Google announced a drastic change in the security policy of the Android operating system, establishing mandatory verification for all developers who distribute applications outside the official store, Play Store. The measure, which will come into force from September, aims to combat the spread of malware, financial scams and fraudulent applications, which often exploit the installation of external sources, a process known as sideloading.
This new layer of protection will initially be implemented in specific markets, including Brasil, Indonésia, Singapura and Tailândia, regions where the incidence of digital fraud through malicious applications is particularly high. The global expansion of the policy is scheduled to occur gradually, expected to be completed by the end of 2027, reinforcing the company’s commitment to creating a safer ecosystem for its billions of users.
The decision was based on internal data that reveals an alarming disparity: applications installed via sideloading are more than 50 times more likely to contain malicious software compared to those downloaded directly from Play Store. With the new rule, the company hopes to create a significant barrier against the actions of cybercriminals who take advantage of the system’s flexibility to deceive users.
How the new developer verification will work
The verification process will require developers to create an account on Play Console, the application management platform for Google. Durante registration, it will be necessary to provide identification information, whether personal or business, which will be validated by the company. Desenvolvedores who already have active accounts at Play Console to distribute their apps in the official store will be able to use the same registration for externally distributed apps, simplifying the transition to the new requirement. Essa identity centralization aims to create a trail of accountability, making it difficult for malicious actors to operate anonymously or create new accounts after being banned from the platform.
More on this story: US court orders Google to remove restrictions on third-party app stores
The implementation schedule was planned in phases to allow for smooth adaptation. An early access period for the verification system will open in October 2025, allowing developers to get ahead and ensure compliance. Full opening for new registrations will occur in March 2026. Starting in September, any attempt to install an application from a source whose developer has not been verified will be automatically blocked by Google Play Protect on certified devices, displaying a clear warning about the potential security risks involved in the installation.
The Future of Sideloading and User Experience
Although the new policy significantly restricts the installation of apps from unknown sources, sideloading will not be completely eliminated from the Android ecosystem. The practice, valued by advanced users and developers to test or access applications not available in the official store, will remain possible, but will go through an installation flow with high friction. The goal is to discourage accidental or coerced installations, which are the main attack vectors used by scammers. Para installing an app from an unverified developer, the user will have to navigate multiple warnings and explicit confirmations, a process designed to ensure that they are fully aware of the risks they are taking. Essa approach seeks to balance the freedom characteristic of Android with the need to protect the vast majority of users who do not have the technical knowledge to evaluate the security of an APK file downloaded from the internet. The change is mainly aimed at neutralizing social engineering tactics, in which criminals convince victims to ignore standard security alerts to install banking trojans or invasive adware.
Repercussions in the technology community
News of the new policy generated mixed reactions and intense debate on online forums, such as Reddit, and among independent developer communities. A significant portion of more experienced users criticized the measure, arguing that it represents a limitation on the freedom and open nature of Android, bringing the system closer to iOS’s more closed and controlled approach to Apple.
The concerns extend to developers of open source software, emulators and niche applications who, for a variety of reasons, choose not to distribute their work through Play Store. Para them, the obligation to provide personal or business data to Google for verification is seen as a bureaucratic barrier and a potential invasion of privacy, which could discourage the creation of independent projects.
Countries selected for the initial phase
The choice of Brasil, Indonésia, Singapura, and Tailândia for the initial policy rollout was not random. Esses markets were strategically selected based on analyzes that indicate a high prevalence of financial scams and digital fraud perpetrated through fake applications distributed outside official channels. Brasil, in particular, is facing a growing volume of attacks involving banking trojans that steal credentials and perform unauthorized transactions, making additional protection an urgent need for local users.
Technical details and the role of Play Protect
Google Play Protect, a security tool integrated into Android, will be the main executor of this new policy. Ele already works by scanning and blocking known malicious applications, but its ability will be expanded to identify and block the installation of any software coming from a developer who has not completed the identity verification process.
Technically, the system will work based on the digital signature of the applications. Aqueles signed with cryptographic keys linked to a registered and verified developer account will pass the filter without any problems. On the other hand, apps with unknown or unregistered signatures will immediately trigger real-time alerts and blocking.
Learn more: End of the dispute between Epic and Google: Play Store will have competing app stores from July
This functionality will be implemented on all Android devices that are Google certified, ensuring broad protection coverage. The full integration of the new security logic should be deepened in future versions of the operating system, such as Android 17, to make protection even more robust and efficient on a global scale.
The logic behind the Google decision
The main motivation of Google is proactive user protection. The company argues that while Android offers freedom, this openness has been systematically exploited by criminals to distribute malware on a large scale. Identity verification is one strategy to dismantle this operating model.
By forcing developers to identify themselves, Google creates an accountability mechanism. If an application turns out to be malicious, the company can not only remove it, but also ban the associated developer, preventing him from simply creating a new anonymous account to continue his illicit activities.
Banking Trojans are one of the biggest concerns, as they disguise themselves as legitimate applications, such as system updates or utility apps, to trick the user into gaining access to sensitive information. Esses scams are especially effective in markets where digital literacy is still developing.
The measure, therefore, focuses on preventing the initial distribution of threats, rather than just remediating problems after infection. Trata is a paradigm shift in the platform’s security approach, prioritizing the prevention of recurring threats.
Flexibility for advanced users and developers
Recognizing that the enthusiast and developer community values the flexibility of Android, Google has confirmed that there will be an alternative flow to allow installation of applications without verification. However, this path will be intentionally more complex and filled with explicit warnings about the dangers involved.
On the same topic: Five paid games are free on the Play Store for a limited time
For independent developers and hobbyists who do not have malicious intent, the company promises a simplified verification process, seeking to minimize friction. Google claims to be collecting feedback from the community to fine-tune the system and find the best balance between maximum security for the average user and the flexibility needed for more technical profiles.
Preparations for the transition
As implementation dates approach, the recommendation for developers distributing their applications outside of Play Store is to begin the registration process in Play Console as soon as possible. This advance will ensure that there are no interruptions in the distribution of your software when the rule takes effect. Para users, the change means a need to pay greater attention to the sources of their applications, prioritizing official and verified channels to ensure the security of their devices and personal data.

