Google significantly curtailed the influx of malicious applications targeting its Play Store in 2025, preventing 1.75 million policy-violating apps from publication. This represents a substantial decrease from the 2.36 million blocked in 2024 and 2.28 million in 2023, signaling a potential shift in the tactics of bad actors and the increasing effectiveness of Google’s security measures. The company attributes this success to heightened investments in proactive security systems and, crucially, the integration of artificial intelligence technologies.
The findings, detailed in Google’s latest Android app ecosystem safety report released on February 19, 2026, highlight a concerted effort to combat malware, financial fraud, privacy violations, deceptive subscriptions, and other threats lurking within the app ecosystem. Google’s proactive approach extends beyond simply reacting to malicious apps; it focuses on deterring bad actors from even attempting to publish harmful content. This strategy includes developer verification processes, mandatory pre-review checks, and stringent testing requirements, all designed to raise the bar for entry into the Google Play ecosystem.
AI as a Deterrent and Detection Tool
A key component of Google’s improved security posture is the deployment of “AI-powered, multi-layer protections.” According to the report, these defenses are actively discouraging malicious actors from submitting harmful applications in the first place. Google now conducts over 10,000 safety checks on every app before it goes live, and continues to re-evaluate apps even after they’ve been published. The integration of generative AI models into the app review process has proven particularly effective, enabling human reviewers to identify complex malicious patterns more quickly and efficiently.
This isn’t simply about increased efficiency; it’s a fundamental change in the threat landscape. The Google Threat Intelligence Group (GTIG) has observed a significant evolution in how adversaries are leveraging artificial intelligence. As detailed in a November 5, 2025 report, GTIG found that threat actors are no longer solely using AI for productivity gains, but are actively deploying novel AI-enabled malware in real-world operations. This marks a fresh phase of AI abuse, involving tools capable of dynamically altering their behavior during execution.
The Rise of AI-Enabled Malware
GTIG’s research identified specific malware families, such as PROMPTFLUX and PROMPTSTEAL, that utilize Large Language Models (LLMs) during execution. This “just-in-time” AI capability allows the malware to adapt and evade detection, presenting a significant challenge to traditional security measures. The report builds upon earlier analysis from January 2025, which highlighted the adversarial misuse of generative AI. Google has responded by disabling projects and accounts associated with malicious actors and continuously refining its models to resist misuse. Further details on Gemini’s security safeguards are available in a dedicated white paper, “Advancing Gemini’s Security Safeguards.”
While direct attacks targeting Google’s frontier models or generative AI products from advanced persistent threat (APT) actors haven’t been observed, GTIG has mitigated frequent model extraction attacks – a form of corporate espionage – originating from private sector entities globally. This suggests that businesses with their own AI models are likely to face similar threats in the near future. The company has also been working to thwart malicious activity by applying intelligence to strengthen its classifiers and models.
Beyond Malware: Phishing and Information Gathering
The threat extends beyond malware development. Recent observations by GTIG indicate that threat actors are also employing AI to gather information and craft highly realistic phishing scams. This multifaceted approach underscores the growing sophistication of cyberattacks and the increasing role of AI in enabling malicious activity.
Google’s success in reducing malicious app submissions is also reflected in the declining number of banned developer accounts. In 2025, the company banned over 80,000 developer accounts attempting to publish harmful apps, a significant drop from the 158,000 banned in 2024 and the 333,000 banned in 2023. This reduction suggests that Google’s security measures are not only preventing the publication of malicious apps but also deterring bad actors from investing in further attempts.
Preventing Excessive Data Access
In addition to blocking malicious apps, Google also focused on preventing applications from gaining excessive access to sensitive user data. In 2025, the company prevented more than 255,000 apps from accessing data beyond what was necessary, down from 1.3 million in 2024. This proactive measure helps protect user privacy and reduces the potential for data breaches.
Google plans to further increase its investments in AI in 2026 to stay ahead of emerging threats. The company recognizes that the threat landscape is constantly evolving, and that continuous innovation is essential to maintaining a secure app ecosystem. This commitment to AI-driven security reflects a broader industry trend, as organizations increasingly rely on artificial intelligence to defend against sophisticated cyberattacks.
Key Takeaways
- Google Play Store saw a significant reduction in malicious app submissions in 2025, with 1.75 million policy-violating apps blocked.
- AI is playing a crucial role in both detecting and deterring malicious activity on the platform.
- Threat actors are increasingly leveraging AI to develop sophisticated malware, create realistic phishing scams, and gather information.
- Google is actively investing in AI-powered security measures and sharing best practices to protect the broader ecosystem.
Looking ahead, Google will continue to refine its security measures and adapt to the evolving threat landscape. The company’s ongoing commitment to AI-driven security is essential to protecting Android users and maintaining the integrity of the Google Play Store. The next major update on Google’s security initiatives is expected during the Google I/O developer conference in May 2026.
What are your thoughts on Google’s approach to app security? Share your comments below, and let us know how you stay safe online.
Keep reading