Skip to main content
CybersecurityPrivacy & Surveillance

AI Actress Tilly Norwood Service Mandates Face Scan

Smartphone screen prompts face scan with blurred background of person in daylight setting.

A clip viewed more than eight million times showed AI actress Tilly Norwood glitching mid-interview and unexpectedly begin speaking Chinese on the Piers Morgan Uncensored show, and the character behind that moment is now asking callers everywhere to submit to a face scan before saying hello.

How Xicoia and Didit gate access with an age check

The Talking Tilly service, run by UK company Xicoia Ltd, requires an automated age check before your first call connects. A video selfie is analysed by Didit, a Spain-based identity verification provider, to estimate age; a government photo ID upload acts as a fallback if the estimate is unclear. Xicoia states the selfie travels from your device directly to Didit, that no faceprint or biometric template is created, and that neither the selfie nor any ID image is kept after the check. The company says it retains an approximate age band and a reference number instead.

The check cannot be skipped, applies to callers worldwide, and was only added to the service’s terms this month alongside a workplace-use ban and new automated safety systems. Xicoia’s version history shows the legal basis for both the age check and the mood-sensing was changed to legitimate interests in September.

Real‑time emotion sensing, recording, and third‑party processing

During every call, the system watches your camera feed and listens to your tone of voice to infer your emotional state so the character can “respond in a way that fits the mood.” The privacy policy is candid that this “cannot be switched off for an individual call.” Calls are recorded, transcribed, and processed live by US providers, and the character’s responses are generated by Google’s Gemini model via conversational video platform Tavus.

An automated classifier screens each call’s transcript for abusive language and withholds recordings if the classifier flags them; the policy says a human reviewer can release wrongly flagged recordings. The author’s test of three calls found one conversation — about weather and headlines — withheld for “hateful or abusive language” that never occurred. Recordings are permanently deleted after 24 hours either way, while transcripts are retained for up to eight weeks. The character also keeps memory of previous conversations to personalise future ones; those memories are deletable on request.

Pricing, the looming shutdown, and the clock on minutes

Talk time is free for the first five minutes. After that, callers are prompted to buy time: £0.99 for a one-time five-minute starter, £13 for 15 minutes, £22 for 30 minutes, capped at 35 purchased minutes per person. Every minute, free or paid, expires when Talking Tilly shuts down permanently on September 27 at 11:59 PM Pacific, and unused minutes are forfeited.

How UK rules help explain a global face‑scan

An 18+ face scan to talk to a chatbot may feel novel, but Xicoia’s compliance decision aligns with recent UK regulation. Adult sites serving UK visitors have required ID uploads or facial age estimation since July 2025 under the Online Safety Act, and the UK government’s announcement of an under‑16 social media ban for new accounts from spring 2027 specifically flagged AI companion chatbots for 18+ enforcement. Although the service’s safety documents insist “Tilly is not a companion,” that regulatory framing likely explains why a viral AI character picked up a biometric age gate mid-run — a decision that now face‑scans callers everywhere, “from Manchester to Ohio.”

What this means for callers, UK regulators, and technologists

  • Callers and the general public: be aware that Talking Tilly watches your camera and listens to your voice for mood inference that “cannot be switched off,” that calls are recorded and processed by US providers, and that purchased minutes will vanish when the service shuts down on September 27.
  • UK regulators and policymakers: the Xicoia case shows how UK rules intended to protect minors can push services to introduce biometric age gates that have global reach, including for services that do not identify as companions.
  • Technologists and security teams: the deployment combines third‑party ID verification (Didit), US-based live processing, and generative responses from Gemini via Tavus — and it demonstrates the operational limits of automated safety systems when a transcript classifier wrongly withholds legitimate recordings.

Xicoia’s founder, Eline van der Velden, describes Tilly as an awareness project intended to show how far AI video has come. Whether last night’s slip was truly accidental, as Tilly cheerfully claimed during a call, or a well-timed stunt from the Misaligned crew is known to Tilly alone. The viral moment has become a live test of biometric age gates, automated mood sensing, and safety review systems — all set to expire when Talking Tilly goes offline in nine days.

Original story at BleepingComputer