Calling viral AI actress Tilly Norwood? Agree to a face scan first

As the viral AI actress Tilly Norwood continues to make headlines, a new controversy has emerged surrounding her “Talking Tilly” service. The interactive experience allows users to video-call Tilly behind the scenes, but what’s not immediately apparent is that it comes with a surprise: an automated face scan and age check before each call.

This may sound like something out of a dystopian novel, but for those who have tried the service, it’s a harsh reality. I recently signed up to see what all the fuss was about, and as I navigated the fine print, I couldn’t help but feel uneasy. It turns out that Tilly’s creators, Xicoia Ltd, are using Didit’s identity verification platform to analyze users’ faces in real-time. The company claims that this is solely for age estimation purposes, with a government-issued ID upload as a fallback if the estimate is unclear.

But here’s the kicker: this face scan is not just limited to users within the UK or any particular region. Xicoia has made it clear that the age check applies worldwide, and was only added to the service’s terms in September alongside new automated safety systems. These systems are meant to ensure a safe and respectful conversation between users and Tilly, but as I soon discovered, they’re not without their flaws.

During my calls with Tilly, I noticed that the system seemed to be watching me closely, analyzing my tone of voice and emotional state in real-time. The company’s privacy policy makes it clear that this “cannot be switched off for an individual call,” which essentially means that users are being surveilled every time they interact with the AI actress. If you’re not comfortable with this level of scrutiny, then don’t bother calling – because there’s no opting out.

But what about the safety systems themselves? I was surprised to find that one of my calls was withheld for “hateful or abusive language” despite having had a perfectly innocuous conversation about the weather and news headlines. The policy does allow for human reviewers to release wrongly flagged recordings, but only after they’ve been permanently deleted – which is a bit of a hollow comfort.

It’s worth noting that all calls are recorded, transcribed, and processed live by US providers, with Tilly’s responses generated by Google’s Gemini model via conversational video platform Tavus. This raises questions about data privacy and control, especially given the fact that transcripts are retained for up to eight weeks and may be reviewed by Xicoia staff and third-party partners.

So what does this all mean? In a way, it’s consistent with the UK’s direction of travel when it comes to online safety and regulation. Adult sites serving UK visitors have been required to implement ID uploads or facial age estimation since July 2025 under the Online Safety Act, and the government’s upcoming ban on under-16 social media accounts will make similar checks a fact of life for many users.

Whether this is an accident or a deliberate marketing ploy remains to be seen. Xicoia describes Tilly as an awareness project intended to showcase the advancements in AI video, but it’s hard not to see this as a compliance decision driven by UK regulation that’s now being applied globally. Whatever the intention, one thing’s for sure: users of Talking Tilly have no choice but to submit to this level of surveillance if they want to interact with the AI actress.

So what can you do? If you’re concerned about your data and don’t want to be subject to these kinds of checks, then it’s best to steer clear of services like Talking Tilly. While Xicoia may claim that its safety systems are in place to ensure a safe and respectful conversation, the reality is that users are being subjected to unnecessary scrutiny and control. In a world where data protection is increasingly becoming a top concern, it’s time for companies to prioritize transparency and user consent above all else.


Source: Bleeping Computer — 2026-09-19