits and multiple warnings.
It's no secret that Android's freedom has always been its biggest advantage over Apple's closed system. Being able to download an APK from anywhere and install it without much explanation has been commonplace for millions of users, especially in Spain, where this ecosystem dominates the market. However, Google has decided it's time to bring some order to the system, and to that end, it will implement a mandatory verification system that promises to be a game-changer starting in the second half of 2026.
This new policy not only affects those who publish on the Play Store, but extends to the entire ecosystem of certified devices. If you're someone who enjoys trying out tools from external sources, get ready, because developer anonymity is coming to an end . The idea isn't to outright ban third-party apps, but rather to ensure that Google knows, by name, who is behind every file you try to install on your mobile phone, to avoid unnecessary surprises.
A common front among the major manufacturers
What makes this move truly significant is that Google isn't alone in this endeavor. Giants like Xiaomi, Samsung, Honor, and OPPO have already confirmed they will integrate this system into their own app stores, such as GetApps or the Galaxy Store. This means that, regardless of where you search for your software, the Android Developer Verifier system will be working in the background to verify that the developer has undergone the official verification process.
Starting September 30, 2026, the rollout will begin in pilot markets, but the intention is for it to reach Europe and the rest of the world in 2027. Developers will have to provide sensitive data such as their physical address, a contact phone number, and, in the case of businesses, their DUNS number. Google has taken this seriously because, according to its own reports, it detects up to fifty times more malware in apps circulating outside its official store than in those under its direct control.
What will happen to traditional APKs?
If you're wondering whether this is the end of free installations, the short answer is no, but it's not going to be convenient. For more experienced users, Google will maintain what's called the "advanced flow." If you try to install an app from someone who hasn't identified themselves, the system will force you to navigate through very deep settings menus , accept several risk warnings, and, in some cases, wait up to 24 hours before the installation button actually activates. It's a way of throwing obstacles in the way so that the average user thinks twice.
On the other hand, students and coding enthusiasts will also have their place. Limited-distribution accounts will be created that don't require official identification or payment, but there's a catch: applications created with this method can only be installed on a maximum of 20 devices. This measure is designed so that those who are learning can test their skills without being compared to a professional cybercriminal, but it limits its reach so that it doesn't become an escape route for widespread malware.
Privacy versus security: the eternal debate
As expected, this tight control hasn't been well received by everyone. Organizations that advocate for an open system, such as the creators of Tor and LineageOS, have joined the "Keep Android Open" campaign. They argue that requiring registration with a central authority violates the philosophy upon which Android was founded. Many fear that this verification layer is the first step toward turning mobile phones into walled gardens where only what Google deems appropriate can be run, something that clashes with European regulations such as the Digital Markets Act.
Despite the criticism, the roadmap seems unshakeable. In June 2026, we will begin to see a new system service called com.google.android.verifier silently installed on our devices. Although we won't notice anything at first, it will be the foundation upon which all future security will be built . In Spain, where many users rely on repositories like Aptoide or F-Droid, this change will mark a turning point in how we understand device ownership and responsibility for what we choose to install on it.
This new legislative and technical landscape for Android aims to professionalize software development and eliminate attackers who hide behind fake identities to steal banking data. While we may lose some of the unfettered freedom of the early years, the industry seems convinced that identifying developers by name is the only way to prevent the world's most widely used operating system from becoming a sieve for threats. Time will tell if this move by Google succeeds in cleaning up the ecosystem or if, on the contrary, it ends up stifling innovation among independent developers who preferred to remain outside the radar of large corporations.
