Google bets on selfie videos
Google has introduced Selfie for Sign-in, an account recovery feature that allows users to verify their identity through a short selfie video if they lose access to their password, phone, or other sign-in methods. The feature marks Google’s latest effort towards biometric authentication, along with passkeys and multi-factor authentication (MFA).
While Google says the feature is designed to make account recovery more secure and convenient, its launch comes amid a rapid increase in deepfakes and identity fraud stemming from artificial intelligence (AI). This raises the question of whether biometric verification can keep ahead of increasingly sophisticated impersonation attacks.
How Google’s selfie works for sign-in
Google describes Selfie for Sign-In as a backup account recovery method rather than a replacement for the password or passkey.
Users first record a short reference selfie video by following guided movements such as turning their head, allowing Google’s system to capture their face from multiple angles. If they later lose access to their account, they can record another selfie video, which Google compares with the original to verify their identity.
According to the company, the verification process uses multiple security checks, including AI-powered facial matching, liveness detection, directed activities, and suspicious sign-ins. These measures aim to reduce the risk of impersonation using photographs, replayed videos or AI-generated deepfakes.
Google says the reference video is encrypted when stored, collected only with the user’s consent and can be deleted at any time through account settings. By default, video is used only for account recovery unless the user explicitly agrees to additional use.
Rather than replace existing security measures, Google keeps selfies as an additional recovery option for sign-in, along with a passkey, recovery contacts, and two-step verification.
However, cybersecurity experts have called for caution, warning that facial data could be misused.
Purushottam Bhatia, head of South Asia consumer business at Kaspersky, said casual fraud attempts are less likely to succeed against sophisticated deepfake detection systems, but targeted attacks on high-value accounts remain a concern.
He said fraudulent websites often request access to the device’s camera under the pretext of account verification. Captured facial data can later be used for unauthorized account access or sold on the dark web.
Cybersecurity professionals generally agree that no single authentication method is sufficient against today’s threats. Instead, security systems are relying on multiple independent methods of verification.
Passkeys based on standards developed by the FIDO Alliance are considered one of the strongest authentication methods because they eliminate traditional passwords and rely on cryptographic keys stored securely on trusted devices.
Two-factor authentication (2FA) adds another protective layer by requiring users to verify their identity through a separate device or authentication application.
The selfie serves a different purpose for sign-in. Instead of authenticating every login, it primarily addresses one of the biggest challenges users face: recovering an account after losing a password or access to a trusted device.
For users who frequently change or lose their phones, this feature can reduce the risk of permanent account lockout while providing stronger security than traditional recovery questions.
However, experts say the biggest risk associated with facial biometric authentication is its irreversibility.
Cyber ​​expert Amit Jaju said, “After compromise, the password can be reset; the face cannot be changed. If the facial template, selfie video or related identity data is stolen, it can create persistent fraud and privacy risks for the individual.”
AI behind verification
At the core of Google’s new system is AI-powered liveness detection. Unlike traditional facial recognition, which simply compares two images, liveness detection attempts to determine whether the person in front of the camera is physically present.
Google’s Guided Head Movement is intended to prevent attackers from simply presenting a photo or replaying a recorded video.
The company says it combines facial matching with multiple security signals and standard account protection systems to identify suspicious account recovery attempts and impersonation.
However, the effectiveness of these systems will depend on how fast they evolve with generative AI.
Modern deepfake tools can already generate convincing facial movements, realistic blinking, and synchronous speech, making impersonation attempts harder to detect.
Jaju told Business Standard that the biometric template should be protected through strong encryption during transmission and while stored. Encryption keys should be kept separate from data, he said, supported by hardware-backed key management, strict role-based access controls, MFA for administrators, immutable audit logs and continuous monitoring for unusual access.
“Biometric records should be logically separated from account-profile and identity-document data so that compromise of a system does not expose a complete identity document,” he said.
Deepfakes have emerged as a major security threat
Google’s announcement comes amid a sharp increase in AI-enabled identity fraud. According to a 2026 report by Pi-Labs, previously cited by Business Standard, deepfake content has increased by 900 percent in recent years.
The report found that more than 90 percent of apparent deepfakes target women, while 65 percent of Indian organizations reported experiencing deepfake-powered attacks in 2026.
It also said that more than 5,000 face-swapping applications and more than 1,000 voice-cloning tools were publicly available, significantly reducing the hurdles for cybercriminals.
The report highlights the increase in cyber crime complaints related to women, from around 50,000 cases in 2024 to around 80,000 by 2026, reflecting the growing misuse of AI for identity manipulation and digital fraud.
These trends explain why technology companies are investing in AI-powered identity verification, while also facing pressure to protect their systems against AI-generated impersonation.
Privacy remains the biggest concern
Security is only one side of the debate. The second is privacy. Unlike passwords, biometric identifiers cannot be easily reset after a breach. If facial data is compromised, users cannot change their face in the same way they can change a password.
Google has tried to address these concerns by saying that selfie videos are recorded only with the user’s consent, are encrypted when stored, are used for account recovery unless the user opts in for other uses, and can be deleted at any time.
According to Bhatia, each selfie video collected for verification represents an ongoing obligation rather than a check that ends once verification is completed.
Kaspersky’s 2025 phishing findings also showed that attackers are moving beyond passwords and increasingly targeting biometric data, as well as electronic and handwritten signatures, he said.
Bhatia said, “None of this data can be reset like a password. The companies that collect it are effectively owning something that the user can’t get back if it’s leaked, so the responsibility doesn’t end when verification is complete. It continues as long as the data remains intact.”
Privacy advocates may also seek clearer information about how long biometric data is retained, whether it is processed only for account recovery, how it is protected from future breaches, and whether independent audits verify Google’s claims.
How Google’s approach compares to rivals
Google is not the first technology company to use biometrics for authentication.
Apple’s Face ID primarily identifies faces on the device, using Secure Enclaves to process and protect biometric information locally rather than storing the facial image in the cloud.
Microsoft supports biometric authentication through Windows Hello, which performs verification on compatible devices without the need to centrally store facial templates of users.
Financial institutions have also increasingly adopted selfie verification during remote onboarding and Know Your Customer (KYC) processes.
Many banks combine facial recognition with identity-document verification and liveness detection to reduce fraud during account opening or other high-risk transactions.
Google’s implementation is different because it primarily serves as a recovery method for one of the world’s largest digital identity platforms.
A Google account can provide access to Gmail, Photos, Drive, Payments, and many third-party services. So securing its recovery process has a broader impact than authenticating a single banking transaction.
Security layer or new attack surface?
Google’s selfie video feature represents the technology industry’s broader move toward biometric authentication to strengthen account security and simplify recovery. For users, this can reduce the risk of permanent account lockout while adding another protective layer beyond passwords and recovery emails.
However, as deepfake technology and AI-powered impersonation attacks evolve, cybersecurity experts caution that no biometric system is completely infallible. The effectiveness of selfie verification will depend on how well AI-powered liveness detection keeps pace with increasingly sophisticated threats.
Biometric data also poses specific privacy and security risks because, unlike passwords, it cannot be changed after a breach.
Experts say strong encryption, limited data retention, user consent and transparency will be key to building trust in such systems.
So Google’s Selfie for Sign-in feature is best viewed as an additional security layer rather than a standalone solution. Its long-term success will depend on the company’s ability to continually strengthen its defenses against AI-driven fraud.
