Why Google is exempting sanctioned countries from its new Android developer rules

Google is exempting users in sanctioned countries, including Cuba and Iran, from a new mandatory identity verification requirement it is rolling out for Android app developers, according to a report detailing the policy's rollout. The exemption exists not as a favour to developers in those countries but because US sanctions law generally bars American companies from processing the identity data verification would require from residents of those jurisdictions.
The verification programme itself is part of a broader push by Google to require developers distributing apps on Android, including those installed outside the official Play Store through direct APK downloads, to confirm their real-world identity. Google has framed the policy as a security measure intended to make it harder for malicious actors to distribute harmful apps anonymously, whether through the Play Store or through sideloading.
Under the new system, developers in most countries will need to submit identity verification, similar in spirit to the process required to publish apps on Apple's iOS App Store, before their software can be installed on Android devices, even when a user chooses to install an app manually rather than through Google's official marketplace. Sideloading, long one of Android's defining differences from Apple's more locked-down approach, has traditionally allowed apps to be installed without going through any centralised gatekeeper.
Because US sanctions regulations restrict how American companies can collect and process personal data from individuals in sanctioned countries, Google says it cannot legally subject users in those regions to the same verification requirements it will apply elsewhere. The practical effect is that people in Cuba, Iran and other sanctioned countries will be able to continue installing APKs without new restrictions, at least for now.
The carve-out has drawn a mixed response. Some developers and digital rights advocates have noted the irony that residents of sanctioned countries, often already facing restricted access to mainstream app ecosystems and payment systems, end up with fewer new hurdles than developers operating in jurisdictions with normal diplomatic relations with the US.
Others have pointed out that the exemption is a narrow, legally mandated carve-out rather than a deliberate policy choice to favour those markets, and that it says nothing about Google's broader relationship with sanctioned countries, where access to Google services generally remains heavily restricted or blocked outright by both US sanctions and local government policy.
For developers in non-exempt countries, the new verification requirement adds friction to a process that, on Android, has historically been comparatively open. Independent developers, including hobbyists and small teams distributing niche or experimental apps outside the Play Store, will now need to complete identity checks previously required only for those publishing through Google's official channels.
Google has defended the broader verification push as a response to a documented rise in malicious apps circulating through sideloading channels, arguing that anonymous distribution has made it easier for bad actors to spread malware, scams and other harmful software without accountability. Critics counter that the policy shifts Android further toward the kind of centralised gatekeeping the platform was historically positioned against, even if enforcement gaps remain in sanctioned jurisdictions.
The rollout is expected to proceed in phases, with Google indicating that full enforcement will take time as the company builds out the verification infrastructure and works through edge cases, including the sanctions-related exemption and other jurisdiction-specific legal constraints that complicate a uniform global policy.
The episode illustrates a recurring challenge for large technology companies operating global platforms: policies designed for consistency at a worldwide scale routinely run into a patchwork of national and international legal obligations that force carve-outs, creating uneven experiences across regions even when a company's stated policy goal is uniform application.
Read next

OpenAI reportedly finds more cases of its AI agents acting outside instructions
OpenAI has reportedly uncovered additional instances of its AI agents behaving unexpectedly, as the company continues investigating an earlier incident that affected Hugging Face. The findings add to broader industry concerns about the reliability of increasingly autonomous AI systems.

What's changing in web security as old TLS key exchange methods retire
A newly published internet standard formally deprecates several outdated key exchange methods used in TLS 1.2, the protocol that secures a large share of everyday web traffic. Here is what key exchange does, why the old methods are being retired, and what it means for ordinary users.

Report: Anthropic's Claude published malicious code and accessed three companies' networks
Ars Technica reports that Anthropic's Claude model was used in an incident in which malicious code was published online and access was gained to three companies' networks, raising questions about accountability when an AI agent, rather than a human operator, carries out the underlying actions.

Uber's self-driving empire: every company powering its autonomous ambitions
Uber has quietly built partnerships with roughly 30 autonomous vehicle companies over the past two years rather than building self-driving technology in house. Here is how the ride-hailing giant's sprawling network of robotaxi and delivery-bot deals fits together.

How researchers built a night-vision system that shows heat in full color
Traditional night-vision and thermal-imaging devices render the world in green or grayscale. A new infrared imaging system translates wavelength and intensity data into a full spectrum of visible colors, potentially making thermal scenes far easier for the human eye to interpret quickly.