Not to mention that if this catches on, ever more parties (that you authenticate with) will be collecting these biometrics, which means there would be an ever greater chance of that data getting used to impersonate you.
To avoid this they would have to keep it on the device, in a secure enclave, in "hashed" form rather than the raw biometric, and only transmit the fact of authentication to Google, much as how Apple deals with Touch ID on the iPhone.
We all know Eric Schmidt's view on privacy:
"If you have something that you don't want anyone to know, maybe you shouldn't be doing it in the first place. If you really need that kind of privacy, the reality is that search engines -- including Google -- do retain this information for some time and it's important, for example, that we are all subject in the United States to the Patriot Act and it is possible that all that information could be made available to the authorities."
"We know where you are. We know where you’ve been. We can more or less know what you’re thinking about.”
“Your digital identity will live forever… because there’s no delete button.”