Android's Identity Wall Goes Up Sept. 30, 2026 — Starting With Four Countries

Brazil, Indonesia, Singapore and Thailand are the first markets where unverified developers lose the right to install apps on certified Android devices, sideload or not.

ThreatVectr Newsdesk· 2 min read
Android's Identity Wall Goes Up Sept. 30, 2026 — Starting With Four Countries
Share

Google has fixed a date. September 30, 2026.

On that day, certified Android devices sold in Brazil, Indonesia, Singapore and Thailand will refuse to install apps whose developers have not registered a verified identity with Google. The block applies regardless of how the app reaches the device — Play Store, a third-party storefront, or a sideloaded APK pulled from a website.

The big regional app stores are participating from day one. That includes the device-maker stores shipped by Samsung, Xiaomi and other OEMs, which had been the obvious workaround for any developer hoping to dodge Play Console identity checks.

Verification means a real legal name, a real address, a contact email and, for organizations, a D-U-N-S number. Google has framed the program as an anti-malware measure, citing internal telemetry that sideloaded apps from outside Play carry materially higher rates of malicious behavior. Critics, including the F-Droid project and several developer-rights groups, read it differently: a chokepoint that turns Google into the gatekeeper of who is allowed to write software for the world's dominant mobile OS.

The rollout sequence matters. The four launch countries are not random. Each has a sizable Android install base, an active sideloading culture, and — crucially — no settled regulatory position on whether a platform owner can condition app installation on identity disclosure to a U.S. company. Expansion to additional markets is scheduled for 2027, with the EU and UK timelines still unconfirmed. Whether the program survives contact with the Digital Markets Act in its current form is an open question for the European Commission, not Google.

Hobbyist developers get a narrower carve-out. A separate "student and hobbyist" tier will allow unverified distribution to a limited number of devices, with the apps tied to specific device IDs. The mechanics of that tier have not been fully documented.

Google's announcement page for the program is .

What developers and users should do now

If you publish Android apps outside Play — including via F-Droid, your own site, or an OEM store — assume you need to complete Google's developer verification before Q3 2026 to keep reaching users in the launch countries. Organizational developers should start the D-U-N-S lookup now; the process can take weeks.

Users in the four launch markets should expect that apps from small or pseudonymous developers may simply stop installing next September. Privacy-focused tools distributed by maintainers who decline to register a legal identity with Google are the most exposed category. There is no current indication that existing installed apps will be retroactively removed, but updates from unverified developers will break.

The policy text, not the blog post, is the document to read.

© 2026 Threat Vectr