Seven episodes into the second season of Breaking Bad, Walt tells Jesse they are not charging enough for the product. Jesse pushes back. Walt does not raise his voice, because he is a teacher and this is a lesson.

Corner the market, then raise the price. Simple economics.

Jesse takes it away and translates it for his dealers as territory, layered like nachos, one neighbourhood stacked on the next until the whole city is theirs.1

The line has stayed with me for years, and not because it is menacing. It is not villain dialogue at all. It is an accurate description of how a market is taken, delivered by a man who has worked out that whether a strategy is decent has no bearing on whether it works. There is no bragging in it either, which is what makes it land. He is just doing the arithmetic out loud in front of somebody who has not caught up yet.

Google has been running that play on Android for about fifteen years. This September it starts on the second half of the sentence.

The years of giving it away

Android arrived free, and the openness was not marketing. AOSP was a real, complete, buildable operating system that anybody could take and ship. Manufacturers did not pay a licence fee. Carriers could brand it. Anyone could fork it, and several people did.

Set that against what it was competing with. Microsoft wanted per-device licensing for Windows Phone. BlackBerry ran a closed stack on its own hardware with its own services underneath. Both were asking phone makers to pay money and cede control to a company that also wanted to sell phones. Google was handing over something comparable for nothing, and the thing it handed over was good.

That was not a close fight. Android now runs on roughly seven in ten of the world's mobile devices, depending on the month you check. Windows Phone is a decade dead. BlackBerry makes security software.

The market got cornered somewhere around 2013, and everything that has happened since belongs to the second half of Walt's sentence.

Then the interesting parts moved out

What happened next is easy to miss because nothing was confiscated. AOSP is still there. You can still clone it, build it, and boot it on hardware today.

What changed is where the useful things live. Location services, push messaging, maps, identity and sign-in, in-app billing, the anti-abuse and attestation machinery: over a decade these moved out of the open platform and into Google Play Services, which is proprietary, ships through the Play Store, and updates on Google's schedule rather than the manufacturer's. Ron Amadeo laid the pattern out in detail for Ars Technica in 2013, back when it was still an argument rather than a description.2

The result is that AOSP and Android became different products wearing the same name. You can build a phone from AOSP without Google. You cannot build one that runs the apps people already have on their current phone, because those apps were written against Google's libraries and not against the open ones. Amazon spent real money learning this with the Fire Phone.

I find the mechanism genuinely elegant, in the way you can admire a lock that just closed on you. Nothing was ever taken out of the open platform. The good parts simply stopped arriving there.

The price

On 30 September 2026, Google begins requiring developer verification for apps installed on certified Android devices, starting in Brazil, Indonesia, Singapore and Thailand, and going global through 2027.3

The part that matters is the scope. This is not a Play Store policy. To put an APK on your own website and have it install on an ordinary phone, you register with Google, provide legal identity including a government ID and an address, and register your app signing keys in a Google console. A new system service called Android Developer Verifier is rolling out to devices to enforce it. Apps from unverified developers are blocked.

Distribution outside the Play Store still exists, and it now runs through a registry that Google operates.

The concessions are real, and I am going to state them properly

Plenty of the commentary on this is overheated, and it will not survive contact with anyone who has read the documentation, so here is what Google has actually conceded.

Installing over ADB is exempt, with no verification and no waiting period, so local development, prototypes and test builds are untouched. In March, Matthew Forsythe, a director of product management on Android App Safety, announced two further accommodations.4 There is a free limited-distribution account for students and hobbyists, with no government ID and no registration fee, that shares an app with up to 20 devices. And there is an "advanced flow" for power users who want to install something unverified anyway, which requires enabling developer mode, restarting the phone, authenticating biometrically, and then waiting a day.

So sideloading is not being switched off, and anybody telling you it is has not done the reading. What is being switched off is anonymous distribution at any meaningful scale. Twenty manually authorised devices is a hobby, and it is not an app store.

The security argument is not a lie

This is the part I want to be careful about, because the cynical reading is the fun one and it is also incomplete.

It is worth reading Google's reasoning in Google's own words rather than in anybody's summary of it, mine included. The policy was announced in August 2025 by Suzanne Frey, a vice president for product on Android, and her stated problem is anonymity rather than sideloading as such:5

malicious actors hide behind anonymity to harm users by impersonating developers and using their brand image to create convincing fake apps

The number offered alongside it is that Google's "recent analysis" found "over 50 times more malware from internet-sideloaded sources than on apps available through Google Play." The March follow-up adds the broader framing, citing a 2025 Global Anti-Scam Alliance figure that 57% of surveyed adults had been hit by a scam in the previous year, for 442 billion dollars of consumer losses worldwide.

Take those at face value for a moment. Malware distributed as APKs to less technical users is a real and well documented problem, and it is worst in exactly the countries Google is starting with. Somebody who installs a banking trojan from a link in a message is not helped by a principled argument about software freedom. The reason is not invented, and a policy that reduces that harm is doing something worth doing.

I can also construct the meeting where this was decided, and it does not contain any villains. It contains a slide with fraud losses on it, a regulator somewhere asking why that number is not coming down, a support organisation drowning in impersonation reports, and an engineering lead who has been given a target and a date. Anonymity is the variable in that model you can actually move. Anyone who has worked to a number and a deadline knows exactly how that reasoning goes, and I am not confident I would have argued differently sitting in that chair with that accountability.

That is the uncomfortable part, and it is why outrage on its own is a weak response. The people who move this will be the ones who turn up with a better mechanism rather than the ones who turn up angry.

What is worth noticing is which of the available mechanisms got chosen. A real problem was solved in the one way that also makes Google the registrar for everyone who ships software to a phone, in a market Google spent fifteen years cornering by promising the opposite. Both of those are true at the same time. Insisting on only the first makes you naive, and insisting on only the second means you lose the argument with everyone who has looked at the malware numbers.

People are already fighting this, and you can join them today

This is the part most write-ups skip, so here is the actual list.

F-Droid and the Electronic Frontier Foundation published an open letter to Alphabet in February asking for the policy to be withdrawn. It has since become the Keep Android Open campaign, which as of this summer carries 71 organisations across 23 countries and over 100,000 signatures. The signatories are not a fringe: the EFF, the Free Software Foundation and FSF Europe, the Tor Project, Article 19, Proton, Vivaldi and Fastmail among them.

Signing takes a minute. It is the lowest-effort item on this list and the number is the entire point, because a regulator counts signatures and a company counts press cycles.

The EFF is worth more than a signature, though. They are one of a very small number of organisations that show up with lawyers when this sort of thing goes to court, and they are membership funded. If you have ever benefited from a piece of software you were not supposed to be allowed to run, they are part of the reason you could.

How to actually petition the EU about it

I live in the EU, which means I have three mechanisms available that most commentary never mentions by name. They differ enormously in effort and in odds, and it is worth knowing which is which.

The Digital Markets Act complaint route. Google is a designated gatekeeper under the DMA, and the Commission runs a citizens and whistleblower portal specifically so that people can report gatekeeper conduct they think breaches it. The Keep Android Open coalition is arguing this falls under Articles 5 and 6, as a gatekeeper using its position to control which software runs on hardware you own. This is the highest-leverage option, because the DMA already has teeth and the Commission has already used them on Android this year.

Petitioning the Parliament. Any EU citizen or resident can submit a petition to the European Parliament on a matter within EU competence. It goes to the Petitions Committee, which can request a Commission opinion and put it in front of MEPs. It is slower and quieter than the DMA route, and it creates a public record with your name attached to it, which is sometimes exactly the point.

The European Citizens' Initiative. The ECI requires one million signatures across at least seven member states before the Commission is obliged to respond formally. I am including it for completeness rather than as a recommendation. The bar is enormous and it is the wrong instrument for a deadline in September.

If you only do one thing, make it the DMA portal. It is the mechanism with an actual regulator behind it and an actual timetable.

The escape hatches, and what they really cost

The technically minded answer is to leave. There are real options and I want to describe them honestly rather than as a slogan.

GrapheneOS is the serious one. It is a hardened Android with a genuinely good security record, and it is the version of this idea that a security professional will actually recommend. It runs on Pixel hardware and effectively nothing else, which means escaping Google's software requires buying Google's hardware. LineageOS covers a far wider range of devices and is the closest thing to a general answer. postmarketOS and the Linux phones are a different proposition again, real Linux on a handset, and they are a hobby rather than a daily driver for most people.

Then you meet the Play Integrity API. It attests to Google's servers about your bootloader state, your ROM signature and your device's verified boot chain, and applications can refuse to run if it does not like the answer. Banks use it. Streaming services use it. Some government identity apps use it.

Now, the honest version, because the internet oversimplifies this in both directions. On GrapheneOS with sandboxed Play Services, a lot of banking apps do work, including plenty of European ones, and there are maintained compatibility lists tracking which. LineageOS fares worse because it generally cannot pass hardware attestation at all.

But look at what that sentence actually says. Whether you can access your own money from your own phone depends on a compatibility list maintained by volunteers, on a policy decision taken inside your bank that you were not consulted about, and on an attestation service run by the company you were trying to leave. You cannot find out in advance. You cannot appeal it. And if your bank changes its mind next year, your recourse is to change banks or change phones.

That is not a technical problem with a technical fix. That is a dependency.

Where I am writing this from

I should say where I stand, because it should change how you read the rest of it.

I am an internet person before I am anything else. I run my own fediverse server. This blog renders out of a CMS I wrote, largely because I wanted to know exactly where my own words were stored and in what format. There is software on my phone that I built for myself and that nobody else is ever going to use. None of that is a protest. It is just how I prefer to work, and it does mean the things being restricted here are things I actually use rather than positions I defend in the abstract.

It does not make me a purist. I carry a phone full of Google services, I use my bank's app like everybody else, and I have shipped plenty of software into ecosystems I did not control and would happily do it again. Shipping into somebody else's platform is most of the job, and a person who refuses on principle to do that is not making a point, they are just not shipping.

The version of the free and open position I think actually holds up is narrower than the slogan. It is not "refuse everything proprietary". It is that a system should keep at least one route open that does not require anyone's permission, and that the route should stay open while things are fine, because you cannot build it on the day you need it. I want the fallback to exist without needing to live in it.

We laugh at the wrong people

There is an old man at the till in front of you counting coins, and the shop has a card-only sign up, and he is holding up the queue insisting they take his money. It is easy to read that as somebody who has not kept up.

He has kept up fine. He has noticed something you have not, which is that every payment he makes now requires a working phone, a working app, a working network, a bank that still has him as a customer and a piece of software that a third party has certified as acceptable. He remembers when it required a coin. He is not confused about the direction of travel, he just got told about it earlier than the rest of us.

The EU is currently legislating this exact point. The regulation on the legal tender of euro banknotes and coins went through the Parliament's position in July and is now in trilogue, and it would oblige member states to monitor whether cash is actually being accepted and whether people can still get hold of it, and to intervene when the answer is no.6 The Commission's reasoning names the people this protects, and it is a longer list than "the elderly": people with disabilities, immigrants, minors, and anyone without meaningful access to digital payment.

We are, in other words, in the middle of writing down as law that a society needs a payment method that does not depend on a private platform granting permission. And in the same year, we are removing the equivalent fallback for software, which is the ability to install a program on a computer you own without registering with a company first.

Europe already leans hard on a small number of banking and payment intermediaries, and every time one of them has a bad afternoon, an entire country discovers how many things quietly stopped working. Adding a mandatory attestation check from Mountain View to the bottom of that stack is not a neutral engineering decision. It is another single point of failure in a stack that already has too few owners.

Don't be evil

Google removed "Don't be evil" from the opening of its code of conduct in 2018. The sentence survives at the very end of the document, which is a fitting place for it.

I do not think the people who built this are cackling. The whole point of the Walt scene is that he is not cackling either. He has an inventory, a distribution problem, and a price he believes is too low, and he works through it in the flat voice of somebody explaining a concept to a student who has not caught up yet. The horror of the line is that it is correct.

What I would take from it

Openness was not a lie during the years Android was open. That is what makes the strategy work. The gift has to be real or nobody takes it, and everyone who took it built on top of it in good faith, which is precisely what makes the second clause enforceable a decade later.

So I have stopped asking whether a thing I depend on is open today, and started asking what it would cost me to leave, and how much of what I have built would still work on the way out. For most of Android that bill comes due on 30 September, and almost everybody who owes it will find out afterwards.

The man with the coins already did the exercise. He is not asking the shop to go backwards. He is asking it to keep one route open that does not require anyone's permission, because he has worked out that the day you need the fallback is not the day you get to build it.

Footnotes

  1. Breaking Bad, season 2 episode 7, "Negro y Azul", AMC, 2009. Walt's line comes in the scene where Jesse argues against raising prices; Jesse's "layered like nachos" pitch to his dealers is the same strategy explained downward.

  2. Amadeo, R. (2013). Google's iron grip on Android: Controlling open source by any means necessary. Ars Technica. The piece that documented the migration of core functionality out of AOSP and into Google Play Services while it was still happening.

  3. Android developer verification, Android Developers. Google's own documentation for the requirement, the rollout schedule and the exemptions, including the ADB carve-out and the limited-distribution account for students and hobbyists. See also Android Authority's timeline of the rollout.

  4. Forsythe, M. (19 March 2026). Android developer verification: balancing openness and choice with safety. Android Developers Blog. Google's response to the criticism, announcing the advanced flow and the limited-distribution account, and citing the Global Anti-Scam Alliance figures.

  5. Frey, S. (25 August 2025). A new layer of security for certified Android devices. Android Developers Blog. The original announcement, and the source of the "over 50 times more malware" figure. Frey is VP of Product, Trust & Growth for Android.

  6. Legal tender of euro banknotes and coins, European Parliament Legislative Train Schedule. Council position December 2025, Parliament position 9 July 2026, currently in trilogue. The proposal obliges member states to monitor both acceptance of and access to cash, and to act where either fails.