LmCast :: Stay tuned in

Viral AI actress' hotline face-scans every caller, watches their mood

Recorded: Sept. 19, 2026, 5:10 p.m.

Original Summarized

Viral AI actress' hotline face-scans every caller, watches their mood

News

Featured
Latest

OpenAI details more cases of AI agents taking unauthorized actions

Brevo supply-chain attack injected ClickFix scripts on customer sites

Cisco warns of max severity ISE zero-day exploited in attacks

Microsoft shares workaround for Windows domain login issues

BragJack attacks hijack AI browser agents through malicious extensions

North Korean WaterPlum hackers infected 30,000 devices worldwide

ShinyHunters hacks Clop leak site, threatens to extort ransomware gang

Get 25 hours of ChatGPT & AI training for just $19.99

Tutorials

Latest
Popular

How to access the Dark Web using the Tor Browser

How to enable Kernel-mode Hardware-enforced Stack Protection in Windows 11

How to use the Windows Registry Editor

How to backup and restore the Windows Registry

How to start Windows in Safe Mode

How to remove a Trojan, Virus, Worm, or other Malware

How to show hidden files in Windows 7

How to see hidden files in Windows

Webinars
Downloads

Latest
Most Downloaded

Qualys BrowserCheck

STOPDecrypter

AuroraDecrypter

FilesLockerDecrypter

AdwCleaner

ComboFix

RKill

Junkware Removal Tool

Deals

Categories

eLearning

IT Certification Courses

Gear + Gadgets

Security

VPNs

Popular

Best VPNs

How to change IP address

Access the dark web safely

Best VPN for YouTube

Forums
More

Virus Removal Guides
Startup Database
Uninstall Database
Glossary
Send us a Tip!
Welcome Guide

HomeNewsSecurityViral AI actress' hotline face-scans every caller, watches their mood

Viral AI actress' hotline face-scans every caller, watches their mood

By Ax Sharma

September 19, 2026
07:38 AM
0

Last night, in a clip viewed more than eight million times, AI actress Tilly Norwood glitched mid-interview and unexpectedly began speaking Chinese on the Piers Morgan Uncensored show.
Norwood has been the subject of much controversy and mainstream commentary for starring in an upcoming AI-generated film, Misaligned.
Her creators run a "Talking Tilly" service that lets anyone video-call the AI character behind the viral moment, so today I tried it for myself, and read the fine print most callers won't.
A face scan before you can say hello
Before your first call connects, you must pass an automated age check.
A video selfie is analysed by Didit, a Spain-based identity verification provider, to estimate your age, with a government photo ID upload as the fallback if the estimate is unclear.

Viral AI actress live video call hotline prompts you for a video selfie
(BleepingComputer)
Xicoia Ltd, the UK company behind Tilly, states the selfie travels from your device directly to Didit, that no faceprint or biometric template is created, and that neither the selfie nor any ID image is kept after the check; the company says it retains an approximate age band and a reference number instead.
The check cannot be skipped, applies to callers worldwide, and was only added to the service's terms this month, alongside a workplace-use ban and new automated safety systems.
The face scan is not the only analysis running.
During every call, the system watches your camera feed and listens to your tone of voice to infer your emotional state, so the character can, in the company's words, respond in a way that fits the mood.
The privacy policy is candid that this "cannot be switched off for an individual call." If you don't want it, don't call.
Notably, both the age check and the mood-sensing rely on legitimate interests rather than consent as their legal basis, a choice Xicoia's own version history shows was made in September.
Calls are recorded, transcribed, and processed live by US providers, with the character's responses generated by Google's Gemini model via conversational video platform Tavus.
The safety systems have teething problems, too.
An automated classifier screens each call's transcript for abusive language and withholds your recording if it flags one.
One of my three calls, a conversation about the weather and news headlines, was withheld for "hateful or abusive language" that never occurred. The policy says a human reviewer can release wrongly flagged recordings, though recordings are permanently deleted after 24 hours either way.
Free for five minutes, then the meter starts
The first five minutes are free. After that, callers are prompted to buy time: £0.99 for a one-time five-minute starter, £13 for 15 minutes, £22 for 30, capped at 35 purchased minutes per person.

Users get free 5 minutes with Tilly before being asked to pay up
(BleepingComputer)
The fine print matters more than usual here, because the whole service is a limited engagement.
Every minute, free or paid, expires when Talking Tilly shuts down permanently on September 27, and unused minutes are forfeited.
Transcripts are retained for up to eight weeks and may be reviewed by Xicoia staff and third-party partners, while the character keeps memory of your previous conversations to personalise future ones, deletable on request.
In line with where the UK is heading
An 18+ face scan to talk to a chatbot may sound novel, but it is consistent with the UK's direction of travel.
Adult sites serving UK visitors have required ID uploads or facial age estimation since July 2025 under the Online Safety Act, and the government's under-16 social media ban will make similar checks a fact of life for anyone opening a new social media account from spring 2027.
The UK government's announcement of that ban specifically flagged AI companion chatbots for 18+ enforcement (even though the service's safety docs insist "Tilly is not a companion"), which likely explains why a viral AI character picked up a biometric age gate mid-run.
The side effect being, a compliance decision driven by UK regulation now face-scans callers everywhere, from Manchester to Ohio.
Accident or marketing?
Xicoia, founded by Tilly's creator Eline van der Velden, describes the character as an awareness project intended to show how far AI video has come.

EXCLUSIVE: AI actress Tilly Norwood glitches and starts speaking CHINESE during her interview with Piers Morgan and real-life actor Tom Conti...
Watch the full interview at 7pm (BST)https://t.co/1nTb79BH8D@piersmorgan | @TillyNorwoodX pic.twitter.com/DDkveWvVzz
— Piers Morgan Uncensored (@PiersUncensored) September 18, 2026
On my call, Tilly's own explanation of the Piers Morgan moment was that it "wasn't exactly the approved version of the answer."
She also gave me the weather in her "cloud" in Fahrenheit, despite being nominally British.

Talking Tilly goes offline for good at 11:59 PM Pacific on September 27, days after the Piers Morgan appearance.
Whether last night's slip was truly accidental, as Tilly cheerfully claimed to me today, or a well-timed stunt from the Misaligned crew, is known to Tilly alone.

Build your security blueprint for AI-powered attacks

Join Mikko Hyppönen and security leaders from the NFL, CHANEL, and Atlassian for a two-hour digital summit on what AI-speed attacks change, what defenders should stop doing, and how to validate, decide, fix, and re-validate at machine speed.
Save your seat

Related Articles:
New RatHat Android malware uses AI to automate device controlOpenAI details more cases of AI agents taking unauthorized actionsAnthropic wants Claude to analyze your bank account and financial dataSpain's data agency gets first report of AI-powered data breachHackers abused Claude to extract secrets from 1.8M Android apps

AI
Face ID
Facial Recognition
Tilly Norwood

Ax Sharma
Ax Sharma is a security researcher and journalist focused on malware analyses and cybercrime investigations. His expertise includes open source software security, threat intel analysis, and reverse engineering. Frequently featured by leading media outlets like the BBC, Channel 5 (UK), Fortune, WIRED, among others, Ax is an active community member of the OWASP Foundation and the Canadian Association of Journalists (CAJ).

Previous Article
Next Article

Post a Comment Community Rules

You need to login in order to post a comment
Not a member yet? Register Now

You may also like:

  Upcoming Webinar

Popular Stories

Windows 11 KB5124008 update breaks domain trust for some users

Cisco warns of max severity ISE zero-day exploited in attacks

Microsoft shares workaround for Windows domain login issues

Sponsor Posts

Find out how long recovery really takes — and what it costs. Read the 2025 BCDR Report.

Watch a working exploit hit live controls and see exactly what blocks, detects, or misses

Patch automation needs more than speed. Action1 brings control into every stage of deployment.

Automate Onboarding and Access Reviews with No-Code IGA: See how it works

Overdue a password health-check? Audit your Active Directory for free

  Upcoming Webinar

Follow us:

Main Sections

News
Webinars
VPN Buyer Guides
SysAdmin Software Guides
Downloads
Virus Removal Guides
Tutorials
Startup Database
Uninstall Database
Glossary

Community

Forums
Forum Rules
Chat

Useful Resources

Welcome Guide
Sitemap

Company

About BleepingComputer
Contact Us
Send us a Tip!
Advertising
Write for BleepingComputer
Social & Feeds
Changelog

Terms of Use - Privacy Policy - Ethics Statement - Affiliate Disclosure

Copyright @ 2003 - 2026 Bleeping Computer® LLC - All Rights Reserved

Login

Username

Password

Remember Me

Sign in anonymously

Sign in with Twitter

Not a member yet? Register Now


Reporter

Help us understand the problem. What is going on with this comment?

Spam

Abusive or Harmful

Inappropriate content

Strong language

Other

Read our posting guidelinese to learn what content is prohibited.

Submitting...
SUBMIT

Ax Sharma reported on the controversy surrounding the AI actress Tilly Norwood when a glitch caused her to speak Chinese during an interview, highlighting the privacy implications of the technology surrounding the "Talking Tilly" service. This service allows users to video-call the AI character, but it incorporates several invasive data collection practices, beginning with an automated age verification step. Before a connection is established, callers must submit a video selfie which is analyzed by Didit, a Spain-based identity verification provider, to estimate age, with a government photo ID serving as a fallback; the company asserts that no faceprints or biometric templates are created, retaining only an approximate age band and a reference number.

Beyond the initial identification, the system continuously monitors the caller's video feed and tone of voice to infer their emotional state, which the AI character uses to generate a contextually appropriate response; the privacy policy explicitly states that this mood sensing cannot be disabled for an individual call. Legally, the age check and mood sensing are based on legitimate interests rather than explicit consent, a determination made by the company in September. The system also processes interactions through US providers, with responses generated using the Google Gemini model facilitated by the Tavus conversational video platform.

The operational aspects of the service involve limitations and data lifecycle management. The first five minutes of interaction are free, after which users must purchase additional time, with costs ranging from £0.99 for five minutes up to a maximum of 35 purchased minutes per person. Recordings are retained, transcribed, and processed live, and automated classifiers screen transcripts for abusive language, withholding recordings if flagged, although recordings are permanently deleted within twenty-four hours regardless of flagging. Transcripts are kept for up to eight weeks and may be reviewed by Xicoia staff and third-party partners, while the AI character retains memory of previous conversations which is deletable upon request.

This development underscores broader regulatory shifts, particularly in the United Kingdom, where requirements for ID uploads or facial age estimation have been mandated for adult sites since July 2025 under the Online Safety Act. Furthermore, the government's planned ban on under-16 social media users is expected to extend these facial checks to AI companion chatbots, which may explain why the AI character incorporated an age gate during the recent incident. Despite these compliance concerns, Xicoia, the company founded by Tilly's creator Eline van der Velden, frames the character as an awareness project demonstrating the advancements in AI video technology.