
Google has introduced selfie for sign-in, a backup account recovery method that allows users to verify their identity through a short selfie video when they lose access to their password, phone, or other sign-in methods. According to reports from Business Standard and Firstpost, the feature began rolling out globally on Thursday, July 23, 2026, as reported by Google, allowing users to create a reference video by following guided movements such as turning their head. If users are later locked out of their Google Account or cannot access their usual recovery methods, they can record another short selfie video, which Google compares with the original recording to confirm their identity. The process includes safeguards designed to ensure that the person in front of the camera is physically present, with Google comparing the new recording against the previously enrolled version before deciding whether to restore account access. The feature is currently rolling out to standard personal Google Accounts and is being introduced gradually across supported accounts, as reported by Google. Users can navigate to their Google Account settings > Security & sign-in > Selfie Video or visit g.co/signin-selfie to set up the feature.
The verification process uses multiple security checks including AI-powered facial matching, liveness detection, guided movements and suspicious sign-in detection, as reported by Business Standard. Google's guided head movements are intended to prevent attackers from simply presenting photographs or replaying recorded videos. The system requires users to perform real-time, dynamic head movements and liveness detection during authentication to prevent spoofing with static photos or video deepfakes. The platform saves the video recording and uses it to authenticate live videos that users upload during sign-in attempts later on. The saved videos are encrypted at rest and users can delete their recorded selfie video at any time through their account dashboard. By default, the video is used only for account recovery unless the user explicitly agrees to additional uses. During enrollment, Google guides users through a series of simple head movements so the system can capture multiple facial angles rather than relying on a single still image, as detailed in Firstpost. The system requires users to perform simple movements during authentication and uses multiple security checks to distinguish genuine users from manipulated images or videos. Current recovery methods remain available including trusted devices, registered phone numbers, recovery contacts, and two-factor authentication. Workspace accounts, child accounts and some high-security accounts are not currently supported for this feature.
Despite Google's privacy assurances, the rollout has sparked significant debate online, with some users questioning whether the company could eventually use the videos to improve its artificial intelligence systems. On Reddit and other online forums like X and TikTok, some users argued that the feature resembles another way for technology companies to collect valuable biometric data, with several speculating that the recordings could be used to train facial recognition or AI models. Others said they were uncomfortable storing facial videos with Google, even if encrypted. However, Google's published policy differs from those claims, according to the company. According to Google, selfie videos are not used for purposes beyond account verification unless users actively opt in. Google says users can separately choose whether to allow their videos to help improve its facial recognition and verification technology, and participation is optional rather than required to use the feature. This distinction has become central to the online discussion, as critics remain sceptical while privacy advocates continue to scrutinize how major technology companies collect and process biometric information. The feature marks Google's latest push towards biometric authentication alongside passkeys and multi-factor authentication (MFA), with Google describing it as a backup recovery method rather than a replacement for passwords or passkeys.
Cybersecurity experts have raised concerns about the permanence of facial biometric data. Purshottam Bhatia, head of consumer business for South Asia at Kaspersky, told Business Standard that while casual fraud attempts were less likely to succeed against sophisticated deepfake detection systems, targeted attacks on high-value accounts remained a concern. Bhatia emphasized that if a facial template is stolen, it creates a persistent fraud and privacy risk for the individual, as users cannot replace their face like they can reset a password. Amit Jaju of global consulting and expert advisory firm Ankura warned that "a password can be reset after compromise; a face cannot be changed. If a facial template, selfie video or associated identity data is stolen, it can create a persistent fraud and privacy risk for the individual." The move is also likely to renew scrutiny around biometric data collection, with regulators in several jurisdictions intensifying focus on how companies gather, store and process facial recognition data, particularly as AI technologies become more capable of analysing and generating realistic human faces. Kaspersky's 2025 phishing findings showed that attackers were moving beyond passwords and increasingly targeting biometric data, with cybercrime complaints involving women increasing from about 50,000 cases in 2024 to nearly 80,000 by 2026, reflecting the growing misuse of AI for identity manipulation and digital fraud.
The launch comes amid a sharp rise in AI-enabled identity fraud, according to a 2026 report by pi-labs cited by Business Standard. The report found that deepfake content has risen 900% in recent years, with more than 90% of explicit deepfakes targeting women, and 65% of Indian organizations reporting experiencing deepfake-driven attacks in 2026. The report also highlighted that more than 5,000 face-swapping applications and over 1,000 voice-cloning tools were publicly available, significantly lowering barriers for cybercriminals. Google addresses these concerns directly, stating in its blog post that "When you use a selfie to sign in, we use multiple layers of security to help prevent impersonation attempts like fake photos and videos (i.e., deep fakes)". The new feature includes protection against impersonation and detection of potential deepfakes, with a new recording being compared with the stored selfie video and users must perform movements to confirm that the video is live. However, modern deepfake tools can already produce convincing facial movements, realistic eye blinking and synchronised speech, making impersonation attempts harder to detect. The effectiveness of these systems will increasingly depend on how quickly they evolve alongside generative AI, with cybersecurity experts cautioning that no biometric system is entirely foolproof.