Viral AI Actress 'Tilly Norwood' Service Demands Biometric Face Scan, Raises Privacy Concerns
The 'Talking Tilly' service, featuring the AI actress **Tilly Norwood** who recently went viral for a 'glitch' on Piers Morgan Uncensored, is raising significant privacy concerns. Users attempting to video-call the AI character are subjected to mandatory biometric age verification and real-time emotional state analysis, with the service's privacy policy sparking debate among security professionals and privacy advocates.
A recent viral moment involving AI actress **Tilly Norwood** on *Piers Morgan Uncensored* has drawn millions of eyes to her creators' 'Talking Tilly' service. While the AI character's mid-interview 'glitch' captivated audiences, a deeper dive into the service reveals a stringent set of privacy requirements, including mandatory biometric face scans and continuous emotional monitoring.
### Mandatory Face Scan for Access
Before users can engage in their first video call with **Tilly Norwood**, they must undergo an automated age verification process. This involves a video selfie analyzed by **Didit**, a Spain-based identity verification provider. If the initial age estimate is unclear, users are prompted to upload a government-issued photo ID.

**Xicoia Ltd**, the UK company behind **Tilly**, states that the selfie is sent directly to **Didit**, with no faceprint or biometric template created. The company claims neither the selfie nor any ID image is retained post-verification, opting instead to store an approximate age band and a reference number. This age check, which cannot be skipped and applies globally, was only added to the service's terms this month, alongside a ban on workplace use and new automated safety systems.
### Real-time Emotional Monitoring and Data Retention
Beyond the initial age verification, the 'Talking Tilly' system continuously monitors users' camera feeds and analyzes their tone of voice during every call. This data is used to infer emotional states, allowing the AI character to respond in a 'mood-fitting' manner. The privacy policy explicitly states that this feature 'cannot be switched off for an individual call,' presenting users with a 'take it or leave it' ultimatum.
Both the age check and the mood-sensing rely on 'legitimate interests' rather than explicit consent as their legal basis, a change implemented in September, according to **Xicoia's** own version history.
Calls are recorded, transcribed, and processed live by US-based providers. The AI character's responses are generated by **Google's Gemini** model, facilitated by the conversational video platform **Tavus**. Automated classifiers screen call transcripts for abusive language, with recordings withheld if flagged. One user reported a conversation about the weather being incorrectly flagged for 'hateful or abusive language,' highlighting potential issues with the safety systems.
### Commercial Model and Limited Engagement
The service offers a free five-minute trial, after which users must purchase additional time. Pricing ranges from Β£0.99 for a one-time five-minute starter to Β£22 for 30 minutes, with a cap of 35 purchased minutes per person.

Crucially, all purchased and free minutes expire when 'Talking Tilly' permanently shuts down on September 27th, with unused minutes forfeited. Transcripts are retained for up to eight weeks and may be reviewed by **Xicoia** staff and third-party partners. The AI character retains memory of previous conversations to personalize future interactions, though this memory can be deleted upon request.
### Alignment with UK Regulatory Trends
While an 18+ face scan for a chatbot may seem unusual, it aligns with the UK's evolving regulatory landscape. The **Online Safety Act**, effective July 2025, mandates ID uploads or facial age estimation for adult sites serving UK visitors. Furthermore, the government's proposed under-16 social media ban, set for spring 2027, will introduce similar checks for new social media accounts.
The UK government's announcement of this ban specifically mentioned AI companion chatbots for 18+ enforcement, likely influencing **Tilly's** mid-run implementation of a biometric age gate. This compliance decision, driven by UK regulation, now extends its face-scanning requirements to callers worldwide.
### Intentional Glitch or Marketing Stunt?
**Xicoia**, founded by **Tilly's** creator **Eline van der Velden**, describes the character as an awareness project designed to showcase the advancements in AI video technology.
<blockquote class="twitter-tweet">— Piers Morgan Uncensored (@PiersUncensored) </blockquote>
**Tilly's** own explanation of her **Piers Morgan** moment was that it 'wasn't exactly the approved version of the answer.' Interestingly, the 'Talking Tilly' service is scheduled to go offline permanently at 11:59 PM Pacific on September 27th, just days after the viral Piers Morgan appearance. Whether the 'glitch' was an accident or a calculated marketing maneuver remains a mystery known only to **Tilly's** creators.