Skip to main content
COSMICBYTEZLABS
NewsSecurityHOWTOsToolsTraining
StudyProjectsNewsletterHire MeAbout
Subscribe

Press Enter to search or Esc to close

News
Security
HOWTOs
Tools
Training
Study
Projects
Newsletter
Hire Me
About
RSS Feed
Reading List
Subscribe

Stay in the Loop

Get the latest security alerts, tutorials, and tech insights delivered to your inbox.

Subscribe NowFree forever. No spam.
COSMICBYTEZLABS

Your trusted source for IT intelligence, cybersecurity insights, and hands-on technical guides.

2926+ Articles
167+ Guides

CONTENT

  • Latest News
  • Security Alerts
  • HOWTOs
  • Checklists
  • Projects
  • Exam Prep

RESOURCES

  • Search
  • Browse Tags
  • Newsletter Archive
  • Reading List
  • RSS Feed

COMPANY

  • About Us
  • Contact
  • Privacy Policy
  • Terms of Service

© 2026 CosmicBytez Labs. All rights reserved.

System Status: Operational
  1. Home
  2. News
  3. AI Actress Tilly Norwood's Hotline Face-Scans Callers for Age and Mood
AI Actress Tilly Norwood's Hotline Face-Scans Callers for Age and Mood
NEWS

AI Actress Tilly Norwood's Hotline Face-Scans Callers for Age and Mood

Talking Tilly's hotline face-scans every caller for age and mood, relying on 'legitimate interest' instead of consent, before its Sept. 27 shutdown.

Dylan H.

News Desk

September 19, 2026
3 min read

What's Happening

Tilly Norwood, the AI-generated "actress" behind UK studio Xicoia, went viral this week after glitching mid-interview on Piers Morgan Uncensored and briefly answering in Cantonese. The clip drove traffic to "Talking Tilly," a video-call hotline where anyone can dial in for a live conversation with the AI character before it shuts down for good.

Before a caller reaches Tilly, the service runs a mandatory face scan. An automated selfie check, handled by Spain-based identity verification provider Didit, estimates the caller's age, with a government photo ID upload as fallback when the estimate is unclear. Xicoia says the selfie travels directly from the caller's device to Didit and that neither the selfie nor an uploaded ID is retained afterward, only an approximate age band and a reference number.

The Biometric Data Question

Age verification is not the only thing the camera is doing. Per BleepingComputer's review of the privacy policy, the system continuously analyzes the caller's camera feed and voice tone throughout the call to infer their emotional state, then uses that read to shape the AI character's responses. Mood-sensing cannot be switched off for an individual call; it runs by default for every caller who connects.

That combination, a face scan for age estimation plus real-time emotion inference from face and voice, sits squarely inside the biometric and special-category data processing that GDPR-style frameworks treat with extra scrutiny. Yet both the age check and mood-sensing rely on "legitimate interests" as their legal basis rather than opt-in consent: callers are never asked to affirmatively agree before processing starts, and cannot complete a call without it.

The Fine Print

Calls are recorded and transcribed, then processed by third-party providers, including Google's Gemini model via the conversational-video platform Tavus, based in the US. Recordings are reportedly kept up to 24 hours and transcripts up to eight weeks, reviewed by Xicoia staff and third-party partners. An automated classifier screens transcripts for abusive language and withholds flagged recordings; BleepingComputer found at least one false positive, an ordinary weather chat flagged as hateful content.

Talking Tilly shuts down permanently on September 27, 2026. Free callers get five minutes; paid tiers cap out at 35 purchased minutes per person, and unused minutes are forfeited with no refund. Left unaddressed: what happens to the age bands, reference numbers, transcripts, and stored conversation history already collected once the service goes dark.

Why IT/Security Teams Should Care

Talking Tilly is a novelty hotline, but the pattern is familiar to any team chasing shadow AI inside its own organization. An employee experimenting with a viral consumer AI tool on a work device can trigger biometric-adjacent data collection, under a privacy policy nobody reviewed and a legal basis that assumes consent is not required. Vendor claims that no biometric template is created are also hard for an outside caller, or a security team, to verify independently; they rest entirely on the vendor's own account of its pipeline.

For AI vendor-risk checklists, Talking Tilly is a useful case study: does the tool process camera or voice data server-side, what is the legal basis, how long is data retained, who are the downstream sub-processors, and what is the documented deletion path once the service disappears. A shutdown date is not the same thing as a data-deletion guarantee.

#AI Privacy#Biometrics#Data Privacy#Consumer AI#BleepingComputer

Related Articles

The Future of Age Verification: Your Face Never Leaves Your Device

As age verification mandates expand globally, on-device facial age estimation is emerging as a privacy-preserving alternative — processing biometric data...

5 min read

UK to Require Government ID or Face Scan Before Creating Social Media Accounts

Opening a new social media account in the UK will soon require proving you are over 16 with a government ID upload or facial age scan, under a ban on...

4 min read

Persona Source Code Leak Exposes Hidden Biometric

A 53MB source code leak from identity verification giant Persona reveals how routine age verification selfies feed into a surveillance system linking...

5 min read
Back to all News