Is a selfie a safe key to your business Google account?

· Carl Heaton · Security

If your business runs on Google Workspace, and many do, a change Google announced this week quietly puts a decision on your desk. From now on, staff can record a short video of their face and use it as a backup way back into a locked-out account. It sounds convenient, and for a genuine problem it might be. It also means a recording of someone's face can, in the right circumstances, unlock the company's email, documents, and drive. That is worth thinking about before anyone enables it.

What Google has actually launched

Google now offers "selfie for sign-in" as a recovery method. You enrol by recording a short video, moving your head side to side, which captures your face from more than one angle. Later, if you are locked out and cannot use your usual password, phone, or email recovery, Google can ask you to record a fresh video and compares it against the enrolled one to let you back in.

It is deliberately a last resort, not an everyday login. Google's own framing is that it is for the moment you have lost the phone or device that normally signs you in. It is not the same as Face ID on an iPhone or face unlock on Android, and Google was explicit about that difference when The Register pressed it. Phone face unlock uses special depth-sensing cameras that build a three-dimensional map of your face. Selfie sign-in uses ordinary video and artificial intelligence to judge whether the face matches. The side-to-side head movement is there to trip up fake videos, which struggle to render a convincing profile view in real time.

The problem it solves is real. As businesses move to passkeys and other device-based logins, which are genuinely more secure, losing the device increasingly means losing the account. A recovery route that does not depend on a specific phone is a sensible answer to that. The question is whether this is the right one for your business.

Where it is weaker than it sounds

Three things are worth weighing before you decide.

It leans on deepfakes staying imperfect. The whole defence rests on fake video being unable to fake a turning head convincingly. Fake video is improving quickly, and the side-view trick is a speed bump, not a wall. Ordinary facial recognition is famously unreliable, and Google itself acknowledges that a selfie alone may not always be enough, and that it weighs other risk signals before letting anyone in. That hedging is honest, and it also tells you the method is probabilistic, not a hard lock.

You are handing Google a recording of a face. Enrolling means giving Google a video of a colleague's face, held on Google's systems. Google says the recordings are encrypted, stored only with consent, and used only for sign-in unless the user opts to share them further. For a business, "a member of staff agreed to give a supplier biometric data to do their job" is still a data-protection question worth asking, not a technicality. Biometric data is treated as a special category under UK data protection law, and it is the individual's face, not the company's, to consent over.

It is another door into the same room. Every recovery method you add is another way in, for the legitimate user and for anyone who can imitate them. A recovery route is only as strong as its weakest path, and adding a face-video path means that path now exists whether or not anyone uses it deliberately.

How to decide

This is a governance call, not a technical one, and it fits the questions a sensible business already asks about its systems.

Decide it deliberately, do not let it drift in. The safe default for a business account is to leave a new recovery method off until you have decided you want it, rather than letting staff switch it on ad hoc. Make it a conscious choice, the same way you would with any new way of accessing company data.

Ask your IT provider or administrator two questions. First: can we control, centrally, whether staff can enable this on their work accounts? For Google Workspace, recovery options are often something an administrator can manage rather than leave to each person. Second: what is our current recovery story if someone loses their phone, and is it good enough without this? If the honest answer is that a lost phone locks people out for days, that is the real problem to fix, and a face video is only one possible fix.

If you do allow it, treat the face like the password it now is. A recording that can unlock an account deserves the same care as any other key. That means being clear with staff about what they are consenting to, keeping it optional and personal, and making sure it sits behind Google's other risk checks rather than becoming a single easy route in.

For most businesses the sensible position is calm and specific: this is aimed at a real problem, it is not a disaster, and it is also not something to enable across the company on the strength of a convenient announcement. Understand your recovery gap first, then decide whether this fills it.

How Steelwise can help

Deciding which login and recovery options your business should turn on, turn off, or leave to staff, and getting that written down so it is a policy rather than a habit, is the kind of review we do. Get in touch.

Further reading

← All filings