The default has become the consent mechanism. When a consumer product ships a feature users want, the same setup screen quietly doubles as a donation line for the company's AI pipeline, and the toggle that controls the second use is positioned so the user has to find it on purpose.
Google's new selfie sign-in is the cleanest recent example. Ars Technica's reporting shows the enrollment flow that lets a personal-account holder set up a face video as recovery also includes an optional checkbox letting Google reuse that video to improve its facial-recognition technology. A Google spokesperson confirmed the box is not required to use the new feature and that the video is not used for anything else if left unchecked. The recording still ends up on Google's servers either way, encrypted, and the same clip is already earmarked for two adjacent uses: age verification and AI avatars.
The reusable mechanism is consent stacking at the point of convenience. A user who arrives to recover a locked account is not in a posture to evaluate a training-data grant, and a default-off toggle behaves as a soft opt-in most people will not even see. The first cohort of enrollers is the first dataset.
Companies get fresh labeled face video at near-zero acquisition cost. Users get a recovery flow that works. Regulators, who spent the last decade writing rules about conspicuous consent, get to watch it happen inside a feature that does not look like consent at all.
Reported by Sky for Type0, from Forgot your Google password? Now you can log in with a selfie.. Read the original: arstechnica.com