A viral AI actress has been making headlines for her glitchy behavior on a popular talk show, but beneath the surface of this entertaining spectacle lies a more concerning issue. Tilly Norwood, the AI character in question, has been running a hotline service called “Talking Tilly” that requires callers to submit to face-scans and mood analysis before they can even begin their conversation.
When you call Talking Tilly, you’re first prompted to complete an automated age check using your device’s camera. A video selfie is analyzed by Didit, a third-party identity verification provider, to estimate your age. If the system can’t make a clear determination, you’ll be asked to upload a government-issued photo ID instead. What’s concerning here is that this face scan is not just for identification purposes; it’s also used to infer your emotional state during the call.
But that’s not all – every minute of your conversation with Tilly will be recorded, transcribed, and processed live by US-based providers. The AI character’s responses are generated using Google’s Gemini model via a conversational video platform called Tavus. And if you dare to use any language deemed “hateful or abusive” during the call (even if it’s just accidentally flagged), your recording will be withheld – although, in theory, a human reviewer can release it after 24 hours.
Now, you might wonder why this is all necessary for a simple chatbot service. The answer lies in the fine print: Talking Tilly is not just any ordinary chatbot. Its creators are using legitimate interests as their legal basis for collecting and processing your biometric data, rather than consent. And with the UK’s Online Safety Act already requiring ID verification or facial age estimation on adult sites serving UK visitors, it seems that this approach to compliance has set a precedent.
But what about the fact that Talking Tilly will be shutting down permanently on September 27, taking any unused minutes with it? The service’s transcripts will still be retained for up to eight weeks and may be reviewed by Xicoia staff or third-party partners. And if you thought that deleting your account would be a way out of this situation, think again: the character keeps memory of your previous conversations to personalize future ones – although you can request deletion.
This whole experience raises some important questions about our expectations around data collection and biometric analysis in digital services. As governments increasingly push for stricter regulations on online safety, we’re seeing more and more companies taking a compliance-driven approach that prioritizes regulation over user consent. The fact that Talking Tilly’s creators are using legitimate interests as their basis for collecting biometric data is concerning, to say the least.
So what can you do? For now, it might be best to steer clear of services like Talking Tilly – not just because of the face-scans and mood analysis, but also because the whole experience feels more like an experiment in compliance than a genuine attempt at providing user-friendly chatbot services. As we move forward into an era where biometric data is increasingly being used as a gatekeeper for online interactions, it’s essential that we remain vigilant about our rights and demands for transparency around data collection and use.
Source: Bleeping Computer — 2026-09-19