Skip to content
News

Google wants a video of your face. You already have better options

On Thursday 23 July 2026, Google added a new way into a Google Account: a short video of your face. You record it in advance, following prompts to turn and tilt your head so the camera captures you from several angles. Google saves the clip. If you are ever locked out, you record a fresh one, and Google compares the two.

The pitch is convenience. Lose your phone, forget your password, and you can still reach your Gmail. Reaction has been cold. The objections are worth going through in detail, because the case against enrolling rests on Google’s own documentation rather than on general suspicion of Google.

The thing you cannot take back

Start with what makes this different from every other credential you own.

Passwords, passkeys and phone numbers can all be replaced after a compromise. A face cannot. If a facial template or a stored selfie video is ever exposed, the exposure is permanent, and it follows you into every other system that checks faces.

Purshottam Bhatia, head of consumer business for South Asia at Kaspersky, put the consequence on the company rather than the user. Firms collecting this data are, in his words, “taking custody of something a user cannot get back if it leaks”. The obligation does not end when the verification passes. It runs for as long as the file exists.

Amit Jaju, a cyber expert quoted by Business Standard, made the same point from the user’s side and added a design recommendation. Biometric records should be kept logically separate from account profile and identity document data, so that breaching one system does not hand over a complete identity dossier. Google’s documentation does not say whether it does this.

Google already solved this problem, twice

The case for selfie video rests on a specific scenario. You have lost the device holding your passkey, you cannot reach your recovery email, and your phone number is gone.

That is a real situation. It is also one Google has been steadily closing for two years without asking anyone for a face.

Passkeys let you sign in using the fingerprint, face scan or screen lock on a device you already trust, and the private key never leaves that device. In October 2025 Google added recovery contacts, letting you nominate up to ten people who can vouch for you. When you are locked out, a chosen contact receives a code valid for fifteen minutes, and you are back in. TechCrunch covered that launch alongside a second addition, signing in with your mobile number using the lock screen passcode from your previous phone.

Neither route goes through your SIM card. Neither requires storing anything permanent about your body. Google’s own representative told The Register that the company expects most people to keep using passkeys for regular sign-in and to reach for the selfie only when the passkey device is gone.

Set up a passkey, a recovery contact and a working recovery email, and the gap selfie video fills shrinks to the case where all three fail at once. Weigh that narrow residue against a permanent identifier before you enrol.

The deepfake defence is already losing ground

Google’s answer to deepfakes is liveness detection. The head movements exist because current face-swapping tools handle a straight-on view far better than a profile.

That advantage is already dated. The attack that defeats it has become the dominant one. Injection attacks feed synthetic video straight into the camera pipeline, so the physical camera never captures anything. There is no screen glare and no bezel to spot, because no real scene existed.

iProov’s 2026 Threat Intelligence Report, published on 8 April 2026, recorded a 741% annual rise in injection attacks, and a 1,151% surge in attacks aimed at iOS devices in the second half of 2025 alone. “Generative AI is allowing attackers to industrialize digital impersonation at scale,” said Dr Andrew Newell, the company’s chief scientific officer.

Read that with one caveat. iProov sells liveness detection, so it has a commercial interest in the threat looking large. The direction of travel is corroborated elsewhere, including by Google building the defence in the first place.

Your face is enrolled once and cannot be reissued, so the system protecting it has to keep working against tools that do not exist yet.

Apple and Microsoft made a different choice

This is not an argument against face unlock. Millions of people use Face ID daily and are right to.

The difference is where the data sits. Apple’s Face ID processes recognition on the device, inside the Secure Enclave, rather than storing a facial image in the cloud. Microsoft’s Windows Hello works the same way, verifying on compatible hardware without centrally storing facial templates.

Google’s selfie video is stored on Google’s servers, because it has to be. A recovery method that only worked on a device you still hold would be useless the moment the device is gone. Server-side storage is a consequence of that design rather than carelessness. It still changes what a breach costs, because compromising an on-device system reaches one phone, while compromising a central store reaches everyone enrolled in it.

What the help page says and the blog does not

The announcement post tells you the video is encrypted, stored with your consent, and deletable whenever you like. Google’s Help Center page adds four things.

Deleting your selfie video means “you may lose access to some advanced features”. Google does not say which. Deletion is not immediate, and the video leaves your account after an unspecified period. If Google decides you have broken its policies, it may keep the video longer to enforce them, which turns a recovery credential into an enforcement record. And the stated purpose is wider than sign-in from the first day, covering confirmation that you are a real person rather than a bot, checks that you have not violated Google’s policies, and access to additional services and features.

Then there is the optional toggle. Submit a selfie and you can allow Google to use the video to develop and improve facial recognition, age estimation and other verification methods. It is off unless you switch it on. It also connects the clip you recorded to reach your inbox with the age estimation systems Google already runs commercially, a link PPC Land traced in detail.

What Kenyan law asks for, and where Google’s terms sit against it

In Kenya a video of your face is sensitive personal data under the Data Protection Act 2019, which carries tighter conditions than a name or a phone number.

The Office of the Data Protection Commissioner finalised its Guidance Note on Biometric Data in 2025. Consent must be freely given, with no negative consequences for anyone who refuses. Users must be able to withdraw consent “without loss of access to unrelated services”. A data protection impact assessment goes to the ODPC at least sixty days before biometric processing begins. Sending sensitive data out of Kenya needs informed consent plus confirmed safeguards under section 49 of the Act.

Google’s line about losing unnamed advanced features if you delete the video sits directly against the consent standard in that guidance. Until Google names the features, nobody can measure how far.

Kenya has a record on this too. In May 2025 the High Court ruled that Worldcoin’s collection of iris scans from Kenyans in 2023 was illegal and ordered the data deleted. We covered the ODPC’s biometric and age verification rules when they went out for comment. We have also reported on 2 million business records leaking from a government registry and on personal records selling online for as little as KES 50. Encryption at rest is a real control with a narrow scope. It describes storage. It says nothing about transit, nothing about processing, and nothing about who inside a company can decrypt a file.

The strongest argument for it, and where it stops

There is one genuinely good reason to want a recovery route that avoids your phone number.

In Kenya, account recovery leans on SMS, and SMS leans on a SIM anyone can steal. This month we reported on a High Court decision making Safaricom and DTB pay KES 4.42 million after a customer’s line was swapped and her bank account drained. Whoever holds your number holds your codes.

Selfie video does remove that failure. Recovery contacts and passkeys remove it too, without storing anything permanent. The SIM problem is an argument for dropping SMS recovery. It does not get you as far as biometrics, because two of the alternatives already close the same hole.

What to do

Selfie video is optional, and nothing on your account stops working if you skip it.

Open your Google Account, go to Security and sign-in, and do three things. Create a passkey. Add recovery contacts. Confirm your recovery email still works. Those three cover almost every lockout, cost you nothing permanent, and are the same steps Google recommends first.

If you still want the selfie option, set it up before you need it, because you cannot add it once you are locked out. Leave the “Improve Google services” toggle off. And go in knowing that deleting the clip later may cost you something Google has not been willing to name.

The checkable thing to watch is whether Google ever publishes the list of advanced features you forfeit by deleting your selfie video. Until it does, enrolling means accepting a cost that nobody outside Google can measure.

The Analyst

The Analyst delivers in-depth, data-driven insights on technology, industry trends, and digital innovation, breaking down complex topics for a clearer understanding. Reach out: Mail@Tech-ish.com

Join the discussion

0 comments
posting as Paa Mwoga

Anonymous by default — no sign-up or email needed. Prefer to be recognised? Add a name or email above, your call. We don't email you about replies, so do check back.

protected, no CAPTCHAs
Back to top button