Google announced that, starting next year, all developers who distributed Android applications would be required to complete their identification, the first of which was implemented in Brazil, Indonesia, Singapore and Thailand in September 2026, requiring third-party store applications to be validated for installation on certified Android equipment, with a global roll-out from 2027.

Google indicated that this was aimed at protecting users from malicious software and fraud by preventing the re-emergence of prohibited developers. Google claims that the number of malicious software for side-board applications (unofficially installed) is 50 times higher than that for Play Shop, emphasizing that the new regulations will “determinate the outlaws and make their commission more difficult”. To facilitate excess, Google plans to provide early access from October 2025, to open registration to all developers in March 2026, to be enforced in September 2026 in the first regions and to be replicated globally from 2027. The developer can complete the validation through the newly launched Android Devloper Console, and students and amateur developers will receive a special account type.
This coincided with increased regulatory pressure on Google, which earlier this month, the United States court dismissed Google ‘ s appeal in the Epic Gomes case and upheld Play ‘ s decision to constitute an illegal monopoly. The judgement requires Google to open up its competitors to shop and payment options over the next three years, to remove the sole-source incentive and to stop imposing its payment system.

This background has given rise to speculation that Google may strengthen ecosystem control through identification policies to address the safety risks of openness. However, critics argue that the new regulations may weaken Android ‘ s open tradition and increase the burden on small-scale developers, particularly those who are unwilling to disclose personal information or register business entities.
For developers, the new rules may enhance the credibility of applications, but may also generate resistance due to privacy concerns or process complexity. Google claims that the authentication information is not publicly available, but that the identity documents to be submitted may give rise to data security disputes. In addition, it was spearheaded in high-side carrying areas such as Brazil, Indonesia, Singapore and Thailand, reflecting Google ‘ s targeted approach to high-risk markets for fraud. However, global outreach may face challenges of cultural legal differences, especially in the private European market.

