Google will begin enforcing Android developer verification on September 30, 2026, for installations from seven participating app stores in Brazil, Indonesia, Singapore and Thailand. Direct sideloading of Android package (APK) files and stores outside that list are not covered by this first phase.

The checks connect a developer's verified identity and signing keys with registered app package names. They do not turn every APK into store-reviewed software, and Google has kept separate routes for advanced users, developers and small private projects.

An older adult holds a smartphone displaying an app screen (illustrative image)

Seven stores form the first enforcement point

The first list comprises Google Play, HONOR App Market, OPPO App Market, Samsung Galaxy Store, Transsion Palm Store, vivo V-Appstore and Xiaomi GetApps. An app whose developer has not completed identity verification and package registration will be unavailable for a new installation through those stores on affected certified devices.

Google limits September enforcement to certified Android phones and tablets in the four named countries and says the requirement applies to certified devices running Android 7 or later. The company plans to extend verification globally in 2027 and later bring all third-party Android app stores into scope, but it has not set out a country-by-country calendar.

Timeline showing Android developer verification, the first four countries and routes for installing unregistered apps

The APK format is not the deciding factor

Android's system links a real-world individual or organization to package names and app-signing keys. A registered app may still be distributed through a developer's website or an independent store, so the file extension or download location alone does not determine whether an ordinary installation succeeds.

Verification also has a narrower meaning than a security review. Google says it confirms who the developer is but does not review the app's content or where it came from, leaving malware detection, permission checks and distribution policies as separate controls.

A smartphone screen displays a white padlock symbol (illustrative image)

Advanced flow preserves a route for unregistered apps

Google's advanced flow requires a user to enable developer options, complete a check against scam coaching, restart the phone and return after a one-day wait. Biometric authentication or the device personal identification number then confirms the change, after which access can remain enabled for seven days or indefinitely.

An installation still shows an unverified-developer warning and an “Install Anyway” choice. Google also says an unregistered app can be installed or updated only while the advanced flow is enabled or through Android Debug Bridge (ADB), so turning the flow off can stop later updates.

ADB installations do not require developer registration and are not subject to the one-day wait. Google describes ADB as the standard route for building, testing and installing modified or otherwise unregistered apps on a developer's own device.

A person confirms an action with biometric authentication on a smartphone (illustrative image)

Limited distribution gives small projects another route

Google's limited-distribution account is free and permits registered apps to be shared with up to 20 devices whose users explicitly authorize them. A quick-response (QR) code or link starts the authorization handshake, making this account suitable for a class project, a hobby app or a closed group rather than a public release.

The account does not require a government-issued identity document, but it is not anonymous. Google requires a Google Account with two-step verification, a payments profile holding the legal name and address, and a contact email address.

A person operates a smartphone at close range (illustrative image)

How this plays out outside Taiwan

The September date creates two different operating periods across English-speaking markets. Singapore enters the first phase on September 30, while the United States, United Kingdom and Australia do not appear in Google's four-country list. Google's documents therefore provide no basis for treating September 30 as a shutdown date for ordinary APK installation in those three markets.

Singapore's first-phase rule is also channel-specific. Google says the September checks apply only to the seven named participating stores, while direct sideloading and installations through other stores remain unchanged during the initial rollout. On a certified Singapore phone or tablet running Android 7 or later, an unregistered package offered through a participating store can be blocked even though the same package obtained directly from its developer remains outside this phase. That difference follows the installation channel, not the APK suffix.

For app publishers, Google's wording places the first trigger at the user's market and installation route rather than the developer's home country. A developer based in the United States, United Kingdom or Australia can still reach a Singapore user through one of the seven stores, so the developer's foreign address does not remove that Singapore installation from the announced scope. A release confined to direct downloads or an unlisted store is treated differently in September, although Google says the global 2027 expansion will cover all apps distributed to certified Android devices.

The United States, United Kingdom and Australia are in the preparation period described by Google's global plan. APPI News could not find an exact 2027 activation date for any of those three countries in the official guidance available at the time of writing. Developers serving those markets can register before enforcement: the Android Developer Console is already available for apps distributed only outside Google Play, while an existing Google Play Console account handles apps distributed both on and off Google Play.

Cost and acceptable documents require separate checks. Google lists a one-time US$25 fee for full distribution, accepts specified credit or debit cards, excludes prepaid cards and says card availability can vary by location. The public page lists Discover for the United States only and Visa Electron outside the United States only. It does not give a local-currency or tax total for Singapore, the United Kingdom or Australia, so the amount presented in the console is the verifiable figure before payment.

Full-distribution identity documents depend on geographic location; Google's public examples of passports, state identification and Internal Revenue Service records are explicitly examples for United States applicants. They should not be treated as a document list for Singapore, the United Kingdom or Australia. Individual accounts require a government-issued photo identity document and proof of address, while organizations also need a Dun & Bradstreet D-U-N-S number and a website verified through Google Search Console. Google directs applicants to a location-specific list of acceptable documents.

Singapore already has another Android installation control, separate from the new developer-identity system. The Cyber Security Agency of Singapore says enhanced Google Play Protect blocks some apps installed from browsers, messaging apps or file managers when they request four permissions often abused in financial fraud. Those permissions cover reading and receiving Short Message Service (SMS) messages, accessibility services and notification listening. An installation blocked by that security feature is not evidence that the developer-verification rule caused the block.

That distinction also matters for ADB. Singapore's cyber agency reported that enhanced fraud protection had prevented more than 2.49 million potentially malicious installations across 550,000 devices by June 2025, and that criminals had misused ADB to take remote control of victims' phones. ADB remaining available under Google's verification policy therefore describes a development capability, not a finding that an installed file is safe.

The United Kingdom and Australia publish security advice rather than country-specific developer-verification deadlines. The UK National Cyber Security Centre advises obtaining delivery apps from official app stores when warning about malware sent through parcel-text scams. The Australian Signals Directorate advises against applications from little-known third-party download sites and points users to the official store for their device. The cited pages are risk-reduction recommendations; neither announces a legal ban on all sideloading or changes Google's published 2027 timetable.

Device status can be checked without guessing from the phone brand. Google Play Help directs users to open the Play Store, select the profile icon, then Settings and About to see the Play Protect certification status. This certification is separate from the Play Protect malware scanner, so disabling the scanner does not turn a certified device into an uncertified one or remove the developer check.

A person holds a smartphone while using a mobile app (illustrative image)

Full distribution ties identity to package and signing key

A developer registering an app outside Google Play enters its package name, adds the SHA-256 certificate fingerprint for the signing key and uploads a signed APK to prove control of an existing package. The console marks the package as registered after review and sends an email when that status changes.

Duplicate package names can require more than proof of a signing key. Google's current allocation rules give priority to a key associated with more than 50 percent of known installs; if no key has a majority, a key with at least 50 installs can qualify. When no key reaches that threshold, registration is first come, first served, while an ineligible developer can request permission through an appeal-like review supported by ownership evidence and a legitimate reason.

A smartphone lies beside electronic components (illustrative image)

Frequently asked questions

Will every Android APK be blocked on September 30, 2026?
No. The first phase covers installations from seven participating stores on certified phones and tablets in Brazil, Indonesia, Singapore and Thailand; direct sideloading and other stores remain outside that phase.

Can an app from an unverified developer still be installed?
Yes. The advanced flow permits installation after its one-time setup and one-day wait, while ADB remains a separate route for development and testing without that wait.

Does a verified developer status mean an APK is safe?
No. Google says verification confirms the developer's identity and package ownership but does not review the app's content or source, so malware and permission controls remain separate.

When will the checks start in the United States, United Kingdom or Australia?
Google says the global expansion begins in 2027 but has not published an exact date for any of those markets. APPI News could not verify a more specific official schedule at the time of writing.

A smartphone connected to a charging cable rests on a desk (illustrative image)