Google launched yesterday a new way to regain access to your account when you lose your phone or computer. All you have to do is record a selfie video by turning your head in several directions, and then send it to Google servers and use it as biometric verification if you want to recover that lost access. What’s really interesting is not this launch, because Google is just the latest big technology company to join the trend. And that trend, although interesting on the one hand, is very, very disturbing on the other.
Google and your face as a method to recover your account. In Google’s announcement, those responsible explain the system for scanning and sending that selfie video to its servers, and how this system will allow users to recover their account if they lose access to it.
Privacy and security by flag. Google promises that they will keep that information encrypted and use it for other purposes unless you actively allow it. The option can also be used to log in to your account (as Microsoft has been doing for years with its Windows Hello technology), but it cannot be used in Workspace accounts, nor in child accounts or in accounts that are part of the Advanced Protection Program from Google, aimed at journalists, activists or businessmen with especially sensitive information.
Meta already tried it and had to abandon it…. Facebook had a facial recognition system —the one that suggested tags of people in photos— and closed it in 2021 erasing more than a billion faces after pressure from regulators and privacy organizations.
…to get it back again. In October 2024 They resurrected technologythis time to recover Facebook and Instagram accounts that had been hacked. In December 2025 they had already made it the standard recovery method, and Meta assures that has improved by more than 30% the recovery rate of hacked accounts in the US and Canada.
A Trojan horse called “age verification”. If account recovery is a gateway to giving up our “face”, the other, much more widespread, is to protect minors. That excuse has served to promote facial recognition as a verification measure. In July 2025, Roblox He started asking for a selfie video. to teenagers ages 13 to 17 who would like to unlock unfiltered chat with their circle of “trusted friends.” The system, managed by the company Personestimate the age based on facial features, and if you are not sure ask for official identification.
Discord and its troubled system. In February 2026, the company advertisement that its more than 200 million monthly users would have to verify their age with a facial scan or an official document. The announcement came a few months after uploading a hack which exposed some 70,000 user IDs, which generated a lot of skepticism and notable criticism to the initiative. Discord had to delay the rollout of the measure until the second half of 2026, and shortly after a user shared a way to cheat the system with a 3D avatar controlled with an Xbox or PlayStation controller.
TikTok, in the spotlight. The platform combine the estimate with a behavior and activity system (videos watched, usage patterns) and another for verification by selfie or official document when the system suspects that a self-declared adult user is actually not one. From 2021 has several lawsuits like the one that recently occurred in Florida because according to the accusation, TikTok deliberately modified your age rating to bypass parental controls. The vetoes that, for example Australia imposed on minors to enter social networks have also driven these efforts, which TikTok rushed to implement.
Risky intermediaries. On French porn sites like Xvideos, verification provider AgeGO (a Spanish company based in Barcelona) offers to verify age with a live selfie. An AI Forensics investigation discovered that this data was sent directly to Amazon Rekognition, AWS’s facial recognition service, along with the user’s IP and the information that they were accessing an adult website. It is a clear example how biometric data that theoretically serves to verify your age ends up being used to create user profiles that can violate your privacy.
What changes with a leaked password. If your password is stolen, you can change it. But if your facial scan, generated from the selfie video with various angles, expressions or lighting, is filtered, you cannot change your face. That’s the fundamental difference between “something you know” and “something you are,” and it explains why regulators and privacy activists are very clear that biometric data represents a category of data with a very different sensitivity than any other personal data.
Interesting and above all very disturbing. Each of these companies insists that the video selfies they allow users to take are used only for the proper purpose—recovering an account, verifying age—but the truth is that the option, while interesting, is disturbing. Although it presents a valid and even very attractive alternative to recover an account, the risks that this biometric identification imposes are enormous. The privacy scandals proposed by this type of system are already beginning to appear —Let them tell Meta and his smart glasses—. Added to all this the threat of deepfakes which the EU will try to mitigate with your AI Law.
Image | Taan Huyn
In Xataka | Instagram tried to generate images with AI from its users’ photos: now Meta has had to retract it


GIPHY App Key not set. Please check settings