How Google's selfie login works, and how safe it actually is

Google has introduced a new feature that expands how people can access their accounts: some users can now log in with a short selfie video instead of a password. The same biometric data can also be used for age verification and to generate AI avatars.
The feature is built on facial recognition technology, but Google's approach differs from traditional face-unlock systems in that it requests a brief video stream rather than a single static photo. The video format is meant to make it harder to fool the system with a fake photo or screenshot; the system performs liveness detection to confirm a real, live face is in front of the camera.
Beyond login, the same selfie video can be used to estimate a user's age. This is offered as a way to verify age without uploading an ID document, at a time when age-based content restrictions are becoming increasingly common.
The feature's third use case is generating AI avatars: a user's facial features can be used as the basis for producing personalised digital characters usable across various apps.
What all three uses have in common is that they rely on sensitive biometric data. Passwords can be changed; a person's face cannot, which means a leak or misuse of facial data carries a risk that is far harder to undo.
Google says this data is processed on-device and is not sent to the company's servers as raw video footage; instead, a mathematical representation of the face — a biometric template — is generated and used for comparison. This approach is standard practice in many modern facial recognition systems.
Privacy experts acknowledge that such systems can be designed to be technically secure, but say the real concern is scope creep over time. A feature introduced for a narrow purpose can later be repurposed by companies to serve other products using the same underlying data.
From a security standpoint, the advantage of selfie login is a smoother user experience compared with forgotten or stolen passwords. But experts caution that biometric systems aren't foolproof either — advanced AI-generated imagery, or deepfakes, can fool some liveness-detection systems.
For regulators, the spread of facial recognition technology raises fresh questions around biometric data collection, retention periods and sharing with third parties; some jurisdictions already require explicit consent and strict retention rules for this kind of data.
The practical advice for users is to review privacy settings — showing what data is collected, where it's stored and what purposes it may be used for — before enabling features like this. Selfie login can be convenient, but every biometric convenience comes with a different privacy trade-off attached.
Read next

Why writing by hand is still better for your brain than typing
Keyboards and touchscreens dominate everyday writing, but a growing body of research shows that putting pen to paper engages the brain differently — and more deeply — than typing does. Here's why that difference emerges, and when it actually matters.

What is negative cash flow, and why did Google just post its first one
Google continues to report record quarterly revenue, but its spending on AI infrastructure has ballooned so sharply that the company posted negative free cash flow for the first time in its history. Here's what cash flow actually measures, and why it matters even for a hugely profitable company.

US warns Iran-linked hackers are targeting water and energy providers
An updated US government advisory warns that Iranian-linked hackers are exploiting systems used by water and energy providers, urging critical infrastructure operators to tighten their defences against the ongoing intrusions.

AMD's Helios rack-scale system takes direct aim at Nvidia's AI dominance
AMD is challenging its chipmaker rival Nvidia with Helios, a new rack-scale AI system that will begin shipping to customers later this year. The launch intensifies competition in the market for infrastructure built to train and run large AI models.

Science Corporation's vision-restoring chip wins EU approval
Science Corporation, the biotech startup founded by former Neuralink president Max Hodak, has won European regulatory approval for a retinal implant designed to restore partial vision to people blinded by age-related macular degeneration. The approval marks a milestone for a company still working to prove a viable business around implantable neurotechnology.