With the machine learning, I am wondering if Apple will add a learning threshold to the device to help satisfy the requirements for Banks and such. I would imagine that as it learns the face, it will be harder to spoof. It would be nice if the user could manually speed up this process by doing a detailed retrain process.
As a rule, I am liking FaceID really well. I LOVE being able to interact with my device without having to pick it up. It is a great device to have in my kitchen. If the device locks, a quick "hey Siri" gets me back to my webpage or recipe without me having to touch the device, or, put my face near my camera for an iris scan.