To Fix a Deepfake, YouTube Wants Your Face. That's the Trap.
YouTube's new likeness detection tool promises to shield creators from deepfakes — but using it means submitting your face to a platform with every incentive to find that data useful.

The pitch is reasonable enough, maybe even generous. Someone is using your face without your consent — your voice, your mannerisms, your name — to make videos you never recorded. The platform where those videos live is offering you a tool to find them and take them down. All you have to do is give the platform a biometric reference sample of your actual face. To fight the fake, hand over the real. Most people, understandably alarmed by the first problem, may not slow down long enough to examine the second.
YouTube's likeness detection system, reported by CNBC in late 2025[4], is framed as a creator protection feature. The mechanics work roughly like this: a creator submits reference data — biometric information derived from their face or voice — and YouTube's systems scan for unauthorized synthetic reproductions of that likeness across the platform. Matches get flagged. The creator can request removal. The problem, from a structural standpoint, is not the goal. Protecting people from nonconsensual deepfakes is a legitimate and urgent aim. The problem is what the solution requires, and who benefits from the exchange.
Deepfake harm is real and it is already distributed unevenly. Creators with large audiences, most of them women, face a disproportionate burden of nonconsensual synthetic content[2] — face-swapped into explicit material, voice-cloned for scams, likenessed into fake endorsements. The psychological damage is documented. The reputational damage is sometimes unrecoverable. A platform tool that helps address this is not inherently suspect. But the specific architecture of this tool — biometric data flowing to a company that operates AI systems at massive scale, under terms of service that have historically expanded over time — deserves a closer look than the headline protection promise usually gets.
What YouTube is building is, at its core, a biometric database of its most prominent creators. That is not a conspiratorial reading of the feature. It is a structural description of what the system produces. Whether that database is ever used for anything other than deepfake detection depends entirely on policy commitments that can change, legal environments that vary by jurisdiction, and corporate incentives that have a consistent historical direction — which is toward finding new uses for data that already exists.
The Asymmetry Built Into the Tool
There is an asymmetry at the center of this feature that rarely surfaces in the coverage celebrating it. The creator who submits biometric data receives a specific benefit: better detection of fake versions of themselves. YouTube receives something more general and more durable: a biometric reference tied to a real identity, stored in its systems, usable across whatever future applications its policies permit. The creator's benefit is bounded by the current problem. YouTube's benefit is bounded primarily by its own future choices.
This asymmetry is not unique to YouTube. It is the standard grammar of platform data collection. A service offers a concrete value — navigation, connection, personalization, now protection — in exchange for data that is far more multivalent than the stated use case. The concrete value is real. The data exchange, because it is framed as a condition of the feature rather than as a separate transaction, tends to receive less deliberation than it deserves. Facial biometrics are categorically different from browsing history or watch time. They are permanent. They cannot be changed if a policy shifts or a breach occurs. Once a reference model of your face exists in a system, the question of what that model might do over time is not paranoia. It is the right question.
“Facial biometrics are permanent — you cannot change your face the way you can change a password.”
Experts in biometric privacy have consistently flagged this architecture. The concern is not that YouTube has announced malicious intent — it has not. The concern is that biometric systems tend to expand. Reference data collected for narrow detection purposes has a history, across industries, of being repurposed for authentication, advertising personalization, behavioral research, or licensing to third parties. The legal frameworks governing biometric data in the United States remain patchwork: Illinois has the Biometric Information Privacy Act[1], which has teeth; most other states have considerably less. Internationally, the picture is similarly uneven. What YouTube is permitted to do with the data it collects depends heavily on where a creator is located, and creators are distributed across nearly every regulatory environment on earth.
What Consent Looks Like When There Is No Good Alternative
Consent frameworks tend to break down when the alternative to consenting is harm. A creator already being targeted by deepfake content faces a real and immediate injury. The platform offering relief is also the platform that has been hosting the injurious content. The opt-in to the detection tool is, in that context, less a free choice than a coerced exchange — you absorb one risk to mitigate another, and the entity managing both risks is the same entity that profits from your presence on the platform regardless.
This is not a hypothetical dynamic. It is the situation many creators already find themselves in. The deepfake ecosystem — synthetic voices used in scam ads, face-swapped explicit content, AI-generated videos impersonating real people for financial fraud — is running on infrastructure that platforms profit from in the form of engagement and advertising revenue, even when the platform has not sanctioned the specific content. YouTube did not create the deepfake problem, but it is a primary surface on which the deepfake problem lives. Offering a biometric detection tool as the solution, while holding the biometric data that solution requires, is a tidy arrangement from YouTube's perspective. From the creator's perspective, it is a choice between two kinds of exposure.
“The entity managing both risks — the deepfakes and the data — is the same entity that profits from your presence on the platform either way.”
There is also a coverage gap problem. The creators most targeted by nonconsensual synthetic content — those with the most urgent need for the tool — are often those with the least institutional support for evaluating its terms. Independent creators, freelancers, smaller-audience educators, journalists, and activists who have ended up with public profiles do not have legal teams reviewing the data collection conditions. They have a help page and a checkbox. The asymmetry of access to legal interpretation compounds the asymmetry of the data exchange itself.
The Training Data Question Nobody Is Answering
There is a question that sits beneath the surface of the detection feature and rarely appears in the product announcement language: what happens to biometric reference data when it is used to train or refine the detection model itself? Machine learning systems that identify synthetic faces need real faces to learn from. A biometric reference submitted by a creator for detection purposes is, technically, an extraordinarily clean training signal — a verified, consented-by-policy, labeled example of what a specific real face looks like. The gap between using that data to detect fakes and using it to improve the systems that process faces generally is not always as wide as product teams imply.
YouTube's parent company, Google, operates some of the most sophisticated AI image and video systems in the world. Those systems require training data. The company has faced scrutiny before over how user-generated content and behavioral data feed into AI development. The specific question of whether creator-submitted biometric reference data could be used, in aggregate or derivative form, to improve synthetic media detection models — which are adjacent to the synthetic media generation models — is one that the product documentation for these features tends to answer vaguely or not at all. The absence of a clear answer is its own kind of answer.
This is not to claim that YouTube intends to use creator face data to train generative models. There is no evidence of that specific plan. The point is structural: the data, once collected at scale, exists in an environment where the incentives to find new uses for it are strong and the external constraints on doing so are uneven. The history of platform data practices is not a history of data sitting inert in a database, used only for its original stated purpose, until quietly deleted. It is a history of scope creep, policy revision, and the gradual normalization of uses that would have seemed alarming at the point of collection.
What a Better Architecture Would Look Like
The critique of this tool is not an argument against deepfake protection. It is an argument about where the detection infrastructure should live and who should control it. There are alternative architectures that would provide similar protection without requiring creators to hand biometric data to the platform. Cryptographic signing systems, for instance, can establish content provenance — whether a video is genuinely associated with a creator — without requiring the platform to hold a biometric reference. Decentralized identity frameworks could allow creators to verify their likeness through a third-party attestation system rather than through a direct submission to YouTube. Coalition-based protection systems, operated by creator guilds or independent trusts, could hold biometric references in escrow with cleaner legal protections and less conflict of interest.
None of these alternatives are as frictionless as submitting your face directly to the platform that already has your channel, your analytics, your tax information, and your audience data. That is precisely the problem. Platforms consistently win on convenience. The path of least resistance in a crisis — someone is faking you, here is a button to stop it — will always attract the majority of affected creators, regardless of what the finer terms say. The architecture that is easiest to use is the architecture that gets built. And the architecture that gets built is the one that most efficiently serves the platform's longer-term interests, which are not identical to the creator's.
“Platforms consistently win on convenience — and the path of least resistance in a crisis is the one most people take without reading what it costs.”
The Habit This Installs
There is a behavioral shift happening beneath the surface of this particular feature, and it is worth naming. We are in an early period of negotiating what it means to have a digital identity in an environment saturated with synthetic media. The norms being established now — about what platforms can ask for, what creators are willing to give, what counts as a reasonable exchange for protection — will shape the regulatory and cultural landscape for years. If the default behavior that gets established is that creators submit biometric data to platforms in exchange for identity protection, that behavior will be difficult to reverse. It will normalize a relationship in which the platform is the custodian of your biological face, and in which the cost of not cooperating is exposure to synthetic harm.
This is the deeper concern with YouTube's likeness detection tool — not that it is a scam, not that it will definitely be abused, but that it is establishing a precedent under conditions of urgency and limited alternatives. Deepfake harm is real enough that creators cannot wait for a better architecture that may arrive too slowly. YouTube is large enough and well-resourced enough to offer the only tool most creators will ever realistically use. The combination of genuine harm, limited alternatives, and a well-designed frictionless interface is precisely the set of conditions under which consequential habits get quietly installed. By the time the full implications are visible, the behavior is already ordinary, the data is already collected, and the debate about whether it was a good idea feels academic.
References
- Biometric Information Privacy Act (ilga.gov)
Establishes Illinois's Biometric Information Privacy Act as an example of state-level biometric regulation with enforcement power. - When non-consensual intimate deepfakes go viral: The insufficiency of the UK Online Safety Act (sciencedirect.com)
Documents that women creators face disproportionate burden of nonconsensual synthetic content, including face-swapping into explicit material. - European Commission investigates Google’s AI training processes (computerworld.com)
Documents European Commission antitrust investigation into Google's use of web publisher and YouTube content to train AI models. - YouTube's new AI deepfake tracking tool is alarming experts and creators (cnbc.com)
Reports that YouTube's biometric tool allows Google to train AI models on creator data, and YouTube's statement that it will not change underlying policy despite concerns.
About Julian Cross
Julian Cross writes about AI, automation, surveillance, digital identity, labor, human relationships with each other and automation, complex systems and attention — less about what new tools, studies and observations can do in theory than what they're already doing to how we work, spend, relate, and get measured. His work follows leads to the point where it stops being a product and starts being a condition.
More like this

Your Mouse Movements Are Setting Your Price. The FTC Just Confirmed It.
A federal market study confirmed what companies wouldn't say out loud: your browsing behavior, down to cursor hesitation and abandoned carts, is being used to charge you a price nobody else sees.

The Algorithm Knows You're Browsing Aimlessly. That's When It Owns You.
Researchers have a name for what happens to your judgment the moment you open an app without a goal — and it turns out platforms have been quietly engineering for it.

Your Employer Is Training Its Replacement on Your Keystrokes
Workplace monitoring has quietly shifted from measuring performance to harvesting the behavioral data needed to automate the people being measured — and most workers have no idea which side of that line they're on.