It is what I would call "functionally true". You have to enable developer mode to install unverified apps. A very, very small subset of users are going to do that.
https://android-developers.googleblog.com/2026/03/android-developer-verification.html?m=1
If you have more information on this, please share.
IMO the answer from a security perspective is that the Linux distro "official repo" model is about as good as it gets. However somehow we still have Fedora COPR, openSUSE OBS, Arch AUR, etc. Those are essentially like FDroid. If someone can solve the problem of why apps can't be easily just added and controlled in the official repos, maybe we'd be getting somewhere. Seems to be an industry issue.