Publishing an app got stricter in 2026. Here is what changed.

Tom Whitfield
Writer
The gap between finished and available got wider
You can build an app faster than at any point in the last decade. Getting it into people's hands is the part that got harder, and it changed twice this year.
None of what follows is a reason not to build an app. It is a list of the admin that now sits between a finished build and a live listing, so it lands in your plan rather than as a surprise a fortnight before launch.
Two changes matter: Google now wants to know who you are, and Apple now wants to know how old your users are.
Google is tying apps to verified identities
Android is moving to a model where apps have to be registered by a verified developer to be installed on certified devices. Verification means giving Google a real identity, personal or business, through the Play Console or the Android Developer Console.
The rollout schedule runs like this. Verification opened to everyone in March 2026, the advanced install flow for unverified apps goes global in August, and enforcement begins on 30 September 2026 in Brazil, Indonesia, Singapore and Thailand. Other regions follow from 2027.
So if you are launching in the UK this year, nothing blocks you today. It blocks you next year, which is well inside the life of anything you build now.
The wider point is that this applies beyond the Play Store. Installing an unregistered app on a certified device, including sideloading, becomes something a user has to work at rather than something that just happens.
What that means if you are paying for an app
Two practical consequences, and the second is the one that causes arguments.
First, verification takes time and identity documents. It is not hard, but it is not something to start the week you want to launch.
Second, and more important: whose identity is on the account? If an agency registers under its own name and its own developer account, then the verified owner of your app is your agency.
This has always mattered for account ownership and it now matters more, because the identity is bound into whether the app can be installed at all. The developer account should be registered to your business, with you as owner, and whoever builds it added as a user with the access they need.
If you are commissioning an app, put that in writing before work starts. Untangling it later means a transfer process, and in the worst case a new listing that loses your reviews and your install base.
There is also a free limited distribution account for students and hobbyists, capped at around 20 devices, which is fine for a prototype shown to a handful of people and not a route to market.
Apple has rebuilt age rules around the operating system
Apple's changes came faster and are already live.
App Store Connect moved to an expanded set of age ratings, adding 13+, 16+ and 18+ to the existing 4+ and 9+. Developers had to answer the updated rating questions by 31 January 2026 or lose the ability to submit updates.
From 24 February 2026, users in Australia, Brazil and Singapore cannot download apps rated 18+ unless they have been confirmed as adults. Apple also expanded its Declared Age Range API, which lets an app ask for a user's age bracket rather than build its own verification, with staged starts in Utah on 6 May 2026 and Louisiana on 1 July 2026.
For the UK, the relevant change arrived with iOS 26.4 in April 2026, which introduced device level age verification tied to the Apple ID under the Online Safety Act. Ofcom welcomed the move , while noting Apple was not legally required to implement it at the operating system layer.
The direction is consistent across both stores. Age assurance is moving down into the platform, and apps are expected to ask the platform rather than roll their own.
The bit that catches ordinary businesses
Most owners hear age verification and assume it is somebody else's problem, because their app has nothing sensitive in it.
The trigger is rarely your content. It is whether your app lets one user send something to another.
A chat feature, comments, reviews, photo uploads, even a support inbox that shows other people's messages, changes what you have to declare in your age rating questionnaire and can pull you into the scope of UK online safety duties. Those duties are shaped by what a service does rather than by how many users it has, so being small is not by itself an exemption.
This is worth raising at the design stage, because the cheapest version of the answer is usually a scoping decision. An app that lets customers message your business is a very different regulatory object from one that lets customers message each other, and plenty of products get the benefit of the first while accidentally building the second.
Budget the admin, not just the build
For a straightforward app with no user to user features, this is days of paperwork rather than weeks. Developer accounts, verification, age rating answers, a privacy policy that matches what the app actually collects.
The things that reliably cause delay are less technical than people expect. Business documents that do not match across the two stores. A company name on the developer account that is not the name on the listing. Nobody with authority to complete identity checks being available in launch week.
The stores are also within their rights to reject a submission for reasons that have nothing to do with code quality, so treat first submission as a milestone with slack after it rather than the day before your launch event.
Where this is heading
Both platforms are converging on the same position. They want a real, accountable identity behind every app, and they want the platform rather than the app to decide who is old enough to use it.
For anyone building a legitimate product, this is broadly good news. It raises the floor, makes impersonation harder, and takes a hard verification problem off your plate.
It does mean the days of shipping something to a store anonymously in a weekend are ending, and that planning a launch now means planning the paperwork alongside the build.
If you want this handled properly
We have taken our own apps through both stores, including Spello and Jude, and built and shipped Freeater for a client, so this process is one we run rather than read about.
If you are planning an app and want to know what the store requirements mean for your idea specifically, book a free 15 minute consultation or email info@kerenlabs.com .
Got an idea you want to build?
Start with a free 15 minute call. Honest advice, no pressure, and nothing to sell you.
