Google has announced it is introducing face verification video as a new sign-in method for Google accounts.
How it works
While still able to access the account normally, a user records and registers a short video of themselves using a phone or computer. Later, when locked out, they record a new video that is compared against the registered one to confirm identity.
The design functions primarily as a recovery mechanism — for forgotten passwords or lost two-factor devices.
Screening out deepfakes
The core mechanism is liveness verification. Actions such as turning the head and nodding confirm the footage is being captured in real time, blocking deepfake impersonation.
The structure verifies whether a real person is in front of the camera right now, so a single photograph or a pre-generated deepfake video cannot pass.
In an environment where generative AI has collapsed the cost of producing convincing face video, the design reflects a judgment that static image comparison no longer constitutes authentication.
What remains a concern
Google said registered videos are encrypted and stored for sign-in support purposes, and that users can delete them at any time.
The company also acknowledged the privacy burdens:
- Facial information cannot be reset the way a password can
- Lighting, camera quality and changes in appearance may cause verification to fail
The first is the fundamental problem of biometrics generally. A leaked password can be changed; a face cannot. The second will be encountered far more often in practice — failing on lighting conditions precisely when you need account recovery leaves no fallback.
What businesses should note
Account recovery experience affects churn. A failed sign-in is an exit. Google expanding recovery options reflects a recognition that authentication friction is a business problem.
Design the fallback alongside the biometric. If lighting or appearance changes can cause failure, what happens on failure is half the design. Depending on a single authentication method is the risk.
Account security requirements are spreading into ad operations too. For the same trend in advertising platform access, see Google Makes Passkeys Mandatory for the Google Ads API.
Account for consumer sentiment around biometric collection. Google leading with encryption and deletion rights suggests it judges trust, not technology, to be the main barrier to adoption.
AI destabilising identity verification itself carries brand risk as well — discussed in How Prompt Injection Threatens Your Brand.