- Open Letter: Over 37 organizations led by the EFF and F-Droid signed an open letter demanding Google rescind its mandatory Android developer registration policy.
- Policy Details: From September 2026, developers distributing apps outside the Play Store must register with Google or have their apps blocked on certified Android devices.
- Key Concerns: Centralized registration would give Google the power to disable any app across its entire ecosystem, threatening free speech, competition, and digital sovereignty.
- Regulatory Context: The letter was copied to competition regulators worldwide as Google faces antitrust scrutiny from the EU and the U.S. Department of Justice.
Starting in September 2026, any developer distributing apps outside Google’s Play Store who has not registered their identity with Google will find their software blocked from running on virtually every Android phone on the planet.
More than 37 civil society organizations, led by the Electronic Frontier Foundation, Article 19, and F-Droid, are demanding Google withdraw the policy before that deadline arrives. The open letter opposing mandatory developer registration, addressed to Sundar Pichai along with co-founders Sergey Brin and Larry Page, calls the requirement a fundamental threat to Android’s open ecosystem.
The letter is also CC’d to regulatory authorities and policymakers around the world, signaling the coalition’s intent to involve competition regulators directly in the dispute. The signatories state their position plainly:
“We, the undersigned organizations representing civil society, nonprofit institutions, and technology companies, write to express our strong opposition to Google’s announced policy requiring all Android app developers to register centrally with Google themselves in order to distribute applications outside of the Google Play Store, set to take effect worldwide in the coming months.”
Keep Android Open coalition signatories (via Keep Android Open)
Spanning civil liberties organizations, free software groups, and commercial software companies across multiple countries, this coalition extends well beyond the open-source community. By routing the letter directly to competition regulators, the signatories convert a developer grievance into a formal record for antitrust review. This frames the policy dispute as evidence of platform control rather than a product disagreement with Google.
According to Google’s developer verification requirements announced in August 2025, the program creates “crucial accountability,” making it much harder for malicious actors to distribute another harmful app after one has been removed. The requirement extends to third-party app stores and enterprise distribution channels, including developers’ own websites and direct device-to-device transfers.
Registration Requirements and Timeline
The registration process requires identity verification, including government-issued identification, agreement to Google’s terms of service, and a $25 one-time fee. Google has required Play Store developers to be verified since 2023, so the change mainly affects developers using alternative channels such as Amazon Appstore, Samsung Galaxy Store, F-Droid, and direct sideloading.
The scheme entered early preview in November 2025 and opens to all developers in March 2026. It becomes mandatory from September 2026, when coverage extends to Brazil, Indonesia, Singapore, Thailand. Developers who have not verified their identities by that date will have their apps blocked from installation on certified Android devices.
The policy does not affect AOSP builds such as LineageOS or GrapheneOS.
The seven-month window between March enrollment and September enforcement compresses what would ordinarily be a multi-year transition for projects like F-Droid, which distributes hundreds of apps from developers who may be anonymous by design. The carve-out for AOSP builds confirms the policy targets the mainstream certified Android market, covering 95% of non-China devices where Google’s certification applies, rather than the technical fringe of the ecosystem.
Why Civil Society Objects
Those implementation details are precisely what the coalition finds deeply alarming. F-Droid raises a pointed technical objection: installing or launching any app on a certified device will phone home to Google to verify the developer before the app is permitted to run. F-Droid reports that 95% of Android devices outside China are Android Certified, meaning real-time verification would reach virtually the entire global Android user base outside that market.
Civil society’s objections center on three claims: that the security rationale is unsubstantiated, that centralized registration gives Google near-total ecosystem control, and that the policy contradicts Android’s historically open character.
On the security argument, the open letter points to Android’s existing mechanisms including OS-level sandboxing, permission systems, sideloading warnings, and Google Play Protect as sufficient protection. The coalition argues no evidence has been presented that these safeguards are insufficient to protect Android users, as they have throughout Android’s seventeen-year existence without requiring central developer identity verification.
Beyond security, the structural concern is more far-reaching. Centralizing registration with Google would give the company the ability to disable any app across the entire ecosystem, for any reason, at any time, concentrating control over hundreds of governments, millions of businesses, and billions of citizens. The coalition characterizes this as incompatible with free speech, competition, and digital sovereignty.
That challenge carries particular force because it comes from organizations with direct technical experience operating Android app distribution at scale, not from critics unfamiliar with the threat environment Google cites.
A Broad Coalition
The named signatories include Article 19, the Electronic Frontier Foundation, the Free Software Foundation, F-Droid, Fastmail, and Vivaldi, alongside the FSFE and Software Freedom Conservancy. F-Droid, which distributes hundreds of applications entirely outside the Play Store, published its own statement:
“The Android Developer Verification program is a grievous breach of trust with the free and open-source community that helped propel Android to the dominant position it holds today in the mobile computing world.”
F-Droid
The question of whether Google will respond to that breach-of-trust argument is one the coalition has been pressing privately for months.
Marc Prud’hommeaux of the Keep Android Open campaign told The Verge that months of outreach to Google had gone unanswered, and that the implications of the company’s threatened action for competition and digital sovereignty were dire.
Google offered vague assurances that an “advanced flow” might eventually allow experienced users to install unverified software. However, F-Droid’s open letter opposing verification reports no such alternative installation path will be confirmed before the September 2026 lockdown, leaving developers with no transition route.
The shift from months of private outreach to a coordinated public letter, copied directly to regulators, indicates the coalition has concluded Google will not move voluntarily. For organizations like F-Droid and the EFF, a public record before competition authorities creates pressure that private correspondence does not: regulators reviewing future antitrust proceedings will have documented evidence of how the policy was contested before enforcement began.
Regulatory Pressure Mounts
The open letter arrives as Google faces intensifying antitrust scrutiny on multiple fronts. Signatories cite the European Commission, the U.S. Department of Justice, and competition authorities in multiple jurisdictions as already scrutinizing dominant platform behavior. As we previously reported, the Keep Android Open campaign had already forced Google to ease sideloading restrictions in November 2025, marking a second confrontation between Google and the same coalition within three months.
Compounding that pressure, the new requirement arrives alongside a Play Store antitrust ruling that compelled Google to allow alternative payments in the United States. The company also reached a secret settlement with Epic to resolve the associated antitrust case.
Court-ordered openness on payments and Google’s simultaneous move to centralize developer identity across the broader Android ecosystem creates a direct contradiction that competition regulators are positioned to exploit. Where sideloading restrictions limited access to distribution channels, centralized identity verification enables retrospective enforcement against any developer, anywhere in the ecosystem. That represents a qualitatively different form of control that the November 2025 reversal did not address.
The coalition’s central demand is that Google rescind the policy and engage with civil society before introducing any alternative security measures. Registration opens next month; enforcement becomes mandatory in September 2026. For developers, open-source projects, and enterprise teams who distribute software outside the Play Store, that deadline carries direct consequences.
Apps that have not cleared Google’s identity process will stop launching on the devices of hundreds of millions of users worldwide.
As the coalition’s letter concludes: Android’s strength has historically come from its openness, and Google must work to restore its role as a faithful steward of that trust.


