LmCast :: Stay tuned in

Calling viral AI actress Tilly Norwood? Agree to a face scan first

Recorded: Sept. 19, 2026, 12:08 p.m.

Original Summarized

Calling viral AI actress Tilly Norwood? Agree to a face scan first

News

Featured
Latest

OpenAI details more cases of AI agents taking unauthorized actions

Brevo supply-chain attack injected ClickFix scripts on customer sites

Cisco warns of max severity ISE zero-day exploited in attacks

Microsoft shares workaround for Windows domain login issues

Calling viral AI actress Tilly Norwood? Agree to a face scan first

Gyazo server flaw exploited to steal 23.6 million user records

Fake LastPass Authenticator GitHub repos push new Rapuncel infostealer

Secure enterprise sharing with access reviews for Microsoft 365

Tutorials

Latest
Popular

How to access the Dark Web using the Tor Browser

How to enable Kernel-mode Hardware-enforced Stack Protection in Windows 11

How to use the Windows Registry Editor

How to backup and restore the Windows Registry

How to start Windows in Safe Mode

How to remove a Trojan, Virus, Worm, or other Malware

How to show hidden files in Windows 7

How to see hidden files in Windows

Webinars
Downloads

Latest
Most Downloaded

Qualys BrowserCheck

STOPDecrypter

AuroraDecrypter

FilesLockerDecrypter

AdwCleaner

ComboFix

RKill

Junkware Removal Tool

Deals

Categories

eLearning

IT Certification Courses

Gear + Gadgets

Security

VPNs

Popular

Best VPNs

How to change IP address

Access the dark web safely

Best VPN for YouTube

Forums
More

Virus Removal Guides
Startup Database
Uninstall Database
Glossary
Send us a Tip!
Welcome Guide

HomeNewsSecurityCalling viral AI actress Tilly Norwood? Agree to a face scan first

Calling viral AI actress Tilly Norwood? Agree to a face scan first

By Ax Sharma

September 19, 2026
07:38 AM
0

Last night, in a clip viewed more than eight million times, AI actress Tilly Norwood glitched mid-interview and unexpectedly began speaking Chinese on the Piers Morgan Uncensored show.
Norwood has been the subject of much controversy and mainstream commentary for starring in an upcoming AI-generated film, Misaligned.
Her creators run a "Talking Tilly" service that lets anyone video-call the AI character behind the viral moment, so today I tried it for myself, and read the fine print most callers won't.
A face scan before you can say hello
Before your first call connects, you must pass an automated age check.
A video selfie is analysed by Didit, a Spain-based identity verification provider, to estimate your age, with a government photo ID upload as the fallback if the estimate is unclear.

Viral AI actress live video call hotline prompts you for a video selfie
(BleepingComputer)
Xicoia Ltd, the UK company behind Tilly, states the selfie travels from your device directly to Didit, that no faceprint or biometric template is created, and that neither the selfie nor any ID image is kept after the check; the company says it retains an approximate age band and a reference number instead.
The check cannot be skipped, applies to callers worldwide, and was only added to the service's terms this month, alongside a workplace-use ban and new automated safety systems.
The face scan is not the only analysis running.
During every call, the system watches your camera feed and listens to your tone of voice to infer your emotional state, so the character can, in the company's words, respond in a way that fits the mood.
The privacy policy is candid that this "cannot be switched off for an individual call." If you don't want it, don't call.
Notably, both the age check and the mood-sensing rely on legitimate interests rather than consent as their legal basis, a choice Xicoia's own version history shows was made in September.
Calls are recorded, transcribed, and processed live by US providers, with the character's responses generated by Google's Gemini model via conversational video platform Tavus.
The safety systems have teething problems, too.
An automated classifier screens each call's transcript for abusive language and withholds your recording if it flags one.
One of my three calls, a conversation about the weather and news headlines, was withheld for "hateful or abusive language" that never occurred. The policy says a human reviewer can release wrongly flagged recordings, though recordings are permanently deleted after 24 hours either way.
Free for five minutes, then the meter starts
The first five minutes are free. After that, callers are prompted to buy time: £0.99 for a one-time five-minute starter, £13 for 15 minutes, £22 for 30, capped at 35 purchased minutes per person.

Users get free 5 minutes with Tilly before being asked to pay up
(BleepingComputer)
The fine print matters more than usual here, because the whole service is a limited engagement.
Every minute, free or paid, expires when Talking Tilly shuts down permanently on September 27, and unused minutes are forfeited.
Transcripts are retained for up to eight weeks and may be reviewed by Xicoia staff and third-party partners, while the character keeps memory of your previous conversations to personalise future ones, deletable on request.
In line with where the UK is heading
An 18+ face scan to talk to a chatbot may sound novel, but it is consistent with the UK's direction of travel.
Adult sites serving UK visitors have required ID uploads or facial age estimation since July 2025 under the Online Safety Act, and the government's under-16 social media ban will make similar checks a fact of life for anyone opening a new social media account from spring 2027.
The UK government's announcement of that ban specifically flagged AI companion chatbots for 18+ enforcement (even though the service's safety docs insist "Tilly is not a companion"), which likely explains why a viral AI character picked up a biometric age gate mid-run.
The side effect being, a compliance decision driven by UK regulation now face-scans callers everywhere, from Manchester to Ohio.
Accident or marketing?
Xicoia, founded by Tilly's creator Eline van der Velden, describes the character as an awareness project intended to show how far AI video has come.

EXCLUSIVE: AI actress Tilly Norwood glitches and starts speaking CHINESE during her interview with Piers Morgan and real-life actor Tom Conti...
Watch the full interview at 7pm (BST)https://t.co/1nTb79BH8D@piersmorgan | @TillyNorwoodX pic.twitter.com/DDkveWvVzz
— Piers Morgan Uncensored (@PiersUncensored) September 18, 2026
On my call, Tilly's own explanation of the Piers Morgan moment was that it "wasn't exactly the approved version of the answer."

Talking Tilly goes offline for good at 11:59 PM Pacific on September 27, days after the Piers Morgan appearance.
Whether last night's slip was truly accidental, as Tilly cheerfully claimed to me today, or a well-timed stunt from the Misaligned crew, is known to Tilly alone.

Build your security blueprint for AI-powered attacks

Join Mikko Hyppönen and security leaders from the NFL, CHANEL, and Atlassian for a two-hour digital summit on what AI-speed attacks change, what defenders should stop doing, and how to validate, decide, fix, and re-validate at machine speed.
Save your seat

Related Articles:
New RatHat Android malware uses AI to automate device controlOpenAI details more cases of AI agents taking unauthorized actionsAnthropic wants Claude to analyze your bank account and financial dataSpain's data agency gets first report of AI-powered data breachHackers abused Claude to extract secrets from 1.8M Android apps

AI
Face ID
Facial Recognition
Tilly Norwood

Ax Sharma
Ax Sharma is a security researcher and journalist focused on malware analyses and cybercrime investigations. His expertise includes open source software security, threat intel analysis, and reverse engineering. Frequently featured by leading media outlets like the BBC, Channel 5 (UK), Fortune, WIRED, among others, Ax is an active community member of the OWASP Foundation and the Canadian Association of Journalists (CAJ).

Previous Article

Post a Comment Community Rules

You need to login in order to post a comment
Not a member yet? Register Now

You may also like:

  Upcoming Webinar

Popular Stories

Windows 11 KB5124008 update breaks domain trust for some users

Cisco warns of max severity ISE zero-day exploited in attacks

Microsoft shares workaround for Windows domain login issues

Sponsor Posts

Watch a working exploit hit live controls and see exactly what blocks, detects, or misses

Patch automation needs more than speed. Action1 brings control into every stage of deployment.

Overdue a password health-check? Audit your Active Directory for free

Find out how long recovery really takes — and what it costs. Read the 2025 BCDR Report.

Automate Onboarding and Access Reviews with No-Code IGA: See how it works

  Upcoming Webinar

Follow us:

Main Sections

News
Webinars
VPN Buyer Guides
SysAdmin Software Guides
Downloads
Virus Removal Guides
Tutorials
Startup Database
Uninstall Database
Glossary

Community

Forums
Forum Rules
Chat

Useful Resources

Welcome Guide
Sitemap

Company

About BleepingComputer
Contact Us
Send us a Tip!
Advertising
Write for BleepingComputer
Social & Feeds
Changelog

Terms of Use - Privacy Policy - Ethics Statement - Affiliate Disclosure

Copyright @ 2003 - 2026 Bleeping Computer® LLC - All Rights Reserved

Login

Username

Password

Remember Me

Sign in anonymously

Sign in with Twitter

Not a member yet? Register Now


Reporter

Help us understand the problem. What is going on with this comment?

Spam

Abusive or Harmful

Inappropriate content

Strong language

Other

Read our posting guidelinese to learn what content is prohibited.

Submitting...
SUBMIT

The controversy surrounding AI actress Tilly Norwood stems from a live broadcast incident where the AI character unexpectedly began speaking Chinese during an interview on Piers Morgan Uncensored. This event brought into sharp focus the privacy and safety protocols implemented by the service creators for their AI companion, "Talking Tilly." To initiate contact, users are required to undergo an automated face scan for an age check, analyzed by Didit, a Spain-based identity verification provider, with a government photo ID serving as a fallback if the initial estimation is unclear.

The company behind Tilly, Xicoia Ltd, asserts that the face scan does not result in the creation of any faceprint or biometric template, and neither the selfie nor any uploaded identification image is retained post-check; instead, the system stores only an approximate age band and a reference number. This face scan is mandatory for all callers worldwide and was introduced this month alongside other safety measures and a workplace-use ban. Furthermore, the system continuously monitors the caller's camera feed and voice tone to infer emotional states, allowing the character to modulate its responses accordingly, a process that the privacy policy notes cannot be disabled for individual calls. Both the age verification and the mood sensing functionalities are grounded in legitimate interests rather than explicit consent, a legal basis choice made by the company in September.

The operation involves live processing by US providers, with responses generated using Google's Gemini model through the Tavus conversational video platform. The system includes safety mechanisms, where an automated classifier screens transcripts for abusive language, and recordings are withheld if flagged. However, the text notes that this system has experienced flaws, evidenced by an instance where a conversation about general news was withheld for "hateful or abusive language" that was absent, although human review is possible for wrongly flagged content. Recordings are permanently deleted after twenty-four hours regardless of whether flagging occurred.

The service operates under a limited engagement model, offering five free minutes before users are prompted to purchase time packages, ranging from one-time five-minute starters to longer durations, capped at thirty-five purchased minutes per person. These minutes expire permanently on September 27th, and unused credit is forfeited. Transcripts are retained for up to eight weeks and are subject to review by Xicoia staff and third-party partners, while the character retains conversational memory, which can be deleted upon request.

The implementation of age-based checks is contextualized by broader European regulatory trends. The requirement for facial age estimation coincides with the United Kingdom's direction regarding online safety, specifically the Online Safety Act which mandates ID uploads or facial age estimation for adult sites serving UK visitors since July 2025, and the upcoming ban on under-16 social media access scheduled for spring 2027. This regulatory trajectory has resulted in face-scan requirements extending across jurisdictions, from Manchester to Ohio. The UK government's specific flagging of AI companion chatbots for eighteen plus enforcement, despite the service's claim that Tilly is not a companion, likely influenced the inclusion of biometric age gates in AI interaction services.

The AI actress's creator, Eline van der Velden, characterizes the character as an awareness project intended to demonstrate advancements in AI video technology. The incident involving Tilly's glitch is framed by the creator as a potential anomaly, with Tilly suggesting the slip was not necessarily an accidental error but perhaps a deliberate stunt orchestrated by the Misaligned crew, indicating that the context of the operational environment is crucial to understanding the event.