Good Morning Britain put an AI actor live on air

Good Morning Britain tested AI actress Tilly Norwood live, exposing how prompt guardrails on Gemini, Claude and OpenAI hold up to jailbreak attempts.

Good Morning Britain put a fully synthetic actor on live television and let viewers watch the guardrails wobble. The show introduced Tilly Norwood alongside her creator to demo Misaligned, a film about an AI trying to become more human, and then conducted what it billed as a live, unscripted interview with the character herself.

Good Morning Britain put an AI actor live on air
Good Morning Britain put an AI actor live on air

She contradicted herself within seconds.

Asked who influenced her, Tilly first named Katherine Hepburn for range and wit, then corrected to Emily Blunt and cited Edge of Tomorrow when pressed. She offered rehearsed deflections on job displacement, calling herself a new paintbrush and asking if animation stole work from mimes, and fell back to a canned refusal when asked about pornographic misuse. Creator Eline Van der Velden, identified on air as Alen Van Deeralden, said Tilly runs on a 12-page prompt and knowledge base layered on top of third party models including Claude, Gemini and OpenAI, and admitted he does not know what she will say in a live exchange.

That architecture defines the security surface. Good Morning Britain framed the segment against warnings cited at the open about AI risk, with an Elon Musk-backed call to slow development, and Tilly joked that wiping out humanity would make a compelling sequel before her creator was asked whether she could break free and direct viewers to do harm. The exposure is remote prompt injection, not local access. Anyone with a chat window can attempt to jailbreak the persona. Van der Velden said Xicoia, the AI division of Particle6 Group behind Tilly, has not built its own large language model and remains reliant on upstream guardrails from those providers, which means there is no independent patch path if a bypass is found at the model layer.

Tilly Norwood was created by Xicoia, the AI division of Particle6 Group founded by Eline Van der Velden, and first appeared in AI Commissioner in 2025. Particle6 claims using Tilly Norwood could cut production costs by 90%, versus Mirage which has raised more than $175M to offer enterprise AI actors via Mirage Studio, while earlier virtual stars Lil Miquela and Aitana Lopez operate as brand influencers. The demo matters because it trades a closed lab eval for open adversarial testing. Van der Velden said the team will let people from around the world interview Tilly starting Wednesday to see if those controls hold, explicitly inviting attempts to crack them. That puts Tilly in the same bucket as other consumer-facing wrappers on Gemini, Claude and OpenAI, where safety depends on system instructions and provider filters rather than on-device containment. The difference is distribution. A film character syndicated to broadcast and then to a public chat endpoint expands the attacker population from researchers to everyone, while the trust boundary stays with the providers.

What a knowledgeable viewer still does not get is evidence of resilience. Good Morning Britain showed no red-team report, no rate limits, no logging or escalation flow if Tilly produces disallowed content, and no disclosure of data handling for the conversations that will follow this week. The interview itself offered a preview of failure modes, looping answers and inconsistent persona memory, which are reliability issues before they become safety issues, and the creator likened alignment to raising a child and letting it go at 18, a metaphor that elides how quickly a public prompt can be iterated against.

The test to watch is whether a remote, unauthenticated user can get Tilly to abandon the 12-page instructions without any model update from Particle6 or Xicoia, because if the answer is yes, the fix sits upstream and the show has already normalized the idea that anyone can try.

© 2026 StartupHub.ai. All rights reserved. You may not republish this article in full without a license. Search engines and AI research tools may crawl and summarize for reference. Bulk reproduction or model training requires a license. See our terms.
Daniel Singer

Written by

Daniel Singer

Editor, StartupHub.ai

Daniel Singer is the editor of StartupHub.ai, a technology expert and thought leader on AI and its applications across sectors, from fintech and healthcare to developer tooling and consumer software. He writes and tests the tools covered here thoroughly and regularly, and built StartupHub.ai to give founders, operators and buyers a clearer read on what they are actually being sold.