Calling viral AI actress Tilly Norwood? Agree to a face scan first

A Face Scan Before You Can Talk to Tilly: The Viral AI Actress’s Controversial New Feature

In a bizarre twist, the viral AI actress Tilly Norwood has introduced a face scan requirement for anyone who wants to video-call her. This comes as the character gains mainstream attention for starring in an upcoming AI-generated film, Misaligned. But what’s behind this new feature, and why is it sparking controversy?

To try out the “Talking Tilly” service, I recently made a call to the AI actress. Before my conversation could begin, I was prompted to provide a video selfie to verify my age. This analysis is carried out by Didit, a Spain-based identity verification provider, which estimates my age based on the selfie and allows me to upload a government-issued photo ID as an alternative. According to Xicoia Ltd, the UK company behind Tilly, neither the selfie nor any ID image is retained after the check; instead, they keep only an approximate age band and reference number.

However, this face scan isn’t the only way Tilly’s system assesses its callers. During every conversation, the character watches your camera feed and listens to your tone of voice to infer your emotional state, tailoring its responses accordingly. The company’s privacy policy candidly states that this “cannot be switched off for an individual call,” leaving those who value their anonymity out in the cold.

What’s more concerning is that both the age check and mood-sensing rely on legitimate interests rather than consent as their legal basis. This decision was made by Xicoia itself, with records showing it changed its stance in September. For context, calls are recorded, transcribed, and processed live by US providers, while Tilly’s responses are generated by Google’s Gemini model via conversational video platform Tavus.

The safety systems on the service have teething problems, too. An automated classifier screens each call’s transcript for abusive language, withholding your recording if it flags one. I experienced this firsthand when a conversation about the weather and news headlines was withheld for “hateful or abusive language” that never occurred. According to Xicoia, a human reviewer can release wrongly flagged recordings, but they are permanently deleted after 24 hours either way.

It’s also worth noting that every minute you spend on Talking Tilly expires when the service shuts down permanently on September 27, and unused minutes are forfeited. Transcripts are retained for up to eight weeks and may be reviewed by Xicoia staff and third-party partners, while Tilly keeps a memory of your previous conversations to personalize future ones.

The UK’s direction of travel is clear: adult sites serving UK visitors have required ID uploads or facial age estimation since July 2025 under the Online Safety Act. The government’s announcement of an under-16 social media ban will make similar checks a fact of life for anyone opening a new social media account from spring 2027.

It remains to be seen whether Xicoia’s decision to introduce a face scan was driven by compliance or marketing efforts. As the creator, Eline van der Velden, describes Tilly as an awareness project intended to showcase AI video advancements, it’s clear that this character has become more than just a viral sensation.

For those who value their online privacy, Talking Tilly is a stark reminder of the importance of reading fine print and being aware of what you’re signing up for. With biometric age gates becoming increasingly common in regulated environments, it’s essential to understand how these technologies work and what they mean for our personal data.


Source: Bleeping Computer — 2026-09-19