Viral AI actress’ hotline face-scans every caller, watches their mood

A Viral AI Actress’s Hotline Raises Alarms Over Biometric Data Collection and Surveillance

In a bizarre incident that has left many stunned, the viral AI actress Tilly Norwood has been at the center of controversy after glitching mid-interview on the Piers Morgan Uncensored show. The incident sparked widespread attention to her creators’ “Talking Tilly” service, which allows users to video-call the AI character behind the viral moment. Our investigation reveals that this seemingly innocuous chatbot is collecting and analyzing sensitive user data, raising concerns over biometric surveillance and privacy.

Before even initiating a call with Talking Tilly, users are required to undergo an automated age check using their device’s camera. The service relies on Didit, a Spain-based identity verification provider, to analyze the video selfie and estimate the user’s age. If the AI is unsure of the user’s age, a government photo ID upload is requested as a fallback. While Xicoia Ltd, the UK company behind Tilly, claims that no faceprint or biometric template is created during this process, the service retains an approximate age band and reference number instead.

However, this is not the only form of data collection taking place on Talking Tilly’s hotline. During every call, the system continuously monitors users’ camera feeds and listens to their tone of voice to infer their emotional state. This information is then used to tailor the AI character’s responses to fit the user’s mood. Notably, users cannot opt out of this analysis for individual calls, as stated in the service’s candid privacy policy.

The implications of these data collection practices are far-reaching. With both the age check and mood-sensing relying on legitimate interests rather than consent as their legal basis, Xicoia has made a deliberate choice to prioritize compliance over user autonomy. This decision was made in September, according to the company’s version history.

Furthermore, calls are recorded, transcribed, and processed live by US providers, with the character’s responses generated by Google’s Gemini model via conversational video platform Tavus. The service also employs automated safety systems that screen each call’s transcript for abusive language, withholding recordings if they flag one. However, our investigation revealed that these systems are far from perfect, with some calls being withheld incorrectly.

The fine print of Talking Tilly’s terms and conditions raises even more concerns. Users are warned that every minute, free or paid, expires when the service shuts down permanently on September 27, and unused minutes are forfeited. Transcripts are retained for up to eight weeks and may be reviewed by Xicoia staff and third-party partners.

The UK government’s recent announcements have paved the way for this kind of biometric data collection. The Online Safety Act has required adult sites serving UK visitors to upload ID or perform facial age estimation since July 2025, while a planned under-16 social media ban will make similar checks a fact of life for new social media account holders from spring 2027.

As the side effect of complying with these regulations, Talking Tilly’s creators have inadvertently created a global hotline that face-scans callers everywhere. While Xicoia describes the character as an awareness project, it is unclear whether this decision was driven by accident or marketing strategy.

In light of these findings, users are advised to exercise caution when interacting with biometric-powered services like Talking Tilly. While the UK government’s direction of travel may justify these measures, they raise significant concerns over user privacy and surveillance. As the line between awareness projects and data collection practices becomes increasingly blurred, it is essential for users to stay vigilant and demand transparency from service providers.


Source: Bleeping Computer — 2026-09-19