Android's Identity Wall Goes Up Sept. 30, 2026 — Starting With Four Countries
Brazil, Indonesia, Singapore and Thailand are the first markets where unverified developers lose the right to install apps on certified Android devices, sideload or not.

Key points
- On September 30, 2026, certified Android devices in Brazil, Indonesia, Singapore and Thailand will block apps from developers who haven't registered a verified identity with Google.
- The block covers every install path: Play Store, device-maker storefronts and sideloaded APKs.
- Samsung, Xiaomi and other OEM app stores are participating from launch, closing the obvious workaround.
- A hobbyist tier exists, but it ties unverified apps to specific device IDs and its full mechanics haven't been published.
- Updates from unverified developers will break; there's no sign existing installs will be pulled retroactively.
What exactly is Google requiring?
Verification means a legal name, a physical address, a contact email and, for organizations, a D-U-N-S number (a nine-digit identifier issued by Dun & Bradstreet to confirm a business exists). Google frames the requirement as an anti-malware measure, citing internal telemetry showing sideloaded apps from outside Play carry materially higher rates of malicious behavior. Critics, including the F-Droid project and several developer-rights groups, read it as a chokepoint: Google becomes gatekeeper of who's allowed to write software for the world's dominant mobile OS.
We first covered this program on 22 June 2026, and the core concern then was the same as now: that identity disclosure to a U.S. Platform owner sits in unresolved tension with local data-protection law in each launch country.
Why these four countries first?
None of the four launch markets has a settled regulatory position on whether a platform owner can condition app installation on identity disclosure to a U.S. Company. Each has a large Android install base and an active sideloading culture. That combination gives Google a meaningful test without triggering immediate confrontation with the EU's Digital Markets Act, which may not accommodate this policy in its current form. Expansion to additional markets is planned for 2027; EU and UK timelines remain unconfirmed.
Should you worry about your installed apps?
Existing installs appear safe. Google hasn't indicated it will remove apps already on a device. What breaks is updates: if a developer hasn't verified by September 30, their updates won't install on affected devices in the four launch markets. For users, the most exposed category is privacy-focused tools distributed by maintainers who won't register a legal identity with Google. Pseudonymous open-source developers are in a structurally difficult position here.
The debug-flag incident we reported on 3 June showed how a sideloaded app could silently steal Microsoft tokens without a prompt. That's the kind of risk Google says this policy addresses. Whether identity verification actually stops it, given that malicious actors can register real identities, is a question the announcement doesn't answer.
What developers and users should do now
If you publish Android apps outside Play, assume you need to complete verification before Q3 2026 to keep reaching users in the launch countries. Organizational developers should start the D-U-N-S lookup now; it can take weeks. Individual developers should work through Play Console's verification flow before the queue gets congested.
Users in the four markets should expect some small-developer apps to stop installing next September. Read the policy text, not the blog post. That's the document that will matter when something breaks.



