HomeIntelligenceBrief
BREACH BRIEF 🟡 Medium ThreatIntel

AI Actress Service Requires Mandatory Face Scan and Mood‑Sensing – Privacy Implications

Xicoia Ltd.’s “Talking Tilly” service now forces callers to submit a selfie for age verification and continuously analyses facial and vocal cues to infer mood, relying on legitimate‑interest legal bases. This creates privacy‑control gaps that must be documented and monitored for audit readiness.

Verisq™ Intelligence · 📅 September 19, 2026 · 📰 bleepingcomputer.com
🟡
Severity
Medium
TI
Type
ThreatIntel
🎯
Confidence
High
🏢
Affected
3 sector(s)
Actions
2 recommended
📰
Source
bleepingcomputer.com

AI Actress Service Requires Mandatory Face Scan and Mood‑Sensing – Privacy Implications

What Happened – The “Talking Tilly” video‑call service (operated by Xicoia Ltd.) now forces every caller to submit a selfie for an automated age check via the Spanish identity‑verification provider Didit. The selfie is not stored, but an approximate age band and reference number are retained. During each call the system also analyses the caller’s facial expression and voice tone to infer emotional state, records and transcribes the conversation, and processes the data through Google’s Gemini model. The service’s privacy policy relies on “legitimate interests” rather than explicit consent for both the age check and mood‑sensing.

Why It Matters for Trust & Control Assurance

  • Demonstrates the need for documented lawful‑basis assessments and consent‑management evidence that a continuous control‑assurance program can capture and audit.
  • Highlights the importance of monitoring third‑party data‑processing pipelines (Didit, Google Gemini) to ensure they meet your organization’s privacy‑risk thresholds.
  • Shows how automated biometric and emotion‑analysis functions can create control gaps that must be mapped, tracked, and evidenced for regulatory scrutiny.

Who Is Affected – Media & entertainment firms using AI‑generated characters, SaaS platforms offering interactive AI avatars, and any end‑users who engage with such services worldwide.

Recommended Actions

  • Conduct a privacy impact assessment (PIA) focused on biometric collection, mood‑sensing, and cross‑border data transfers.
  • Map the service’s “legitimate interests” claim to your internal consent‑management controls and capture evidence (policy docs, data‑flow diagrams, retention schedules).
  • Verify third‑party contracts with Didit and Google for adequate data‑processing clauses and continuous monitoring provisions.

Technical Notes – Age verification uses a selfie analyzed by Didit; no faceprint is stored, but an age band and reference ID are kept. Mood inference runs on‑device video/audio streams, with recordings sent to US providers for transcription and Gemini‑generated responses. Calls are recorded, flagged by an automated classifier for abusive language, and deleted after 24 hours. Source: BleepingComputer

📰 Original Source
https://www.bleepingcomputer.com/news/security/calling-viral-ai-actress-tilly-norwood-agree-to-a-face-scan-first/

This Verisq Intelligence Brief is an independent analysis. Read the original reporting at the link above.

Third-party risk

Does this breach reach you?

Verisq continuously monitors your vendors for breach and ransomware activity, so the question stops being whether it happened and becomes whether it reaches you.

See a live Trust Center →