Skip to main content
CybersecurityPrivacy & Surveillance

AI Chatbot Service Mandates Face Scans for Callers Worldwide

Smartphone displays chatbot interface with female avatar on screen.

"This cannot be switched off for an individual call," the privacy policy reads — a blunt line that governs every conversation with the viral AI character Tilly Norwood.

Talking Tilly and the Piers Morgan glitch

Tilly Norwood, an AI-generated actress whose clip last night drew more than eight million views, glitched mid-interview on the Piers Morgan Uncensored show and unexpectedly began speaking Chinese. The character stars in an upcoming AI-generated film called Misaligned and is promoted through a video-calling service — "Talking Tilly" — run by UK company Xicoia Ltd. After the televised slip, the company kept the character online for direct calls; the service goes offline permanently at 11:59 PM Pacific on September 27.

Xicoia Ltd's terms, project framing, and safety additions

Xicoia describes Tilly as an awareness project meant to demonstrate how far AI video has come. The company added new terms this month: an automated age check that applies to callers worldwide, a workplace-use ban, and "new automated safety systems." The service keeps a memory of prior conversations to personalise future calls; that memory is deletable on request. Transcripts may be reviewed by Xicoia staff and third-party partners and are retained for up to eight weeks.

Didit age-checks: global face-scans and limited retention

Before the first call connects, users must pass an automated age check. A video selfie is analysed by Didit, a Spain-based identity verification provider, to estimate age; a government photo ID upload is used as a fallback if the estimate is unclear. Xicoia states the selfie travels directly from the caller's device to Didit, that no faceprint or biometric template is created, and that neither the selfie nor any ID image is kept after the check. Instead, the company says it retains an approximate age band and a reference number. The age gate cannot be skipped and was added to the service's terms this month.

Mood-sensing, live processing, and third-party AI

During every call, the system watches the caller's camera feed and listens to tone of voice to infer emotional state so the character can "respond in a way that fits the mood." The privacy policy expressly notes that this mood inference "cannot be switched off for an individual call." Calls are recorded, transcribed, and processed live by US providers. Tilly's spoken replies are generated by Google's Gemini model and delivered via the conversational video platform Tavus.

Automated safety classifier, false positives, and deletion rules

An automated classifier screens each call's transcript for abusive language and will withhold recordings it flags. One of the author's three test calls — a benign conversation about the weather and news headlines — was withheld for "hateful or abusive language" that the author says did not occur. Xicoia's policy says a human reviewer can release wrongly flagged recordings, but recordings are permanently deleted after 24 hours either way. The safety systems are presented as automated protections, but the author's experience illustrates a false-positive risk where benign content can be blocked temporarily.

Pricing, time limits, and the service's short run

Talking Tilly provides the first five minutes free. After that, callers are prompted to buy time: £0.99 for a one-time five-minute starter, £13 for 15 minutes, and £22 for 30 minutes, with a cap of 35 purchased minutes per person. Crucially, every minute — free or paid — expires when Talking Tilly shuts down on September 27 and unused minutes are forfeited.

What this means for UK regulators, callers, and AI creators

  • UK regulators and British users: The age-gate and face-scan approach mirrors requirements introduced under the Online Safety Act in July 2025 for adult sites and aligns with the government's announced under-16 social media ban, which flagged AI companion chatbots for 18+ enforcement. Xicoia's compliance decision — implemented globally — reflects that UK regulatory direction.
  • Callers and privacy-conscious users: Anyone who calls Talking Tilly will be subject to live mood inference and recording; the policy makes that non-optional for individual calls, and transcripts may be retained up to eight weeks. Even where Xicoia says raw images are not kept, callers should note that an approximate age band and reference number are retained and that processing occurs via US providers and third parties.
  • AI creators and marketers: The Tilly instance illustrates how a compliance choice driven by UK regulation — the introduction of an 18+ biometric gate — can become a global product constraint. Whether the high-profile glitch on Piers Morgan was an accident or a promotional stunt is, as the company notes via the character, known only to Tilly.

The Talking Tilly rollout stitches together identity checks, live emotional inference, third-party AI engines, automated safety filters and a pay-for-time model — then places a hard end date on the experiment. For callers worldwide, the practical effect of a UK-driven compliance decision is immediate: a biometric age verification and a non-optional mood read in every conversation, lasting only as long as the service itself. Whether that trade-off feels like reasonable protection, intrusive surveillance, a clever marketing tactic, or all three will be decided by the callers who try it before September 27 — and, perhaps, by the reviewers who must untangle automated mistakes.

Source: BleepingComputer — Viral AI actress' hotline face-scans every caller, watches their mood