On 24 July 2026, Google began rolling out a new way to sign in. You record a short video of yourself performing guided head movements. Google keeps the video, captures your face from multiple angles, and compares it against a live video of you the next time you try to get into your account. The feature reached Australian users from Friday. Google pitches it as a recovery option for people locked out of their accounts, with checks to catch deepfakes and impersonators.
Underneath the convenience framing, the largest advertising company on earth is asking you to hand over a stored, multi-angle biometric map of your face, and it will hold that recording for as long as you keep using the feature. Google says the video is used only for sign-in unless you opt into other uses. That last clause is doing a lot of work. Google's entire business is finding new uses for data it already holds, and the opt-in for those other uses will arrive inside a consent screen most people click through in seconds.
A password is a secret you can replace. When a database leaks, you rotate the credential and move on. A face is a credential you wear in public every day for the rest of your life, and it cannot be reissued. Once a high-fidelity, movement-verified recording of your face exists on someone else's server, every future breach, subpoena, and policy change applies to a biometric you can never take back. Google says you can delete the video at any time in your account settings. Deletion promises from companies that build products on retained data deserve exactly as much trust as their track record earns them.
For Australians, the rollout lands in the same month the eSafety Commissioner confirmed platforms are expected to run age checks on Australian users, and the government's Age Assurance Technology Trial promoted face scanning as a compliance tool. Every product like this trains people that pointing a camera at your face is a normal toll for using the internet. The under-16 ban makes face checks a legal expectation. Google makes them a habit.
Account recovery is the moment users are most desperate and least likely to weigh a privacy trade. Locked out of a decade of email, photos, and documents, almost anyone will record almost anything. Google put the face video there deliberately, as the rope at the bottom of a well that Google dug.
You do not have to take the deal. Strong unique passwords, hardware keys or TOTP two-factor, and printed backup codes recover accounts without donating your face. All of those credentials share the property that matters. When they leak, you can replace them.
Blackout VPN exists because privacy is a right. Your first name is too much information for us.
Keep learning
FAQ
What is Google's selfie video sign-in?
An account sign-in and recovery option where you record a short video performing guided head movements. Google stores the video and compares it against a live video of you at future login attempts.
Is the face video mandatory?
No. It is opt-in, and Google says the video can be deleted at any time in account settings. Passwords, hardware keys, TOTP codes, and printed backup codes still work for recovery.
Why is a stored face video riskier than a password?
A leaked password can be changed in seconds. A leaked biometric is permanent. Your face identifies you in every camera feed for the rest of your life and cannot be reissued.
Does Google use the video for anything besides sign-in?
Google says it is used only for sign-in unless you opt into other uses. That opt-in is a policy promise, not a technical limit, and it can change.
What should I use instead for account recovery?
A password manager with strong unique passwords, hardware security keys or TOTP two-factor, and printed backup codes stored offline. All are replaceable if compromised.
