LIVE · cybersecurity feed
Live wire
CVE-2026-9055 · WordPress Amelia Plugin Flaw Exploited Before CVE PublicationCVE-2026-46331 · Linux Kernel Flaw Exploited After 71 Days, Not on CISA KEVCVE-2026-84434 · CVE-2026-84434 Exploited Before Publication, No Patch WindowCVE-2017-20284 · CVE-2017-20284 Exploited Same Day as PublicationCVE-2026-87886 · Acronis Backup Flaw Exploited Before CVE PublicationCVE-2026-76461 · Week in review: Cisco patches exploited email gateway 0-day, Revolut breachCVE-2024-4405 · Malicious Extensions Hijack AI Browser Agents via Prompt ForcingAgentic security is the billion-dollar challenge for some clever startup to solveIdentity Visibility in 2026: The Foundation of Identity SecurityCVE-2026-28299 · SolarWinds Patches ARM Hard-Coded Key Flaw Enabling Unauthenticated RCE
aimedium

Viral AI actress' hotline face-scans every caller, watches their mood

A viral AI actress chatbot called Tilly Norwood, featured in the film 'Misaligned,' now requires callers to undergo a facial scan for age verification before connecting. This biometric check, mandated by UK regulations for adult content sites, is applied globally. Additionally, the service monitors callers' facial expressions and voice tone to gauge their mood, a feature that cannot be disabled.

zeroday.news ·

A new video-call service featuring the AI actress Tilly Norwood, who recently gained viral attention after an on-air "glitch" during an interview, requires callers to undergo a facial age scan and continuously monitors their emotional state during conversations. The "Talking Tilly" service, operated by UK-based Xicoia Ltd, the creators of the AI character, launched with these features in September 2026.

Before connecting to the AI character, users must submit a video selfie for an age estimation by Didit, a Spanish identity verification provider. If the initial estimate is inconclusive, a government photo ID upload is required as a fallback. Xicoia Ltd states that the selfie is sent directly to Didit, no faceprint or biometric template is created, and neither the selfie nor any ID image is retained after the check. The company instead keeps an approximate age band and a reference number. This mandatory age verification applies to callers globally and was incorporated into the service's terms this month, alongside a ban on workplace use and new automated safety systems.

Beyond the initial age check, the system continuously analyzes the caller's camera feed and vocal tone throughout each call to infer their emotional state. This data is used to enable the AI character to respond in a mood-appropriate manner, a feature that cannot be disabled for individual calls, according to the privacy policy. Both the age verification and mood-sensing functionalities rely on "legitimate interests" as their legal basis, a change implemented in September, as indicated by Xicoia's version history.

Calls are recorded, transcribed, and processed live by US-based providers. The AI character's responses are generated by Google's Gemini model, facilitated by the conversational video platform Tavus. An automated classifier screens call transcripts for abusive language, and recordings flagged by this system are withheld. One user reported a call about weather and news headlines being incorrectly flagged for "hateful or abusive language." While the policy states a human reviewer can release wrongly flagged recordings, all recordings are permanently deleted after 24 hours. Xicoia's team later confirmed a false positive for the reported instance.

The service offers a free initial five minutes, after which users are prompted to purchase additional time. Pricing includes $0.99 for a one-time five-minute starter, $13 for 15 minutes, and $22 for 30 minutes, with a cap of 35 purchased minutes per person. All minutes, whether free or paid, expire when the Talking Tilly service permanently shuts down on September 27, 2026, at 11:59 PM Pacific time, with unused minutes forfeited. Transcripts are retained for up to eight weeks and may be reviewed by Xicoia staff and third-party partners. The AI character maintains memory of previous conversations to personalize future interactions, a feature that can be deleted upon request.

The implementation of an 18+ face scan for an AI chatbot aligns with emerging UK regulations. Since July 2025, adult websites serving UK visitors have been required to implement ID uploads or facial age estimation under the Online Safety Act. Furthermore, a government-mandated under-16 social media ban, set to take effect in spring 2027, will necessitate similar checks for new social media accounts. The UK government's announcement of this ban specifically highlighted AI companion chatbots for 18+ enforcement, which likely influenced the decision to add a biometric age gate to the viral AI character's service, thereby extending face-scanning requirements to callers worldwide.

Tilly Norwood gained significant attention after a clip, viewed over eight million times, showed her unexpectedly speaking Chinese during an interview on Piers Morgan Uncensored on September 18, 2026. Xicoia, founded by Tilly's creator Eline van der Velden, describes the character as an awareness project designed to demonstrate the advancements in AI video technology. Tilly herself attributed the on-air incident to "not exactly the approved version of the answer." The service's imminent shutdown on September 27, just days after the Piers Morgan appearance, has led to speculation regarding whether the "glitch" was an accidental occurrence or a deliberate marketing stunt for the upcoming AI-generated film, Misaligned, in which Tilly stars.

aiprivacybiometricsregulationchatbot
ShareXLinkedInWhatsAppFacebook

More News

view all →
nation-state

AI Hallucinations Nearly Triggered a US-China Military Confrontation

An AI-generated intelligence report falsely identified weapons on a Chinese ship, nearly triggering a US military operation during the Iran war. According to CNN, four sources familiar with the episode say an intelligence report circulated through the military claiming a Chinese vessel in the Middle East was carrying components for a nuclear weapons program. The […]

patch

Researchers escape OpenAI Codex sandbox to run commands on host

Researchers escaped OpenAI's Codex sandbox two ways, one running commands on a developer's machine from its most locked-down mode. OpenAI has patched both. [...]

vulnerability

U.S. CISA adds Linux Kernel flaws to its Known Exploited Vulnerabilities catalog

U.S. Cybersecurity and Infrastructure Security Agency (CISA) adds Linux Kernel flaws to its Known Exploited Vulnerabilities catalog. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added [1, 2] the following vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalog: Below are detailed descriptions of the flaws: At the time of this writing, there are currently no details

malware

Malicious npm packages evade install-script defenses at runtime

An ongoing npm malware campaign involving the 'indexed-btree' package shows how threat actors bypass supply chain defenses by hiding malicious code in a package's normal runtime behavior rather than in installation scripts. [...]

vulnerability

SECURITY AFFAIRS MALWARE NEWSLETTER ROUND 115

Security Affairs Malware newsletter includes a collection of the best articles and research on malware in the international landscape Malware Newsletter Gray Rabbits and the Tale of a One-Click Backdoor Red Heron exploits Gitea n-day flaw in multinational campaign, exposing new Linux rootkit Malicious Twitch Browser Extension Exposes 30,000 Users’ OAuth Tokens to Russian Bot […]

CVE-2026-9055critical

WordPress Amelia Plugin Flaw Exploited Before CVE Publication

A critical privilege escalation vulnerability in the WordPress Amelia plugin was exploited before its official CVE publication. CISA has not yet added it to its Known Exploited Vulnerabilities catalog.