Google is betting that the answer to deepfake-era identity is motion. On July 23 it rolled out a selfie-video verification option for Google Accounts — a way for locked-out users to prove they're both the right person and a live one.

How it works

Users record a reference selfie video in advance, following guided head movements that capture the face from multiple angles. At recovery time, they record a fresh video with the same guided movements, and Google compares the two. Crucially, setup must happen before a lockout — it can't be added after.

Built against deepfakes

The choreographed movements are explicit liveness checks: Google says the system uses "multiple layers of security" to fend off impersonation via AI-generated photos and videos. A static deepfake — or a replayed clip — shouldn't satisfy prompts issued in real time.

The privacy terms

The reference video is stored encrypted in the account and can be deleted anytime. By default it's used only for sign-in — though an optional, revocable setting lets Google use it to improve facial recognition and age estimation.

Who's excluded

Not available for Workspace accounts, child accounts, or Advanced Protection Program enrollees, and it requires a camera-equipped mobile device; regional availability varies after earlier testing in Brazil. Selfie video is positioned as a fallback for when passkeys, backup codes and trusted devices aren't available — not a replacement for them.

The bigger picture

Account recovery has long been security's soft underbelly: it is the flow attackers target precisely because it bypasses passwords and two-factor checks. Google is wagering that verified liveness beats security questions in a world where anyone's face can be copied — and at billion-account scale, that wager becomes the industry default.