Google is about to change the rules of the Android ecosystem in a way that not many people are yet seeing clearly. Starting in September 2026, in select countries, with global rollout in 2027, any developer who wants their APK to be installable on a certified Android device will have to register their real identity in the Android Developer Console: official ID, email address, phone number. No exceptions. The official argument is reducing malware in sideloaded apps, which according to Google generate fifty times more infections than apps distributed through the Play Store. The real argument — the one worth analyzing — is considerably more complicated.

Before dismissing this as a minor technical issue, it's worth understanding what sideloading actually means in everyday practice. It's not just for advanced users installing custom ROMs. It's the channel through which millions of people access applications that Google has decided to exclude from its store for reasons that suit its business model. AdGuard, one of the most respected ad blockers in the world, isn't on the Play Store precisely because blocking ads undermines Google's revenue. The same applies to dozens of privacy tools, open-source apps, and personal projects that have no place in the official ecosystem.

The mandatory verification policy puts these developers in an uncomfortable position. AdGuard, for example, has built part of its value proposition on the ability to distribute its software independently, without revealing identity data to the platform that has direct incentives to sabotage its business. Under the new policy, that anonymity disappears. This isn't paranoia: it's a real structural tension between the verifier and the verified. AdGuard has already launched the #KeepAndroidOpen campaign along with other ecosystem players, and community pressure is growing, though there are no formal lawsuits in process yet.

I recognize these patterns in other contexts where a dominant platform introduces "security" requirements that, by design or by consequence, end up eliminating the most inconvenient competitors. There's no need to speculate much: the history of tech platforms is full of moves like this. Microsoft and the browser market in the nineties. Apple and iOS sideloading restrictions, which took years to generate a European regulatory response. Now Google and Android, the operating system that was born under the promise of being open.

What's at stake isn't just the convenience of a handful of independent developers. F-Droid, the open-source repository that serves as a community alternative to the Play Store, would effectively be blocked for users of certified devices if its contributors — many of whom are anonymous or pseudonymous by choice — don't register with real identities. Personal projects, educational tools, nonprofit apps: they all fall into the same bucket. And the twenty-five dollar developer account fee, which might seem trivial, is enough to exclude hobbyists in economies where that amount isn't negligible.

The malware argument deserves to be taken seriously, because it isn't false. Apps installed outside official stores do have considerably higher infection rates, and that causes real harm to real users. But the proposed solution has a proportionality problem. It's like responding to theft in a marketplace by building a wall that only lets in those who pay a fee and show ID, and then calling it "security" that small vendors can no longer get in. The wall does reduce some theft, sure. It also concentrates all commerce in the hands of whoever controls the gate.

This kind of move has clear historical precedents. Medieval European guilds used exactly this logic: mandatory certification as a quality mechanism that, in practice, worked to exclude outside competition and consolidate the power of established members. It wasn't pure malice; there was genuine concern about standards. But the structural result was concentration. When markets opened up and guilds lost control, innovation exploded in multiple directions. That pattern — certification as market dominance disguised as a quality standard — keeps showing up whenever a dominant platform feels pressure from competitors it can neither buy nor absorb.

The timing isn't a coincidence. Google faces antitrust pressure on multiple fronts, including the August 2024 U.S. ruling that determined it illegally maintained its search monopoly. In that context, reinforcing dominance over Android — the operating system that runs on more than eighty percent of mobile devices worldwide — has a defensive logic. If the app ecosystem becomes more centralized under Google's verification, competitors' ability to distribute alternative software shrinks, and with it the pressure on the advertising model that is the heart of the business.

The resistance that's emerging is interesting because it isn't purely technical. There are public letters from developers, there are digital rights organizations documenting the impact, and there's a growing conversation about what "open source" even means when the platform running it can decide who gets access. F-Droid and similar projects have spent years building alternative infrastructure, and that work matters more now. Emerging economies, which in many cases depend more heavily on sideloading for reasons of access and cost, have a lot to lose from this policy and probably a lot to say in the coming months.

It's still unclear how this ends. European regulatory pressure, which already forced Apple to open iOS to sideloading in the European Union, could eventually reach Google in similar territories. But that takes time, and by September 2026 the policy will already be in effect. What is clear is that the smartest response isn't just passive resistance: it's strengthening the alternatives. F-Droid needs more contributors. Ad blockers need more users who understand why their independence matters. And the conversation about what kind of Android we want — genuinely open or open only in name — needs to leave the technical circle and reach users who don't yet know this decision affects them directly.

Organizations tend to close ranks when they become profitable and when those who control them feel that openness costs them more than it gives them. Android has reached that point. The question isn't whether Google has the technical right to implement this policy — it probably does, within current legal limits. The question is whether users, developers, and regulators are going to accept "open" being redefined to mean its opposite.

Stones don't lie, but historians sometimes do.


Sources:

1. Google Android Developer Policy Center — Developer identity verification requirements (2025)

2. AdGuard Blog — #KeepAndroidOpen campaign documentation

3. F-Droid Project — Official repository and contributor guidelines (f-droid.org)

4. U.S. Department of Justice v. Google LLC — Antitrust ruling, August 2024

5. European Commission — Digital Markets Act, sideloading obligations for gatekeepers (2023-2024)