Google is trying to normalize a new "complete the captcha on your phone by scanning a QR code" flow, which I'm sure will be a whole new vector for scams.
Users are habituated to clicking links (mostly from their email) as verification, too. QR codes get a weird amount of hate for something that basically amounts to a hyperlink you can transmit through meatspace.
Or you could send them to download some spyware/adware Play Store app