Last night, in a clip viewed more than eight million times, AI actress Tilly Norwood glitched mid-interview and unexpectedly began speaking Chinese on the Piers Morgan Uncensored show.
Norwood has been the subject of much controversy and mainstream commentary for starring in an upcoming AI-generated film, Misaligned.
Her creators run a “Talking Tilly” service that lets anyone video-call the AI character behind the viral moment, so today I tried it for myself, and read the fine print most callers won’t.
Before your first call connects, you must pass an automated age check.
A video selfie is analysed by Didit, a Spain-based identity verification provider, to estimate your age, with a government photo ID upload as the fallback if the estimate is unclear.
Xicoia Ltd, the UK company behind Tilly, states the selfie travels from your device directly to Didit, that no faceprint or biometric template is created, and that neither the selfie nor any ID image is kept after the check; the company says it retains an approximate age band and a reference number instead.
The check cannot be skipped, applies to callers worldwide, and was only added to the service’s terms this month, alongside a workplace-use ban and new automated safety systems.
The face scan is not the only analysis running.
During every call, the system watches your camera feed and listens to your tone of voice to infer your emotional state, so the character can, in the company’s words, respond in a way that fits the mood.
The privacy policy is candid that this “cannot be switched off for an individual call.” If you don’t want it, don’t call.
Notably, both the age check and the mood-sensing rely on legitimate interests rather than consent as their legal basis, a choice Xicoia’s own version history shows was made in September.
Calls are recorded, transcribed, and processed live by US providers, with the character’s responses generated by Google’s Gemini model via conversational video platform Tavus.
The safety systems have teething problems, too.
An automated classifier screens each call’s transcript for abusive language and withholds your recording if it flags one.
One of my three calls, a conversation about the weather and news headlines, was withheld for “hateful or abusive language” that never occurred. The policy says a human reviewer can release wrongly flagged recordings, though recordings are permanently deleted after 24 hours either way.
The first five minutes are free. After that, callers are prompted to buy time: £0.99 for a one-time five-minute starter, £13 for 15 minutes, £22 for 30, capped at 35 purchased minutes per person.
The fine print matters more than usual here, because the whole service is a limited engagement.
Every minute, free or paid, expires when Talking Tilly shuts down permanently on September 27, and unused minutes are forfeited.
Transcripts are retained for up to eight weeks and may be reviewed by Xicoia staff and third-party partners, while the character keeps memory of your previous conversations to personalise future ones, deletable on request.
An 18+ face scan to talk to a chatbot may sound novel, but it is consistent with the UK’s direction of travel.
Adult sites serving UK visitors have required ID uploads or facial age estimation since July 2025 under the Online Safety Act, and the government’s under-16 social media ban will make similar checks a fact of life for anyone opening a new social media account from spring 2027.
The UK government’s announcement of that ban specifically flagged AI companion chatbots for 18+ enforcement (even though the service’s safety docs insist “Tilly is not a companion”), which likely explains why a viral AI character picked up a biometric age gate mid-run.
The side effect being, a compliance decision driven by UK regulation now face-scans callers everywhere, from Manchester to Ohio.
Xicoia, founded by Tilly’s creator Eline van der Velden, describes the character as an awareness project intended to show how far AI video has come.
EXCLUSIVE: AI actress Tilly Norwood glitches and starts speaking CHINESE during her interview with Piers Morgan and real-life actor Tom Conti… Watch the full interview at 7pm (BST)https://t.co/1nTb79BH8D@piersmorgan | @TillyNorwoodX pic.twitter.com/DDkveWvVzz
On my call, Tilly’s own explanation of the Piers Morgan moment was that it “wasn’t exactly the approved version of the answer.”
She also gave me the weather in her “cloud” in Fahrenheit, despite being nominally British.
Talking Tilly goes offline for good at 11:59 PM Pacific on September 27, days after the Piers Morgan appearance.
Whether last night’s slip was truly accidental, as Tilly cheerfully claimed to me today, or a well-timed stunt from the Misaligned crew, is known to Tilly alone.
Update September 19th, 4:31 PM ET: Following publication, Xicoia’s team reviewed the withheld recording and released it, confirming the flag was a false positive.
Join Mikko Hyppönen and security leaders from the NFL, CHANEL, and Atlassian for a two-hour digital summit on what AI-speed attacks change, what defenders should stop doing, and how to validate, decide, fix, and re-validate at machine speed.
New RatHat Android malware uses AI to automate device control
OpenAI details more cases of AI agents taking unauthorized actions
Anthropic wants Claude to analyze your bank account and financial data
Spain’s data agency gets first report of AI-powered data breach
Hackers abused Claude to extract secrets from 1.8M Android apps
People are producing all kinds of garbage to make money? Wow, that really is news. But that is actually not the problem… The problem are those millions and millions of morons who will consume anything as long as they get feeling it makes their mediocre existence something special. When you are asked to this or that, to get another this or that, and it includes doing stuff like that and you not simply press “delete”, than YOU ARE THE PROBLEM. If you have your camera switched on when you are surfing, you should be checked out at a loony bin…. So do not complain about stuff like that. YOU are making sh** like this possible….
If we’re afforded the luxury of humanity 2.0, it’ll come equipped with awareness on how privacy, critical reasoning and agency are important for our survival. Current AI is nothing more than Social Media made worse, more automated, more misinformed, more untrustworthy, more prone to making people more fear driven, confirmation bias leading everything, Dunning-Kruger effect dominating, division going up and empathy going further down, with similar anti-trust effects that Big Tech has been forcing on people from a couple of decades ago up to now driven further now with the service sector, with more corporations being given free reign and power above law to push their inconsequential and reckless mentality over the entire population in the name of profit above everything else. Current AI will also empower, much like Social Media, all the criminals, organized crime, terrorists groups, politicians with populist fascist agenda and so on. Because it’s being led by the exact same people who let Social Media get to the point it did. It’ll drive radicalization and extremism further, because it’s being born from it. And while it’s doing that, it’s also allowing businesses, corporations and whatnot to dismiss all of it’s human workforce to be replaced by the same regurgitating black box, making the eventual fight against the machine be even more lopsided. How people still cannot see this I don’t really understand, but if there is some humanity left after this period, it’ll likely be seen as something like a consented ignorant age. A period when democracies failed over their own hubris, had to reform themselves to avoid being taken over by greedy egocentric people with an egocentric short sighted project for power. We had a millennium to learn from, let alone the past couple of decades regarding tech development and effect in society, and we learned nothing.
That is an excellent comment… except for the last paragraph. “How people still cannot see this I don’t really understand, but if there is some humanity left after this period, it’ll likely be seen as something like a consented ignorant age.” You are missing the understanding of one small fact. Type into your browser: “bell curve of intelligence”. It explains why the majority will always be morons out of necessity. Being enough of a cynic, my favorite sentence from you is: “Current AI will also empower, much like Social Media, all the criminals, organized crime, terrorists groups, politicians with populist fascist agenda and so on.” As I have done since the turn of the century, I will keep on having a nice view of the whole circus sitting on the veranda of my house in Koh Samui, watching the insanity float by, with a nice glass of wine in my hand.
Gyazo server flaw exploited to steal 23.6 million user records
Fake LastPass Authenticator GitHub repos push new Rapuncel infostealer
ShinyHunters hacks Clop leak site, threatens to extort ransomware gang
Overdue a password health-check? Audit your Active Directory for free
Watch a working exploit hit live controls and see exactly what blocks, detects, or misses
Patch automation needs more than speed. Action1 brings control into every stage of deployment.
Find out how long recovery really takes — and what it costs. Read the 2025 BCDR Report.
Automate Onboarding and Access Reviews with No-Code IGA: See how it works
Terms of Use – Privacy Policy – Ethics Statement – Affiliate Disclosure
Read our posting guidelinese to learn what content is prohibited.



