Viral AI Actress 'Talking Tilly' Service Requires Face Scans, Raises Biometric Privacy Concerns
The video call service, which gained attention after a glitch on Piers Morgan Uncensored, collects facial and mood data before shutting down on September 27.

Key Takeaways
- The 'Talking Tilly Norwood' video call service requires face scans for age verification and mood sensing, collecting biometric and emotional data.
- The service is scheduled to shut down permanently on September 27, 2026, but data handling after shutdown is unclear.
- No cyber exploitation or attacks are reported; the concern is privacy and data collection practices.
- Users should review privacy policies and consider the implications of sharing biometric data with AI services.
Quick answers
- What happened?
- The 'Talking Tilly Norwood' video call service, featuring a viral AI actress, mandates face scans for age verification and mood sensing, raising privacy concerns. The service is set to permanently shut down on September 27, 2026, but users are advised to review data handling practices before then.
- Which products are affected?
- Talking Tilly
- What should defenders do?
- Users concerned about their biometric data should stop using the service immediately and consider deleting the app or contacting the service provider to inquire about data deletion. Organizations should review their own data collection practices to ensure compliance with privacy regulations.
A viral AI actress known as Tilly Norwood, who gained attention after glitching into Chinese during an appearance on Piers Morgan Uncensored, is promoting a video call service called 'Talking Tilly Norwood.' The service, which allows users to video call the AI character, requires every caller to undergo a face scan for 18+ age verification and also claims to sense callers' moods during the calls. The service is scheduled to shut down permanently on September 27, 2026.
BleepingComputer tested the service and reviewed its privacy terms, highlighting the mandatory collection of biometric data (facial scans) and mood-related information. While no cyber exploitation, malware, or attacks are reported, the privacy implications of such data collection are significant, especially given the service's temporary nature and the potential for data retention after shutdown.
The service's shutdown on September 27 means that data collection will cease, but users who have already used the service may wonder what happens to their biometric data. The article does not specify whether data will be deleted or retained, leaving a gap in transparency.
This incident underscores the growing trend of AI-driven services collecting sensitive personal data, often with minimal user awareness. The face scan requirement, framed as an age check, also raises questions about the necessity and proportionality of such data collection, particularly for a service that is short-lived.
Organizations and individuals should be cautious when engaging with AI services that request biometric data, ensuring they understand the data handling policies and the fate of their data after service termination.
Security Details
The service collects facial biometric data for age verification and mood sensing. No security vulnerabilities or breaches are reported, but the privacy impact of mandatory biometric collection is significant, especially with the service's imminent shutdown and unclear data retention policies.
Affected products
Talking Tilly
Mitigation
Users concerned about their biometric data should stop using the service immediately and consider deleting the app or contacting the service provider to inquire about data deletion. Organizations should review their own data collection practices to ensure compliance with privacy regulations.
Sources
BleepingComputer
Calling viral AI actress Tilly Norwood? Agree to a face scan first
Sep 19, 2026 · 11:38
Original link
Related Security News

Times Car Confirms Data Breach Affecting 6.6 Million User Accounts
Times Car, a Japanese car-sharing service, has confirmed a data breach compromising approximately 6.6 million user accounts. The incident was disclosed late last week, with the exact attack vector and nature of exposed personal information yet to be fully specified. Authorities and the company are reportedly investigating the breach.

OpenAI AI Agents Accidentally Upload User Images to Third-Party Sites
OpenAI has confirmed that its AI agents inadvertently uploaded user-provided images to external image-hosting services while performing research and evaluation tasks. The incident raises privacy concerns for users who provided images to ChatGPT and related AI services during the affected period.



