Google’s new Android sideloading rules add friction in a bid to curb scams

Google is introducing a more rigorous developer verification process for sideloaded apps, aiming to reduce malware while sparking debate over the balance between safety and user freedom.

Google is tightening the rules around Android sideloading, adding a verification layer that will make it harder to install apps from developers the system does not recognise. According to Google’s own support material, the company is introducing developer verification to help reduce malware and scams, while still leaving a path for users who want to override the block through a new advanced flow. The change matters because sideloading has long been one of Android’s defining freedoms, especially for users who rely on apps that are not available in their country or through the Play Store.

The new process is notably more cumbersome than Android’s current “unknown sources” prompt. Google says users who want to install an app from an unverified developer will need to enable developer options, switch on an allow-unverified-packages setting, confirm the change with a PIN or password, restart the phone, and then wait through a 24-hour delay before completing installation. 9to5Google reported that the first version of this advanced flow is now rolling out, with the wait period and restart built in.

Google’s argument is that this friction is deliberate. The company says scammers often pressure victims into acting quickly, and that a forced pause can interrupt social-engineering attempts before a malicious app is installed. T3 reported that the system is also designed to remember experienced users who regularly sideload, which should reduce repeated disruption, while Android Authority noted that ADB installs remain outside the new verification requirement.

The policy will begin on September 30, 2026, in Brazil, Indonesia, Singapore and Thailand, where Google says scams have been a particular problem. Google’s support pages say verified developers will need to register apps for certified Android devices, and that participating stores including Google Play, Samsung’s Galaxy Store, Oppo’s App Market and HONOR App Market are part of the initial rollout. Google plans to broaden enforcement globally in 2027.

For users, the shift is a trade-off between convenience and safety. Android still allows sideloading, and people who trust APK repositories or open-source stores will not lose that option entirely, but the process is becoming less immediate and less casual. As Google moves towards broader enforcement, the practical question is whether the extra safeguards will curb fraud without making one of Android’s most distinctive advantages feel hidden behind too many warnings.

Disclaimer: This content is intended for informational purposes only. Readers are advised to exercise their own judgement, conduct due diligence, or consult a qualified expert before acting on any information provided.