Google has added a new way into locked accounts: a short selfie video that stands in for a password when the usual sign-in options fail. Announced on July 23, 2026, the feature, called "selfie video," is aimed squarely at account recovery, the moment a user is locked out because they lost a phone, forgot a password, or are stuck on a borrowed device. It joins passkeys, recovery emails, phone numbers, and recovery contacts rather than replacing any of them, and it lands at a time when AI-generated deepfakes have made identity verification a harder problem across the industry.
How the Selfie Video Actually Works
Setup happens inside a Google Account's security settings, where users look into their device camera and complete several guided head movements so Google can capture their face from multiple angles. If they later get locked out, they record a fresh selfie video, and Google compares it against the enrolled version to confirm it is the same person. The head-turning requirement doubles as a liveness check, since real-time deepfake tools and face-swapping software tend to struggle with side profiles and sudden movement, making it harder to fool the system with a still photo or a pre-recorded clip. Users without a camera on their computer can hand off enrollment to a phone through a QR code.
What Happens to the Video After You Record It
Google says the video is encrypted at rest and used only to verify sign-in unless a user separately opts in to let it be used for other purposes, such as improving the company's facial recognition systems more broadly. That opt-in is off by default. Users can delete their enrolled video at any time from their account settings, and once deleted it can no longer be used for recovery. Google has noted it may keep deleted videos for a short period afterward for security purposes, and longer in cases tied to policy enforcement.
Why Google Is Pushing This Now
Account recovery has become one of the weakest points in modern authentication. Passkeys and hardware security keys have reduced how much people rely on memorized passwords, but the fallback path when someone loses their device still typically runs through a recovery phone number or email address, both of which attackers can intercept through SIM swaps or phishing. Google is framing the selfie video as a way to close that gap, especially since the accounts in question often hold years of emails, photos, and documents that would be difficult or impossible to replace.
The timing also lines up with a broader surge in AI-driven identity fraud. Industry research this year has pointed to a sharp rise in deepfake content and a growing number of publicly available face-swapping and voice-cloning tools, which has lowered the technical bar for impersonation attacks. That backdrop has pushed several major platforms toward biometric recovery methods that are harder to spoof than a static photo or a security question with a guessable answer.
How This Compares to What Apple and Microsoft Already Offer
Google is a late mover here rather than a pioneer. Apple has offered Face ID since the iPhone X launched in 2017, using it for device unlock, app authentication, and Apple Pay, though it is tied to Apple hardware rather than account-level recovery across devices. Microsoft's Windows Hello has supported facial recognition sign-in since Windows 10 launched in 2015, primarily as a way to unlock a specific device rather than to recover a locked account from anywhere. Google's version is different in scope: it works across devices and platforms as an account-level recovery method, closer to a biometric replacement for security questions than a device unlock feature.
The feature is rolling out to eligible users now, with Google positioning it as a recovery-first tool even though it can also be used for regular sign-in. Its success will likely hinge on two things: how well the liveness checks hold up against increasingly capable deepfake tools, and whether users trust Google enough to hand over a biometric video of their face for something as high-stakes as account recovery. Security researchers have already flagged that any biometric system tied to something as permanent as a face carries higher stakes than a password, since a face cannot be reset the way a leaked password can. How Google handles edge cases, disputed identity checks, and the rare but real risk of a compromised enrollment video will be the real test of whether this becomes a trusted recovery option or another attack surface.
Comments