HomeIntelligenceBrief
BREACH BRIEF 🟡 Medium ThreatIntel

AI Actress ‘Talking Tilly’ Service Scans Callers’ Faces and Moods Without Consent

Xicoia Ltd.’s ‘Talking Tilly’ AI avatar requires a selfie for age verification and continuously analyses video and voice to infer mood, relying on a ‘legitimate interests’ legal basis instead of consent. This practice tests privacy‑by‑design controls and highlights the need for auditable consent management for AI‑driven biometric processing.

Verisq™ Intelligence · 📅 September 20, 2026 · 📰 bleepingcomputer.com
🟡
Severity
Medium
TI
Type
ThreatIntel
🎯
Confidence
High
🏢
Affected
2 sector(s)
Actions
4 recommended
📰
Source
bleepingcomputer.com

AI Actress “Talking Tilly” Service Scans Callers’ Faces and Moods Without Consent

What Happened — The UK‑based Xicoia Ltd. launched “Talking Tilly,” an AI‑driven video‑call service that forces every caller to submit a selfie for an automated age check and continuously analyses the video‑feed and voice tone to infer emotional state. The provider claims no biometric template is stored, yet the selfie and voice data are processed by third‑party Didit and Google Gemini, and the service relies on a “legitimate interests” legal basis rather than explicit consent.

Why It Matters for Trust & Control Assurance

  • Demonstrates a gap in privacy‑by‑design and lawful‑basis documentation – a core control objective for continuous privacy assurance.
  • Highlights the need for transparent consent management and evidence‑backed data‑minimization when processing biometric‑like data.
  • Shows how AI‑driven mood‑sensing can trigger false‑positive content‑blocking, underscoring the importance of AI governance and audit‑ready logging of automated decisions.

Who Is Affected – Media & entertainment firms offering consumer‑facing AI avatars, AI‑SaaS platforms that process video/audio, and any organization that uses biometric‑like analytics for user verification.

Recommended Actions

  • Conduct a privacy impact assessment (PIA) focused on biometric and mood‑analysis processing.
  • Document the lawful basis (consent vs. legitimate interest) and update privacy notices to give users a real opt‑out.
  • Implement audit‑ready logging of AI inference outcomes and provide a manual review pathway for false‑positive blocks.
  • Map these practices to the VCF control objective “Privacy and data‑protection controls” and capture evidence in your Trust Center.

Technical Notes – The age‑check uses a selfie sent to Didit (Spain) for AI‑based age estimation; mood detection runs on Google Gemini via Tavus, with live transcription and US‑based storage. No biometric template is retained, but approximate age band and reference numbers are stored. Source: BleepingComputer

📰 Original Source
https://www.bleepingcomputer.com/news/security/viral-ai-actress-hotline-face-scans-every-caller-watches-their-mood/

This Verisq Intelligence Brief is an independent analysis. Read the original reporting at the link above.

Third-party risk

Does this breach reach you?

Verisq continuously monitors your vendors for breach and ransomware activity, so the question stops being whether it happened and becomes whether it reaches you.

See a live Trust Center →