Technology

You Can Now Unlock Your Google Account With a Selfie Video

Martin HollowayPublished 2w ago4 min readBased on 2 sources
Reading level
You Can Now Unlock Your Google Account With a Selfie Video

Google announced on July 23, 2026 that users can now sign in to their Google accounts using a selfie video. This adds a new option alongside existing methods like passwords, text message codes, and authenticator apps. The company detailed the feature in a blog post and TechCrunch reported on the announcement the same day.

Here is how it works. When you set up the feature, you look at your device's camera and follow on-screen prompts to turn your head right, then left, then nod. This captures a short video of your face from multiple angles. That video becomes the reference point Google uses later. If you ever get locked out of your account, you record a new selfie video. Google compares the new video to the one you recorded during setup. If they match, Google restores your access.

The guided head movements do two things. They capture your face from different angles, which makes matching more reliable. They also serve as a liveness check, meaning they help prove you are recording the video right now, in real time, rather than holding up a photo or playing a pre-recorded clip. Google states that the system uses multiple layers of security to defend against impersonation attempts, including fake photographs and deepfake videos — realistic, computer-generated footage of a person's face designed to look real.

Google also says the selfie videos are stored securely using encryption, which scrambles the data so it cannot be easily read, and that the videos remain protected when not actively in use. Users can delete their stored selfie videos from their Google account at any time.

The background here is that account security is currently split across several approaches that each solve different problems. Passkeys, which Apple, Google, and Microsoft support, aim to replace passwords by storing a digital key on your device. But passkeys do not help if you lose that device. Text message codes have become less reliable because criminals can trick phone companies into transferring your phone number to a device they control. Authenticator apps and physical security keys remain strong but create their own problems when devices are lost or tokens are misplaced.

Selfie-video sign-in is not meant to replace passwords or passkeys as your everyday way of logging in. It is a recovery pathway, meaning it exists for when you are locked out and need to prove you are who you say you are. The guided head movements during both setup and recovery are the mechanism Google has chosen to resist the most obvious tricks: static photos, replayed video, and AI-generated deepfakes.

One concern worth examining is the deepfake question. Google's blog post names deepfake videos as a threat the system is designed to resist, but the company has not published technical details about how it tells the difference between a real-time, AI-generated face and a genuine one. The competition between fake-face technology and detection tools has been intensifying for years. Any system that claims it can resist deepfakes without public, independent testing invites skepticism. Google's decision to name deepfakes explicitly in its announcement suggests the company knows this is the first question people will ask.

The privacy side also deserves a closer look. Storing biometric data, even encrypted, creates a tempting target. Google addresses this by emphasizing encryption and user-controlled deletion, but the available facts do not specify whether the video is processed entirely on your device or whether your facial data is sent to and stored on Google's servers. The difference matters. Apple's Face ID, for comparison, keeps facial data on the device itself and never sends it to a server. A system that stores biometric data on company servers, even with encryption, concentrates sensitive information in a way that a determined attacker might try to target. The blog post's language about videos being "stored securely using encryption" leans toward a server-side model, but the full architecture is not described.

In my view, the feature's real value is convenience when you are locked out, not extra security for everyday logins. Anyone who has watched a family member struggle through a multi-step recovery process — checking a backup email, waiting for a text that may never arrive, answering security questions set years ago — can see the appeal of a 10-second selfie video instead. The trade-off is that you are handing over biometric data, and how comfortable people feel about that will likely depend on how much they trust Google with sensitive personal information.

The feature is rolling out now, per Google's announcement. Users who want to try it can enroll through their Google account security settings, and those who do not can simply ignore it.

You Can Now Unlock Your Google Account With a Selfie Video | The Brief