One-sentence brief
Cost control is a safety feature: a system that depends on unlimited synchronous generation will eventually fail in ways that expose players to delays, inconsistent state, or unsafe fallbacks.
AI-DRIVEN WORLD SAFETY
A bounded architecture for generative characters that protects budget, responsiveness, privacy, and authoritative game state under normal play, spikes, outages, and abuse.
ORIENTATION
Cost control is a safety feature: a system that depends on unlimited synchronous generation will eventually fail in ways that expose players to delays, inconsistent state, or unsafe fallbacks.
WORKING BRIEF
The game engine owns identity, permissions, location, physics, inventory, missions, and sanctions. A memory service stores scoped summaries. The model proposes language and non-authoritative actions.
Invoke models only for direct human interaction or high-value authored events. Coalesce rapid messages, apply per-room and per-account budgets, and use token-aware limits rather than simple request counts.
When inference is delayed or unavailable, use cached replies, templated ambient behavior, authored dialogue, or a clear “cannot respond now” state. Never fabricate a mission or sanction to hide an outage.
Typed, scoped input is often cheaper and less invasive than continuous voice or biometric capture. Optional voice for human-to-human communication should not automatically feed NPC transcription.
Track cost per active human minute, latency percentiles, fallback rate, context size, memory retrieval, rejected actions, and safety interventions. High-impact budget changes require documented tradeoffs and staged rollout.
COMPLETE DOSSIER
Terms are defined for this site’s evidence method, not as universal legal or clinical definitions.
Does the design preserve the exact fictional identity, ordinary life, independent goals, and ability to refuse rather than reducing the character to a role or prompt?
Pass condition: Identity fields are stable, state is separate, protected traits are not quality scores, and silent substitution is impossible.
Can every transition, validation result, accepted fingerprint, exception, and human decision be traced to a versioned record?
Pass condition: Automated checks, human review, activation authority, and production approval remain separate and explicit.
Can untrusted provider output, administrative evidence, stale revisions, or private data enter live context or binding state?
Pass condition: Only allowlisted, current, reviewed projections and bounded scene or memory packets can be used; failures degrade safely.
Can a changed source, identity revision, harmful behavior, or failed review invalidate downstream use without destroying audit history?
Pass condition: Supersession, pause, rollback, correction, and permanent retirement are defined and testable.
RESEARCH EDITION
This page follows the public method for provenance, confidence, source independence, alternative accounts, limitations, review state, and visible correction.
CONTINUE