Google has introduced the 'video selfie for sign-in' feature—an account recovery tool that allows users to verify their identity via a short video selfie if they lose access to their password, phone, or other login methods.
This functionality is part of Google's latest efforts to implement biometric authentication alongside the use of passkeys and multi-factor authentication (MFA). Although the company claims this feature will improve convenience and recovery security, its launch comes amid a rapid rise in deepfake fraud generated by artificial intelligence (AI).
How the Google feature works
Google positions the 'video selfie for sign-in' as an additional recovery method, not a complete replacement for passwords or passkeys. The process begins with the user recording a short reference video selfie performing specific movements, such as turning their head, so that Google's systems can capture the face from different angles. Upon subsequent loss of account access, the user can record a new video, which is then compared to the original for identity verification.
According to the company, the verification process includes several security measures, such as AI-based facial recognition, liveness detection, motion control, and detection of suspicious login attempts. These measures are intended to reduce the risk of impersonation using photographs, replayed videos, or AI-generated deepfakes.
Data processing and storage
Google states that the reference video is encrypted during storage, is collected only with user consent, and can be deleted at any time through account settings. By default, the video is used exclusively for account recovery unless the user explicitly agrees to additional use cases. The company emphasizes that the 'video selfie for sign-in' complements existing protection measures, such as passkeys, recovery contact details, and two-step verification.
Cybersecurity expert warnings
Nevertheless, cybersecurity specialists urge caution, pointing to the potential misuse of facial data. Purshottam Bhatia, Head of Consumer Business in South Asia at Kaspersky, noted that simple fraudulent attempts are unlikely to succeed against sophisticated deepfake detection systems, but attacks targeting high-value accounts remain a problem.
He added that fraudulent websites often request access to the device camera under the guise of account verification. The obtained facial data can subsequently be used for unauthorized account access or sold on the dark web. Experts agree that no single authentication method is sufficient protection against modern threats; instead, systems increasingly rely on multiple independent verification methods.
Comparison with other protection methods
Passkeys, based on FIDO Alliance standards, are considered among the most reliable authentication methods because they eliminate traditional passwords and use cryptographic keys securely stored on trusted devices. Two-Factor Authentication (2FA) adds another layer of protection by requiring users to confirm their identity via a separate device or authenticator app.
The 'video selfie for sign-in' serves a different purpose: it primarily solves one of the biggest user problems—regaining access after losing passwords or trusted devices—rather than authenticating every login. For users who frequently change or lose phones, this feature can reduce the risk of permanent account lockout while providing higher protection than traditional recovery questions.
Irreversibility of biometric data
Experts warn that one of the biggest risks associated with facial biometric authentication is its irreversibility. Amit Jaju from the consulting firm Ankura stated: 'A password can be reset after compromise; a face cannot be changed. If a face template, video selfie, or related identification data is stolen, it can create a permanent risk of fraud and privacy for the individual.'
AI technologies in verification
At the core of Google's new system is AI-based liveness detection. Unlike standard facial recognition, which simply compares two images, liveness detection attempts to establish whether a person is present in front of the camera at that moment. The head movements specified by Google are designed to prevent attackers from simply presenting a photograph or replaying a recorded video.
The company claims to combine facial matching with multiple security signals and standard account protection systems to detect suspicious recovery attempts and impersonation. However, the effectiveness of these systems will depend on how quickly their development keeps pace with generative AI. Modern deepfake tools are already capable of creating convincing facial movements, realistic eye blinking, and synchronized speech, which complicates the detection of impersonation attempts.
Deepfake threats and privacy
Google's announcement coincides with a sharp increase in AI-driven fraud. According to a 2026 report by pi-labs cited by Business Standard, the volume of deepfake content has increased by 900 percent in recent years. The report noted that over 90 percent of explicit deepfakes target women, and 65 percent of Indian organizations reported deepfake-based attacks in 2026.
Furthermore, over 5,000 face-swapping applications and more than 1,000 voice cloning tools have become publicly available, significantly lowering the barrier for cybercriminals. The rise in reports of cybercrimes involving women, from approximately 50,000 cases in 2024 to nearly 80,000 by 2026, reflects the growing abuse of AI for identity manipulation and digital fraud.
Privacy as the main issue
Beyond security concerns, there is also the issue of privacy. Unlike passwords, biometric identifiers cannot simply be reset after a leak. If facial data is compromised, users cannot replace their face in the same way they can change a password. Google attempts to address these concerns by stating that video selfies are recorded only with user consent, are encrypted during storage, are used only for account recovery unless the user agrees otherwise, and can be deleted at any time.
According to Bhatia, every collected video selfie represents an ongoing commitment, not a check that concludes after verification. Kaspersky's 2025 phishing study also showed that attackers are moving beyond passwords and increasingly targeting biometric data, as well as electronic and handwritten signatures. He emphasized: 'None of this data can be reset like a password. Companies that collect it are effectively taking guardianship over something the user cannot get back if it leaks, so responsibility does not end when verification is complete. It continues as long as the data is stored.'
Comparison with competitors
Google is not the first technology company to use biometrics for authentication. Apple uses Face ID, which performs facial recognition primarily on the device, utilizing the Secure Enclave for local processing and protection of biometric information, rather than storing the face image in the cloud. Microsoft supports biometric authentication through Windows Hello, which similarly performs verification on compatible devices without centralized storage of user face templates.
Financial institutions are also increasingly adopting selfie verification for remote registration and KYC (Know Your Customer) processes. Many banks combine facial recognition with document verification and liveness detection to reduce fraud when opening accounts or conducting other high-risk transactions. Google's implementation differs in that it functions primarily as a recovery method for one of the world's largest digital identity platforms, as a Google account grants access to Gmail, Photos, Drive, payments, and numerous third-party services.
Security layer or new attack surface
Google's video selfie feature reflects a broader trend in the technology industry—the shift towards biometric authentication to strengthen account security and simplify recovery. For users, this can reduce the risk of permanent account lockout and add a protective layer on top of passwords and emails. However, according to cybersecurity experts, no biometric system is absolutely secure, as deepfakes and AI-driven attacks are constantly evolving. The effectiveness of selfie verification will depend on how quickly AI-based liveness detection can keep up with increasingly complex threats.
Biometric data also creates unique privacy and security risks because, unlike passwords, they cannot be changed after being breached. Experts insist that strong encryption, limited data retention, user consent, and transparency will be critical to gaining trust in such systems. Thus, the 'video selfie for sign-in' feature should be viewed as an additional layer of security, not a standalone solution, and its long-term success will depend on the company's ability to continuously enhance defense against evolving AI-driven fraud.