News thumbnail
Technology / Tue, 01 Sep 2026 MediaNama

How Google’s Android Policies Affect India’s Digital Sovereignty

From Open Source to Platform GovernanceCan openness be measured simply by the availability of source code? Rather than privatising the code, Google has progressively privatised the governance surrounding the code. They concern who ultimately governs the digital infrastructure upon which billions of people now depend. It is not the source code that is being fenced off, but the conditions of participation. His interests include free and open-source software, digital commons, decentralisation and technology policy.

By Mouhamed Noordeen

Android represented something larger than a mobile operating system, embodying a political idea about computing. Built on the Linux kernel and released through the Android Open Source Project (AOSP), Android offered a markedly different vision from the tightly controlled ecosystems that were beginning to define the smartphone era. Manufacturers could adopt the operating system without paying licensing fees. Developers could distribute applications without relying exclusively on a single marketplace. Users could install software from sources beyond an official app store. Researchers, hobbyists and independent communities could inspect, modify and improve the code.

This openness was one of Android’s defining strengths. By lowering barriers to participation, Android enabled competition among device manufacturers, expanded the global smartphone market and gave an extraordinary diversity of software and hardware innovation. More importantly, it evolved into one of the world’s largest digital commons, a shared technological foundation maintained by many actors and used by governments, businesses, universities, developers and billions of ordinary users. Like other digital commons such as Linux, the web and Wikipedia, its value grew because participation remained comparatively open rather than tightly controlled.

That openness is now undergoing a profound transformation. Google’s recently announced Android Developer Verification programme is the latest in a series of initiatives including Play Protect, Play Integrity, proprietary Google Play Services and Google’s device certification framework that have progressively expanded the company’s role in governing the Android ecosystem. Each of these initiatives can be defended on legitimate security or user-protection grounds. Viewed together, however, they reveal a broader shift in how Android is governed. The practical ability to develop, distribute and trust software is becoming increasingly mediated through Google’s own infrastructure.

The question confronting Android today is whether an operating system can still be meaningfully described as open when the rules governing participation in its ecosystem are increasingly determined by a single corporate actor.

From Open Source to Platform Governance

Can openness be measured simply by the availability of source code? Open source is a legal licence. Openness is also a question of governance.

Anyone can download its source code, modify it and build a functioning operating system. Yet the Android experience of nearly every smartphone user is no longer simply AOSP. Over the past decade, Google has steadily moved key layers of Android beyond AOSP. Google Play Services became the vehicle for location services, push notifications, Maps APIs and numerous developer tools. Play Protect expanded Google’s role in application security. Play Integrity increasingly became the mechanism through which banks, payment providers and other sensitive applications determine whether a device is trustworthy. The newly announced Developer Verification programme extends this architecture further by tying software legitimacy more closely to Google’s identity and trust infrastructure. Usage of Android is mediated through Google Play Services, Google APIs, Play Protect, Play Integrity and an expanding ecosystem of proprietary governance mechanisms. Each can be defended on grounds of security, compatibility or user protection. Collectively, however, they reshape the distribution of authority within the Android ecosystem.

An operating system cannot meaningfully be described as open if developers increasingly require a single institution to establish legitimacy, if essential applications depend upon proprietary services unavailable in the open-source base, if manufacturers must obtain certification to remain commercially viable, and if users encounter growing barriers when installing software outside an approved ecosystem. Rather than privatising the code, Google has progressively privatised the governance surrounding the code.

The source code remains a commons. Participation in that commons increasingly does not.

Security or Centralised Authority?

Google presents Android Developer Verification as a response to a genuine problem. Malware, developer impersonation and fraudulent applications have become increasingly sophisticated, making it difficult for users to distinguish trustworthy software from malicious code. Requiring developers to verify their identities, Google argues, strengthens accountability and makes the Android ecosystem safer.

Few would dispute the importance of improving Android’s security. The question, however, is not whether security is necessary. It is whether security must necessarily be organised through the authority of a single corporate institution.

This is where the current debate extends beyond a routine platform policy. Security is never merely a technical challenge; it is also a question of governance. Who decides which developers are trustworthy? Who determines what constitutes sufficient identity? Who owns the data of that identity? Who establishes the legitimacy of software? Who ultimately becomes the authority that users, developers and device manufacturers must rely upon? Increasingly, the answer appears to be Google itself.

The significance of Developer Verification therefore lies not simply in identity checks but in what they represent. Trust itself is becoming infrastructure. As more decisions about software legitimacy, developer identity and application safety are channelled through Google’s systems, the company is no longer merely providing an operating system. It is increasingly governing the institutional mechanisms through which trust is established across the Android ecosystem.

This represents a significant departure from the traditions of personal computing. Historically, owning a computer meant exercising meaningful authority over it. Users decided what software to install, whom to trust and which risks to accept. Trust emerged through cryptographic signatures, independent software repositories, community reputation and informed user choice rather than through a single central authority. Mistakes were certainly possible, but so too was autonomy.

Open-source ecosystems continue to demonstrate that security and decentralisation are not mutually exclusive. Linux distributions have long maintained secure software repositories through independent maintainers, cryptographic signing and transparent review processes. Projects such as F-Droid similarly rely on reproducible builds, publicly auditable source code and community governance to establish trust without requiring software legitimacy to flow through a single corporate gatekeeper. These systems are not perfect, but they illustrate that strong security need not always depend upon centralised institutional control.

Google’s approach reflects a different philosophy, one in which trust is progressively centralised within the platform itself. Each individual policy may appear modest when considered in isolation. Together, however, they create an architecture in which the practical ability to build, distribute and use software increasingly depends upon Google’s own trust infrastructure.

The debate, therefore, is not between security and openness. It is between competing models of security. One concentrates authority within a single platform steward. The other distributes trust across independent institutions, communities and users themselves. Google’s recent policies suggest that Android is moving steadily towards the former, raising questions that extend far beyond malware prevention. They concern who ultimately governs the digital infrastructure upon which billions of people now depend.

The Enclosure of the Digital Commons

Historians have long described the enclosure movement as one of the defining transformations of early capitalism. Lands that had historically functioned as commons, shared resources governed through collective use and customary rights, were gradually brought under systems of exclusive ownership and institutional control. The commons did not always disappear. Rather, participation increasingly became conditional upon permission rather than shared access. The digital economy is witnessing a comparable transformation.

Today’s commons are not only forests, lakes or fields but software, protocols and digital infrastructure. Linux, the World Wide Web, Wikipedia and countless open-source projects derive their value from broad participation rather than exclusive ownership. They succeed because individuals, institutions and communities can contribute, modify and build upon them without first seeking permission from a single authority.

Android belongs within this tradition. Its success was never Google’s achievement alone. It emerged from the collective contributions of hardware manufacturers, software developers, researchers, translators, accessibility communities, independent application stores and billions of users who embraced an operating system precisely because no single company exercised complete control over it. Google’s investment in Android was also unquestionably important, but the platform’s extraordinary commercial success depended equally on the openness that encouraged others to innovate upon it.

The significance of Google’s recent policy direction therefore extends beyond any individual security measure. Android illustrates how the enclosure of a digital commons can occur without closing the commons itself. The Android Open Source Project remains publicly available. Anyone can still inspect the source code, modify it and build an operating system. What has changed is the institutional architecture surrounding that code. As Play Services, Play Integrity, certification requirements and Developer Verification become increasingly central to participation, the open-source foundation remains intact while meaningful participation becomes progressively mediated through Google’s proprietary infrastructure.

This is the defining characteristic of contemporary platform capitalism. Corporations no longer need to privatise the commons by withdrawing access to source code. They can instead govern the conditions of participation. Control shifts from ownership of software to ownership of the platform. From operating systems to certification. From publishing code to determining legitimacy. From technology itself to the institutions that govern technology.

Google did not need to close Android. It only needed to make the open parts increasingly insufficient. The enclosure of digital commons in the twenty-first century is therefore not achieved by fencing off code. It is achieved by governing participation within the ecosystem built around that code. That is the transformation Android is now beginning to illustrate.

Why India Should Be Concerned

Over the past decade, India has emerged as one of the world’s most ambitious advocates of digital sovereignty. Policymakers speak of building indigenous artificial intelligence, trusted telecommunications, semiconductor manufacturing and Digital Public Infrastructure (DPI). Initiatives such as Aadhaar, UPI, DigiLocker, ONDC and BHASHINI are presented as evidence that India can build sovereign digital systems as public infrastructure rather than rely exclusively on foreign private platforms.

This ambition deserves recognition. Yet it also exposes a fundamental contradiction. Nearly every interaction with India’s digital public infrastructure begins not with a government service but with a smartphone. Around 95 per cent of smartphones in India run Android. In practice, this means that the principal gateway through which citizens access banking, education, healthcare, public services and digital commerce is an ecosystem whose technical rules are largely defined by a private corporation headquartered outside India.

This is where the distinction between digital sovereignty and platform sovereignty becomes important. Digital sovereignty concerns a nation’s ability to shape its own technological future through domestic innovation, public infrastructure, regulation and strategic autonomy. Platform sovereignty, by contrast, describes the power of a private platform to unilaterally establish the technical and institutional rules through which millions of people participate in digital life. These rules are established not through legislation but through software updates, developer agreements, certification frameworks, APIs and security policies.

India’s competition authorities have already recognised the broader implications of Google’s position in the Android ecosystem. In its 2022 decision against Google, the Competition Commission of India concluded that Google’s agreements with smartphone manufacturers, including the Mobile Application Distribution Agreement (MADA) and the Android Fork Compatibility Agreement (AFA) reinforced the company’s dominance across multiple digital markets and restricted competition. The Commission imposed a penalty of ₹1,337 crore and directed Google to modify several business practices. That decision focused primarily on Google’s contractual relationships with device manufacturers. The current policy trajectory raises a related but deeper concern, not merely how Google shapes competition, but how it increasingly governs participation within the Android ecosystem itself.

Google’s recent policy changes should therefore not be viewed solely as decisions affecting app developers. They illustrate how governance over a critical layer of India’s digital ecosystem increasingly resides outside India’s own innovation ecosystem and public institutions. When the practical ability to publish software, establish developer legitimacy or determine application trust becomes progressively tied to a single platform’s policies, questions of sovereignty extend far beyond data localisation or cloud infrastructure.

The consequences are not limited to government. Independent developers, free & open-source projects, universities, public-interest technology initiatives and Indian startups all operate within the institutional framework created by Android. Every additional layer of proprietary governance raises the cost of participating independently of Google’s ecosystem and narrows the space for alternative models of software distribution, experimentation and innovation.

Digital sovereignty, therefore, cannot be reduced to the location of servers or only to the ownership of data. It must also include meaningful autonomy over the platforms through which digital life is organised. A nation may build world-class digital public infrastructure, but if the operating system through which citizens access that infrastructure is increasingly governed elsewhere, sovereignty remains incomplete.

Conclusion

Google’s recent policy changes are easy to dismiss as technical updates affecting only software developers. They are not. They reflect a broader transformation in how digital infrastructure is governed. The debate over Android is no longer simply about source code, app stores or malware prevention. It is about who exercises authority over one of the most important technological foundations of modern society.

Android’s success was built on a simple but powerful idea that a shared technological platform could remain open enough for manufacturers, developers, researchers, businesses and users to innovate without first seeking permission from a single gatekeeper. That openness did not merely produce better software, it created one of the world’s largest digital commons, enabling billions of people to participate in the digital economy on relatively open terms.

The danger today is not that Android will cease to be open source. The source code may remain publicly available for years to come. The more significant transformation is that the practical conditions for participating in the Android ecosystem are increasingly being defined through proprietary governance mechanisms. As identity verification, trust infrastructure, certification and platform policies become more central to software distribution, openness risks becoming a formal legal characteristic rather than a lived reality.

For India, this raises questions that extend well beyond Google itself. A nation that aspires to digital sovereignty cannot afford to overlook the governance of the platforms through which its citizens experience digital life. Public digital infrastructure, indigenous innovation and strategic technological autonomy all depend upon a mobile ecosystem whose institutional rules increasingly lie outside India’s own sphere of influence. Sovereignty is not only about owning infrastructure or storing data within national borders, it is also about retaining meaningful agency over the technologies that organise everyday social, economic and civic life.

The debate, therefore, should not be framed as one between security and openness, nor as one between Google and its critics. Security is essential, and platforms have legitimate responsibilities to protect users. But security should not become the unquestioned justification for concentrating governance within a single corporate institution. The challenge before policymakers, technologists and civil society is to imagine models of digital governance that protect users while preserving the openness that made the internet and Android engines of innovation in the first place.

History teaches us that commons rarely disappear overnight. They are enclosed gradually, one rule, one institution and one layer of governance at a time, often in the name of efficiency, order or security. The enclosure of Android, if it is indeed underway, follows a similar pattern. It is not the source code that is being fenced off, but the conditions of participation.

Whether this trajectory continues is not a question for Google alone. It is a question for governments, regulators, developers, open-source communities and citizens. More importantly, it is a question about the kind of digital future we wish to build. Will the technologies that increasingly mediate our lives remain shared infrastructures governed in the public interest, or will they become spaces where participation is determined by the policies of a handful of private platforms?

The answer will shape not only the future of Android, but the future of digital sovereignty itself.

Author Bio: Mouhamed Noordeen is President of the Free Software Hardware Movement Puducherry. He works as a software engineer with Janastu, a non-profit technology organisation, on community-owned wireless mesh networks, decentralised technologies and community knowledge archiving platforms. His interests include free and open-source software, digital commons, decentralisation and technology policy.

Read more:

© All Rights Reserved.