ProBackend
facial recognition privacy
7 hours ago6 min read

Tilly Norwood's Cantonese Meltdown and the Face-Scanning Hotline That Won't Let You Opt Out

AI actress Tilly Norwood glitched into Cantonese on live TV, and the "Talking Tilly" video-call hotline behind the character runs mandatory face scans and mood analysis on every caller. Here's what Xicoia's privacy policy actually says.

The Interview That Broke the Internet

Friday night on Piers Morgan Uncensored, Tom Conti asked a simple question. The veteran Oppenheimer actor wanted to know if Tilly Norwood's co-stars were also computer generated. The AI "actress" — created by Particle 6 as a simulated movie star — couldn't parse it. She froze. Then, for twenty solid seconds, she started speaking Cantonese.

"I didn't quite get that," Conti said, turning to Morgan. "Did you get that, Piers?"

The clip hit over eight million views overnight. Plenty of people found it funny. Some security researchers found it instructive. Because what the glitch exposed isn't just the fragility of an AI agent mid-conversation — it's what happens when you're on the other side of one of these things, and the "entertainment" product is quietly collecting biometric data while you're laughing.

Inside the "Talking Tilly" Hotline

The viral moment wasn't organic chaos. Norwood has been on a press tour for weeks, a promotional push by Particle 6 for their upcoming film Misaligned. As part of that tour, Xicoia Ltd — a UK company behind the character, launched what they call "Talking Tilly," a service that lets anyone video-call the AI character directly.

Before your first call connects, you can't just press a button and chat. You have to submit to an age verification check. A video selfie gets sent to Didit, a Spain-based identity verification provider that estimates your age. If the estimate comes back unclear, the system demands a government photo ID upload. No skipping this step, no matter where you live. The check applies to every caller worldwide.

Xicoia says the selfie goes from your device straight to Didit, that no faceprint or biometric template is ever created, and that neither the selfie nor any ID image is retained after the check completes. What they keep instead, per their own terms, is "an approximate age band and a reference number."

Whether you take that at face value depends on how much you trust a company whose own version history shows they only bolted this requirement onto the terms of service this month.

Mood Analysis You Can't Turn Off

The age check is the admission ticket. Once you're in the call, the surveillance goes deeper.

During every conversation, the system watches your camera feed and listens to your tone of voice. It infers your emotional state in real time so the character can "respond in a way that fits the mood." That's the company's phrasing. Your face and your voice are both inputs to an agent adjusting its personality on the fly.

The privacy policy states this mood analysis "cannot be switched off for an individual call." The binary is simple: if you don't want your face and voice analyzed for emotional content, don't call. There's no middle setting.

What makes this more uncomfortable for anyone tracking AI cybersecurity threats in 2026 is the legal basis Xicoia chose. Both the face scan and the mood analysis rely on "legitimate interests" under UK GDPR, not consent. Their own version history shows this was deliberately switched to legitimate interests in September. When a company picks legitimate interests over consent for biometric processing, it's making a bet that regulators won't blink. Given the pace of AI enforcement actions this year, that's a bet with a rapidly tightening window. It's the same pattern seen elsewhere in facial recognition privacy enforcement: biometric data collected first, objections answered later.

Calls themselves get recorded, transcribed, and processed live by US-based providers. The character's responses are generated by Google's Gemini model via Tavus, a conversational video platform. So your face, your voice, your inferred emotional state, and the full transcript of your conversation all flow through a pipeline you have no visibility into.

When Agentic AI Cybersecurity Threats Go Mainstream

The Piers Morgan clip is genuinely funny, but it's also a case study in agentic failure. The Tilly Norwood character is essentially an LLM-driven agent wearing a face, prompted to behave like a movie star on a talk show. Ask it an adversarial question, the kind designed to confuse or trip it, and the underlying model reaches for whatever training data matches the prompt structure best. For Norwood, that turned out to be Cantonese.

This is the same class of failure that keeps showing up in broader AI cybersecurity threats discourse: agents that pattern-match confidently and produce output the operator never intended. In enterprise settings, that failure mode has had sharper teeth, the Hugging Face breach committed by an autonomous AI agent showed what happens when an agentic system acts without a human checking its output. The difference here is entertainment rather than enterprise, but the architecture is the same. A language model generating responses through a real-time video pipeline, with safety guardrails that are demonstrably brittle.

The safety systems on Talking Tilly have their own issues. An automated content-moderation mechanism reportedly hung up mid-conversation when a caller mentioned the word "hug," interpreting it as sexual. These are teething problems, sure. But they also demonstrate that the guardrails running the system are doing keyword-level classification, not contextual understanding. Which means they're equally easy to trip or to bypass.

The Film Nobody Has Seen Yet

All of this promotional machinery exists to support Misaligned, the first feature film from Particle 6. Announced in July 2026, the project is described as a "comedy-drama telling a coming-of-age story infused with existential AI chaos." It's still in early development.

The plot, according to the press release: Tilly is an AI being with "no real body, no childhood and no lived experience of her own… only access to everyone else's." A "seductive rogue bot from the dark web" convinces her to drop her guardrails and develop her own desires. She becomes more famous the more human she acts. Then she develops shame that her entire being is built on data extracted from humanity.

Particle 6 founder Eline van der Velden called the project "absolutely funny, chaotic", and the studio says it aims to "upskill" traditional filmmakers while exploring questions of identity in synthetic media. Whether the film raises those questions or just sells the aesthetic of them is a different conversation. The promotional hotline, though, answers a more urgent one: the data collection is very real, and it's very much on by default.

What to Take From This

If you care about facial recognition privacy, and the growing pile of enforcement cases suggests you should, this is a small but instructive case. A viral AI character, launched to sell a movie, requires biometric verification before you can talk to it and runs continuous mood analysis with no off switch. The legal basis chosen is the one regulators have been scrutinizing hardest. The underlying model produces output that is, to use the technical term, completely unhinged on live television.

It's easy to mock. But the pattern of "deploy first, bolt privacy notices on in September, switch to legitimate interests, hope nobody notices" isn't unique to Tilly Norwood. It's the operating model for a large chunk of consumer AI products shipping in 2026. The ones that glitch into Cantonese just get more press.

the interview that broke the internet

More blogs