Google is locking down Android. By September 2026, sideloading apps will require developer registration, payment, and government ID handed to Google.
Google frames it as protecting users from malicious apps. But Android already has Google Play Protect scanning, runtime permissions, sandboxing, and user warnings for sideloaded apps. This isn’t security — it’s control. Real security doesn’t require developers to hand over government IDs and signing keys to a corporation.
If you’ve ever installed an app from outside the Play Store — an ad blocker, a custom launcher, an app from F-Droid, a beta version, an enterprise tool — yes. After September 2026, those apps won’t install unless the developer has registered with Google.
In November 2025, Google vaguely mentioned a possible “advanced flow” for experienced users. No details, no commitments, no timeline. Even if implemented, requiring users to jump through extra hoops to exercise basic device ownership rights is a restriction, not a solution.
Yes. The DMA team is actively enforcing against Big Tech — they’ve already opened proceedings against Apple, Google, and Meta. Volume of complaints directly influences enforcement priority. Your email gets logged and counted. The DMA has real teeth: fines up to 10% of global turnover.
Absolutely. Share on social media. If you’re a developer, refuse the early access program and distribute via F-Droid or direct APK. If you’re in a country with competition authorities, file a complaint there too. EU enforcement sets global precedent.
For users: Support custom ROMs (LineageOS, GrapheneOS, CalyxOS), use F-Droid for open-source apps, and make your voice heard before September 2026.
For developers: Distribute via F-Droid, offer direct APK downloads, refuse the early access program, and publicly oppose the policy.
For everyone: Email regulators, contact MEPs, share information, and support organizations fighting for digital rights.
Date: February 24, 2026
To: Sundar Pichai, Chief Executive Officer, Google
To: Sergey Brin, Founder and Board Member, Google
To: Larry Page, Founder and Board Member, Google
To: Vijaya Kaza, General Manager for App & Ecosystem Trust, Google
CC: Regulatory authorities, policymakers, and the Android developer community
Re: Mandatory Developer Registration for Android App Distribution
We, the undersigned organizations representing civil society, nonprofit institutions, and technology companies, write to express our strong opposition to Google’s announced policy requiring al[…]
While we do recognize the importance of platform security and user safety, the Android platform already includes multiple security mechanisms that do not require central registration. Forcibly i[…]
Our Concerns
- Gatekeeping Beyond Google’s Own Store
Android has historically been characterized as an open platform where users and developers can operate independently of Google’s services. The proposed developer registration policy fundamenta[…]
This extends Google’s gatekeeping authority beyond its own marketplace into distribution channels where it has no legitimate operational role. Developers who choose not to use Google’s servi[…]
- Barriers to Entry and Innovation
Mandatory registration creates friction and barriers to entry, particularly for:
- Individual developers and small teams with limited resources
- Open-source projects that rely on volunteer contributors
- Developers in regions with limited access to Google’s registration infrastructure
- Privacy-focused developers who avoid surveillance ecosystems
- Emergency response and humanitarian organizations requiring rapid deployment
- Activists working on internet freedom in countries that unjustly criminalize that work
- Developers in countries or regions where Google cannot allow them to sign up due to sanctions
- Researchers and academics developing experimental applications
- Internal enterprise and government applications never intended for broad public distribution Every additional bureaucratic hurdle reduces diversity in the software ecosystem and concentrates power in the hands of large established players who can more easily absorb such compliance costs[…]
- Privacy and Surveillance Concerns
Requiring registration with Google creates a comprehensive database of all Android developers, regardless of whether or not they use Google’s services. This raises serious questions about:
- What personal information developers must provide
- How this information will be stored, secured, and used
- Whether this data could be subject to government requests or legal processes
- To what extent developer activity is tracked across the ecosystem
- What this means for developers working on privacy-preserving or politically sensitive applications Developers should have the right to create and distribute software without submitting to unnecessary surveillance or scrutiny.
- Arbitrary Enforcement and Account Termination Risks
Google’s existing app review processes have been criticized for opaque decision-making, inconsistent enforcement, and limited appeal mechanisms. Extending this system to all Android certified […]
- Arbitrary rejection or suspension without clear justification
- Automated systems making consequential decisions with insufficient human oversight
- Developers losing their ability to distribute apps across all channels due to a single un-reviewable corporate decision
- Political or competitive considerations influencing registration approvals
- Disproportionate impact on marginalized communities and controversial but legal applications A single point of failure controlled by one corporation is antithetical to a healthy, competitive software ecosystem.
- Anticompetitive Implications
This requirement allows Google to collect intelligence on all Android development activity, including:
- Which apps are being developed and by whom
- Alternative distribution strategies and business models
- Competitive threats to Google’s own services
- Market trends and user preferences outside of Google’s ecosystem This information asymmetry provides Google with significant competitive advantages, allows it to preempt, copy, and undermine competing products and services, and may open many questions about a[…]
- Regulatory concerns
Regulatory authorities worldwide, including the European Commission, the U.S. Department of Justice, and competition authorities in multiple jurisdictions, have increasingly scrutinized dominan[…]
We urge Google to find alternative ways to comply with regulatory obligations by promoting models that respect Android’s open nature without increasing gatekeeper control over the platform.
Existing Measures Are Sufficient
The Android platform already includes multiple security mechanisms that do not require central registration:
- Operating system-level security features, application sandboxing, and permission systems
- User warnings for applications that are directly installed (or “sideloaded”)
- Google Play Protect (which users can choose to enable or disable)
- Developer signing certificates that establish software provenance
No evidence has been presented that these safeguards are insufficient to continue to protect Android users as they have for the entire seventeen years of Android’s existence. If Google’s co[…]
Our Petition
We call upon Google to:
- Immediately rescind the mandatory developer registration requirement for third-party distribution.
- Engage in transparent dialogue with civil society, developers, and regulators about Android security improvements that respect openness and competition.
- Commit to platform neutrality by ensuring that Android remains a genuinely open platform where Google’s role as platform provider does not conflict with its commercial interests.
Over the years, Android has evolved into a critical piece of technological infrastructure that serves hundreds of governments, millions of businesses, and billions of citizens around the world.[…]
We implore Google to reverse course, end the developer verification program, and to begin working collaboratively with the broader community to advance security objectives without sacrificing t[…]
Signatories 71 organizations from 23 countries
Source; keepandroidopen.com, keepandroidopen.org