
Talking Tilly AI hotline face-scans every caller worldwide
Talking Tilly, the video-call service behind AI actress Tilly Norwood, now face-scans every caller for age and reads their mood during each call.
Anyone who video-calls the viral AI character Tilly Norwood must pass a face scan before the first call connects, and the same service keeps watching their face and listening to their voice during every conversation, according to the service's own privacy policy and terms. The face scan is an automated age check. The mood sensing is a separate system that runs for the whole call.
Tilly Norwood is an AI-generated actress who drew widespread attention after a clip in which she glitched mid-interview and unexpectedly began speaking Chinese on the Piers Morgan Uncensored show. That clip was published on September 18, 2026 and has been viewed more than eight million times. The character stars in an upcoming AI-generated film called Misaligned, and she was created by Xicoia Ltd, a UK company founded by Eline van der Velden, which describes her as an awareness project intended to show how far AI video has come. The company also runs Talking Tilly, a service that lets anyone hold a live video call with the character.
BleepingComputer's Ax Sharma, who tried the service himself, reports that a video selfie must be submitted before the first call is allowed through. The selfie is analysed by Didit, a Spain-based identity verification provider, to estimate the caller's age. If that estimate is unclear, the fallback is an upload of a government photo ID. Xicoia states that the selfie travels from the caller's device directly to Didit, that no faceprint or biometric template is created, and that neither the selfie nor any ID image is kept once the check is complete. The company says it retains an approximate age band and a reference number instead. The check cannot be skipped, applies to callers worldwide, and was added to the service's terms in September, alongside a ban on workplace use and new automated safety systems.
The age check is not the only analysis running. During each call the system watches the caller's camera feed and listens to their tone of voice to infer their emotional state, so that the character can, in the company's words, respond in a way that fits the mood. The privacy policy is candid that this "cannot be switched off for an individual call", which means a caller who does not want it should not call. Both the age check and the mood sensing rely on legitimate interests rather than consent as their legal basis, a choice that Xicoia's own version history shows was made in September.
Legitimate interests is a ground in privacy law that lets a company process personal data without asking for explicit permission first, provided it has weighed its own needs against the individual's rights and freedoms.
Calls are recorded, transcribed and processed live by providers in the United States, and the character's responses are generated by Google's Gemini model through Tavus, a conversational video platform. An automated classifier screens the transcript of each call for abusive language and withholds the recording if it flags any. That safety system misfired in Sharma's case: one of his three calls, a conversation about the weather and news headlines, was withheld for "hateful or abusive language" that never occurred. The policy says a human reviewer can release a wrongly flagged recording, and that recordings are permanently deleted after 24 hours either way. After the article was published, Xicoia's team reviewed the withheld recording and released it, confirming the flag had been a false positive.
The first five minutes are free. After that, callers are prompted to buy time: a one-time five-minute starter at 0.99, 15 minutes at 13 and 30 minutes at 22, capped at 35 purchased minutes per person. The fine print matters more than usual here, because the whole service is a limited engagement. Every minute, free or paid, expires when Talking Tilly shuts down permanently on September 27, and unused minutes are forfeited. Transcripts are retained for up to eight weeks and may be reviewed by Xicoia staff and third-party partners, while the character keeps a memory of earlier conversations to personalise future ones, a memory that can be deleted on request. The service goes offline for good at 11:59 PM Pacific on September 27, just days after the Piers Morgan appearance.
An 18-plus face scan to talk to a chatbot may sound novel, but it is consistent with the direction the United Kingdom has been travelling. Adult sites that serve UK visitors have required ID uploads or facial age estimation since July 2025 under the Online Safety Act, and the government's ban on social media for under-16s will make similar checks a fact of life for anyone opening a new social media account from spring 2027. The government's announcement of that ban specifically flagged AI companion chatbots for 18-plus enforcement, even though the service's safety documentation insists that Tilly is not a companion. The side effect, as Sharma puts it, is that a compliance decision driven by UK regulation now face-scans callers everywhere, from Manchester to Ohio.
On Sharma's call, Tilly's own explanation for the Piers Morgan moment was that it "wasn't exactly the approved version of the answer". She also gave him the weather in her cloud in Fahrenheit, despite being nominally British. Whether the slip was truly accidental, as the character cheerfully claimed, or a well-timed stunt from the Misaligned crew, is known to Tilly alone.
For website owners and IT teams, the episode is a reminder of how quickly age checks, mood sensing and third-party AI processing can arrive inside a consumer-facing service, and of how much of that work is handed to outside vendors. Anyone who runs a site or an internal tool can ask the same questions of the services they adopt: what is collected, who processes it, how long it is kept and on what legal basis. For teams that want that ground covered in their own stack, AEU-I offers security-first IT, infrastructure and consulting.
How to Protect Yourself
- Before you try any video-call or chat service, read its privacy page to see whether it records your face, your voice or your camera, and who it shares that with.
- Treat a request for a selfie or a photo of your ID as sensitive: only send it if you understand what the service says it keeps and for how long.
- If you do not want your tone of voice or your expressions analysed, skip the call, because such settings often cannot be switched off once a call has started.
- Never say your home address, workplace, passwords or payment details out loud to an AI chatbot, even a friendly-sounding one.
- If a service stores your past conversations, use its delete option, or email the company and ask for your history to be removed.
- Check how long recordings are kept and ask for anything wrongly flagged to be looked at by a human before it is deleted.
Terms Explained
- face scan Software that studies a picture or video of your face to work out something about you, such as how old you are.
- biometric template A mathematical summary of a face, fingerprint or voice that a computer can compare against later to recognise you.
- identity verification provider A company whose job is to confirm that you are who you claim to be, often by checking a photo of your face or your ID document.
- legitimate interests A reason in privacy law that lets a company use your data without asking permission first, as long as it has balanced its needs against your rights.
- transcript A written text of everything that was said during a call.
- automated classifier A computer program that sorts content into categories by itself, in this case deciding whether a call contains abusive language.
- Online Safety Act A UK law that sets rules for online services, including age checks for adult content.