All news
productcybersecurityregulation

Google Adds Selfie Video Sign-In for Account Recovery

24 Jul 2026

Google announced on Thursday (per TechCrunch, dated July 23, 2026) that it is adding a selfie video option as a new way for users to sign in to their accounts — specifically targeting the frustrating scenario where someone is locked out, has forgotten their password, or has lost access to their phone, computer, or two-factor authentication app.

How it works

Setup requires users to look at their device camera and follow onscreen prompts, capturing multiple angles of their face through simple head movements. This reference video is recorded and stored in the cloud using encryption. Google states that selfie videos remain protected "even when they're not being used," and users can delete their stored video from their account at any time.

To actually sign in later, users capture another short video performing simple movements — a liveness check designed to prove the video is being recorded in real time rather than replayed. Google says it uses "multiple layers of security to help prevent impersonation attempts like fake photos and videos (i.e., deep fakes)," though the company hasn't disclosed the technical details of how that detection works.

By default, the stored selfie video is used only for sign-in, but users can opt to share it for unspecified "additional purposes" — a detail Google has not elaborated on.

The feature is rolling out gradually worldwide in phases, though Google has not specified a start or completion date, nor which countries or account types (personal vs. Workspace) get access first. Users can check eligibility and set up the feature at g.co/signin-selfie.

The privacy trade-off

The upside is real: losing access to a 2FA device or forgetting a password is one of the most common — and costly — support headaches for any product with an authentication flow. Biometric video recovery could meaningfully cut friction and reduce reliance on knowledge-based methods like security questions or SMS codes.

But storing biometric reference videos, even encrypted, raises the stakes of any future data breach — biometric data can't be reset the way a password can. The optional sharing of selfie videos "for additional purposes" also invites questions about scope creep, especially since Google hasn't detailed what those purposes might be. And with no public data on false positive/negative rates or accessibility considerations, it's hard to independently assess how robust the deepfake-detection layer really is.

Why founders should care

For founders building or evaluating authentication and identity-verification products, this is a signal worth tracking closely. It's plausible that Google's move will accelerate consumer and enterprise comfort with biometric video as a recovery mechanism, particularly for products that currently lean on SMS or app-based 2FA and see meaningful support costs from lockouts. Startups in the identity space should likely expect increased scrutiny — regulatory and user-driven — around biometric storage and consent, and may want to get ahead of privacy questions proactively rather than reactively. At the same time, given the missing details on rollout scope, breach-impact severity, and technical safeguards, founders should treat this as an early signal rather than a proven playbook, and watch how users and regulators respond as the phased rollout expands.

Sources