Android will take a key turn to sideloading: Apps can only be installed on certified devices if their creator has verified their identity. The measure, which applies to both installations from alternative stores and direct APK downloads, seeks to eliminate the anonymity that facilitates the distribution of malware and scams.
Google insists it is not closing the door to alternative sources: sideloading is still allowed, but with an identity prerequisite. The company justifies the change with internal data: there are more than 50 times more malware from Internet sources that on Google Play, and its current barriers already prevented the publication of 2,3 million malicious apps in the official store in 2024.
What's changing for sideloading on Android?

The change will affect certified Android devices (those that have Google services and Play Protect). In them, any app that you try to install —also by side loading— must be registered by a verified developer. Excluded are builds without Google, minorities outside of China, where this requirement does not apply.
Google describes it as a “identity check at the airport”: It confirms who signs the app, but its content is not inspected. That is, it is not a security audit of the code; verification is intended to traceability and responsibility to quickly stop repeat offenders.
For those who distribute outside the Play Store, Google will create a Android Developer Console specific. There the verification and the application registration (including package names and signing keys), so that the system can authorize their installation on certified devices.
Developers already operating on Google Play probably comply with a good part of the requirements, since the Play Console requires verification since 2023. The novelty is that These rules extend to all distribution channels.
What verification will be like and who will it affect?

The process will ask each developer Full legal name, address, email, and phone number. In the case of companies or organizations, additional information will be required, such as a unique business identifier (e.g., DUNS) and verification of ownership of the official website. This data will not be made public; only Google will have access.
Google will enable a differentiated flow for students and hobby developers, tailored to your needs, with requirements less strict that the commercials and without paying the rate of 25 dollars of usual registration. However, in order for your apps to be installed on certified devices, they must go through the corresponding verification route.
The company emphasizes that the measure does not change the essence of the ecosystem: Android will remain open and developers will retain the freedom to distribute their apps directly or through third party storesThe change is that, from its deployment, the system will require verified identity of the author in all cases.
Official deployment schedule: in October of 2025 will open a early access to start the verification; in March 2026 the process will be enabled for all developers; and in September 2026 It will be mandatory in a first phase for Brazil, Indonesia, Singapore and Thailand, markets particularly hard hit by fraud. The expansion will be completed throughout 2027 globally
In addition to statistical data, Google cites institutional support In pilot countries, such as ministries and banking associations, they see the measure as a step forward in reducing convincing fake apps and financial crimes. At the same time, there is debate in the technical community about the balance between security and privacy of independent developers, who will have to link their real identity to their projects.
For users, the practical effect will be that will continue to be possible install APK from the web or alternative stores, but only if the creator is verified. For security teams, the new requirement adds traceability and makes it difficult for the same actor to reappear with another malicious app after a previous block.
The remaining photo is of an Android reinforcing its perimeter without closing any doors: same level of opening in distribution, with an identity filter ahead that promises less abusive anonymity and faster response to threats, especially in the field of side loading.