15 - Sep - 2026

Google just made sideloading harder, but there’s still a way around it

For years, Android has drawn a fairly simple line around sideloading. Tell the OS you trust the source, accept the warning, and you can install an APK that never touched Google Play. That freedom is one of the biggest differences between Android and the iPhone.

Starting September 2026, Google begins changing that arrangement. The first phase begins in Brazil, Indonesia, Singapore, and Thailand, then expands globally in 2027. Google hasn’t announced a specific US date, but the worldwide rollout will eventually cover American Android devices too. The company insists sideloading isn’t going away, and technically, that’s true. You can still install whatever you want.

You might just have to convince Android you really mean it first.

Google is putting an ID checkpoint in front of Android apps

Your APK now comes with a name tag

The big change is developer verification. On certified Android devices, Google wants apps tied to a verified developer before they can be installed. The rule applies to mainstream certified Android hardware, while AOSP builds and non-certified devices are exempt.

The first enforcement wave covers apps installed through participating stores, including Google Play, Samsung’s Galaxy Store, Xiaomi GetApps, OPPO App Market, HONOR App Market, Vivo’s V-Appstore, and Transsion’s Palm Store. In 2027, Google plans to expand verification globally across all installation sources, including APKs downloaded directly from websites.

Google describes the process as an identity check rather than an app review. It isn’t inspecting an APK and declaring its contents safe; instead, it’s linking the app’s package and signing identity to the person or organization distributing it.

Developers who distribute outside Google Play can sign up for a full-distribution Android Developer Console account for $25 and complete identity verification. Developers already publishing through Google Play handle the process through Play Console. Google also offers a free limited-distribution account aimed at students and hobbyists, which skips the government-ID requirement but caps distribution at 20 devices.

This doesn’t make Google the only Android app store. It does, however, put Google in the role of identity authority beneath much of Android software distribution. A developer can skip the Play Store entirely and publish through another store or directly from a website, but getting an app onto a certified Android phone without extra friction will increasingly require registering with Google first.

Sideloading survives, but Google makes you prove you mean it

The 24-hour wait isn’t quite what it sounds like

Google has left an escape hatch for anyone who still wants to install software from an unverified developer. It’s called the advanced flow, and the first version started rolling out in August.

To use it, you’ll need to:

  • Enable Developer Options on your Android device.
  • Scroll to the Apps section, open Apps from unverified developers, then turn on Allow apps from unverified developers.
  • Confirm through Android’s warnings that nobody is coaching you through the process.
  • Restart your phone when prompted.
  • Wait through the one-time 24-hour security delay.
  • Authenticate again with your PIN, password, or biometrics.
  • Choose whether to allow apps from unverified developers for seven days or indefinitely.

You don’t wait 24 hours every time you download some obscure GitHub project. Once you complete the advanced flow and enable it indefinitely, you can install future apps from unverified developers after another warning and an Install anyway prompt. You can even turn Developer Options back off afterward without losing the setting.

According to Google, the extra friction targets coercion scams. The company says its analysis found more than 90 times as much malware coming from sideloaded sources as from Google Play, and the advanced flow is designed to make those scams harder to carry out in real time. A scammer posing as a bank employee or tech-support agent can keep someone on the phone and walk them through disabling security protections. Restarting the phone can break that interaction, while a 24-hour delay takes away the urgency those scams often depend on.

There’s also a way around the waiting period entirely. ADB installs remain exempt, so anyone comfortable connecting a phone to a computer and using Android Debug Bridge can keep installing unregistered apps without going through the advanced flow.

For most people, this shouldn’t change much. Apps from registered developers will keep installing normally. The extra friction only shows up when you deliberately install software from developers who haven’t registered with Google.

Android is opening one door while narrowing another

The timing couldn’t be much stranger

A smartphone displaying the Google Play store interface for downloading the Aptoide Games third-party app store.
Google Play store third-party app distribution featuring Aptoide Games on an Android smartphone.

This change lands in the middle of one of the biggest shake-ups Google Play has seen in years.

After Google’s long antitrust battle with Epic Games, the Play Store in the US is now required to accommodate competing app stores. Third-party app stores can now be distributed through Google Play, and Aptoide became the first rival storefront distributed directly through Google Play in August.

Android software distribution is opening up commercially as a result. Google Play has to leave more room for competing stores, alternative billing systems have gained ground, and users have more options for where they get their apps. At the same time, Google is building a new identity checkpoint into Android itself, underneath all of those choices.

A reasonable security argument for it is that requiring malicious developers to attach a persistent identity to their apps could make it harder to disappear after one malware campaign and immediately return under a new name. The advanced flow also means experienced users still get the final say over what they install.

Google’s sideloading limits have already drawn criticism as an anti-consumer move, and the open-source community’s pushback is easy to understand, too. F-Droid and other free-software groups have criticized the verification system because independent developers who want smooth distribution on certified Android devices are being nudged toward registration with a single company. Developers who rely on anonymity have an even clearer reason to object.

Google softened the most restrictive version of its original plan by adding the advanced flow, but the broader direction hasn’t changed. Certified Android devices are moving toward a world where app distribution can come from many places, while developer identity increasingly runs through Google.

Android stays open, but the default just changed

Google isn’t killing sideloading, but it is redefining what Android treats as the normal, trusted path for installing software.

You can still install an unverified APK if you really want to, but Google now wants that decision to be deliberate, not routine. For most users, the extra friction may be a fair security tradeoff. For people who’ve always valued Android because it made installing software outside any company’s approval relatively easy, though, the platform has become a little less open.

Leave a Reply

Your email address will not be published. Required fields are marked *