Google’s Android Developer Verification sparks debate over open-source access and security

Google’s new app verification system, set to roll out in 2026, aims to improve security but raises concerns about centralising control and restricting independent developers, prompting backlash from open-source communities.

Google’s plan to require Android Developer Verification marks a significant shift for the platform’s open model. According to Google’s support pages, the company introduced the system in August 2025 to improve security and accountability, and it requires developers to verify their identity and register their app package names before their software can be installed on certified Android devices. The rules are not confined to the Play Store: they also cover apps distributed outside it, including sideloaded APK files and software shared through alternative channels. Google says the aim is to make it harder for malicious actors to keep returning under different names.

The roll-out is set to begin in September 2026 in Brazil, Indonesia, Singapore and Thailand, before expanding more widely. Google’s developer documentation says verified developers will need to complete identity checks and, where relevant, provide additional business details such as a D-U-N-S number for organisations. The company also says non-compliance may lead to apps being blocked from installation on certified devices in the affected regions. For developers, that means the familiar Android workflow of building an app and sharing it directly could increasingly depend on passing through Google’s registration process first.

That prospect has triggered concern among open-source and privacy-focused communities. The Keep Android Open campaign says the policy could centralise control over who can distribute Android software and make it harder for independent developers, volunteers and pseudonymous contributors to reach users. The campaign, which says it has been signed by more than 60 organisations including the Electronic Frontier Foundation, F-Droid, Brave and the Tor Project, argues that identity-based gatekeeping is more likely to discourage legitimate software distribution than to stop determined attackers.

Google, by contrast, presents the policy as a straightforward security measure. Its FAQ says verification creates accountability and helps deter the spread of harmful apps. Yet critics point out that Android already uses malware-scanning tools such as Play Protect, and they question whether tying app installation to government identification materially improves safety for ordinary users. The dispute is therefore not only about security, but also about who controls access to software on devices people already own.

Disclaimer: This content is intended for informational purposes only. Readers are advised to exercise their own judgement, conduct due diligence, or consult a qualified expert before acting on any information provided.