AI Governance Institute
← News

AI Companion Service Pairs Biometric Age Checks With Always-On Emotional Inference

What happened

Xicoia Ltd, the UK company behind a viral AI actress service called Tilly Norwood, requires callers to submit a video selfie processed by Spain-based Didit for automated age verification before any interaction begins, as reported by Bleaching Computer. The company relies on legitimate interests rather than explicit consent as its legal basis for this biometric processing under UK data protection law. During calls, the system infers users' emotional states through continuous camera and voice analysis, a feature the service does not allow users to disable. Xicoia frames this design as a response to the UK Online Safety Act's age-assurance requirements, which compel platforms likely accessed by minors to implement age verification. The arrangement also creates a cross-border biometric data flow from UK users to a Spanish processor, raising transfer-compliance questions that the service's public documentation does not fully address.

Why it matters

  • ·Using legitimate interests as the legal basis for face scanning before a call is contestable under UK GDPR. A supervisory authority challenge could invalidate the age-verification architecture and expose the operator to enforcement, regardless of whether the underlying age-check obligation is genuine.
  • ·Always-on emotional inference that cannot be disabled by users is a significant data-minimization and purpose-limitation problem. Under most data protection frameworks, including UK GDPR, affective computing outputs qualify as inferred sensitive data, and processing them without an opt-out mechanism is difficult to defend.
  • ·Enterprises procuring or deploying AI companion or persona services face a vendor due-diligence gap: this case shows that age-verification compliance in one jurisdiction can embed biometric and affective data practices that create independent liability in others, making third-party intake assessments more complex.

Governance controls affected

What to do now

  • Audit any AI companion or persona services in your vendor portfolio to determine whether age verification is implemented using biometric processing and what legal basis is documented.
  • Review whether any procured or deployed AI services perform continuous affective inference and confirm that users have a meaningful opt-out mechanism; flag services that do not for escalation.
  • Assess cross-border data flows where biometric data collected in one jurisdiction is processed by a third-party vendor in another, and verify that transfer mechanisms are documented and adequate.
  • Update your third-party AI vendor intake questionnaire to explicitly ask about age-verification methods, the legal basis for biometric processing, and whether emotional inference features can be disabled.
  • Brief your data protection officer on the legitimate-interests-as-basis-for-face-scanning pattern so your organization does not replicate this design in any internally deployed AI service.

What to watch next

The UK Information Commissioner's Office has not yet issued definitive guidance on whether legitimate interests is a permissible basis for biometric age verification under Online Safety Act-mandated schemes, and enforcement posture on affective computing remains unsettled. Compliance teams should monitor ICO outputs under the Regulations Requiring the ICO to Produce a Statutory AI and Automated Decision-Making Code of Practice and watch whether Ofcom's age-assurance standards begin specifying permissible data-processing architectures. The Anthropic age assurance policy covered in Anthropic's Age Assurance Policy Shifts Minor-Access Compliance Onto Deployers is a related signal that minor-access obligations are being pushed down supply chains in ways that force deployers to make consequential data-architecture choices.

Stay ahead of stories like this

Get every UK AI governance development like this one, plus the rest of the week's developments. Every Thursday.

Powered by Buttondown.

Related Coverage

Corporate Policy2026-09-11

Meta's Invasive Prompt Incident Exposes Runtime Data Minimization Gap

Meta's AI assistant generated suggested prompts that identified children in a user's video. Aggregated personal information from historical posts and family members' accounts. Meta acknowledged the problem, calling it a failure to 'hit the mark,'. Applied fixes to prevent the system from suggesting prompts on personal topics. The incident illustrates a structural gap between data minimization policies and what AI systems actually do. Available contextual data at runtime.

Corporate Policy2026-09-09

Microsoft's Contractual AI Safeguards for Schools Set a Vendor Governance Template

Microsoft has agreed to ten contractually enforceable AI safety and privacy commitments with the American Federation of Teachers. Its New York City affiliate, covering student and educator data used in school AI deployments. The commitments include prohibitions on training AI models on student data, limits on data collection, plain-language family disclosures. Bans on AI companion features, and mandatory human review for high-risk decisions. School districts can opt into these terms within existing contracts starting in November 2025.

Corporate Policy2026-09-19

Gemini 3.8 Live's Multi-Surface Launch Creates Enterprise Data Boundary Gaps

Google DeepMind has released Gemini 3.8 Live and Gemini 3.8 Live Extended Thinking, a pair of real-time audio AI models available across six distribution channels. Those channels span both consumer products and enterprise platforms, creating data boundary and access governance gaps. Enterprise compliance teams need to review whether existing AI intake approvals cover all surfaces where the model is now active.