AI Companion Service Pairs Biometric Age Checks With Always-On Emotional Inference
What happened
Xicoia Ltd, the UK company behind a viral AI actress service called Tilly Norwood, requires callers to submit a video selfie processed by Spain-based Didit for automated age verification before any interaction begins, as reported by Bleaching Computer. The company relies on legitimate interests rather than explicit consent as its legal basis for this biometric processing under UK data protection law. During calls, the system infers users' emotional states through continuous camera and voice analysis, a feature the service does not allow users to disable. Xicoia frames this design as a response to the UK Online Safety Act's age-assurance requirements, which compel platforms likely accessed by minors to implement age verification. The arrangement also creates a cross-border biometric data flow from UK users to a Spanish processor, raising transfer-compliance questions that the service's public documentation does not fully address.
Why it matters
- ·Using legitimate interests as the legal basis for face scanning before a call is contestable under UK GDPR. A supervisory authority challenge could invalidate the age-verification architecture and expose the operator to enforcement, regardless of whether the underlying age-check obligation is genuine.
- ·Always-on emotional inference that cannot be disabled by users is a significant data-minimization and purpose-limitation problem. Under most data protection frameworks, including UK GDPR, affective computing outputs qualify as inferred sensitive data, and processing them without an opt-out mechanism is difficult to defend.
- ·Enterprises procuring or deploying AI companion or persona services face a vendor due-diligence gap: this case shows that age-verification compliance in one jurisdiction can embed biometric and affective data practices that create independent liability in others, making third-party intake assessments more complex.
Governance controls affected
What to do now
- ☐Audit any AI companion or persona services in your vendor portfolio to determine whether age verification is implemented using biometric processing and what legal basis is documented.
- ☐Review whether any procured or deployed AI services perform continuous affective inference and confirm that users have a meaningful opt-out mechanism; flag services that do not for escalation.
- ☐Assess cross-border data flows where biometric data collected in one jurisdiction is processed by a third-party vendor in another, and verify that transfer mechanisms are documented and adequate.
- ☐Update your third-party AI vendor intake questionnaire to explicitly ask about age-verification methods, the legal basis for biometric processing, and whether emotional inference features can be disabled.
- ☐Brief your data protection officer on the legitimate-interests-as-basis-for-face-scanning pattern so your organization does not replicate this design in any internally deployed AI service.
What to watch next
The UK Information Commissioner's Office has not yet issued definitive guidance on whether legitimate interests is a permissible basis for biometric age verification under Online Safety Act-mandated schemes, and enforcement posture on affective computing remains unsettled. Compliance teams should monitor ICO outputs under the Regulations Requiring the ICO to Produce a Statutory AI and Automated Decision-Making Code of Practice and watch whether Ofcom's age-assurance standards begin specifying permissible data-processing architectures. The Anthropic age assurance policy covered in Anthropic's Age Assurance Policy Shifts Minor-Access Compliance Onto Deployers is a related signal that minor-access obligations are being pushed down supply chains in ways that force deployers to make consequential data-architecture choices.
Stay ahead of stories like this
Get every UK AI governance development like this one, plus the rest of the week's developments. Every Thursday.
