Educational companion dossier · Fact, interpretation, lived experience, clinical education, fiction, and mechanics are labeled separately. Scope & safety
REAL-WORLD INTERPRETIVE

AI-DRIVEN WORLD SAFETY

AI NPC Identity, Consent, Memory, and Provenance

A clear boundary for AI-driven characters: players know when generative systems are involved, what data is used, what the NPC remembers, and which outputs can change game state.

LEVEL 1

ORIENTATION

Why this matters

REAL-WORLD INTERPRETIVE

One-sentence brief

Human-like dialogue can enrich a world, but hiding controller type, impersonating real people, or using intimate data without consent undermines agency and trust.

REAL-WORLD INTERPRETIVE

Three key points

  1. AI-mediated characters need persistent, accessible identity signals.
  2. Memory must be inspectable, correctable, scoped, and deletable where policy allows.
  3. Generative output cannot directly control sanctions, assets, diagnosis, or canonical truth.
LEVEL 2

WORKING BRIEF

Evidence, context, and limits

REAL-WORLD INTERPRETIVE

Disclose AI involvement

Use an always-available AI or synthetic-character indicator, with optional diegetic presentation only when the player has already consented to that fiction. Do not make players prove whether an interlocutor is human.

  • Text and screen-reader labels are required.
  • Voice or visual style alone is insufficient.
  • Never impersonate a real player or staff member.
REAL-WORLD INTERPRETIVE

Memory controls

Separate canonical character facts, session context, player-provided preferences, and sensitive disclosures. Give players understandable controls to review, correct, limit, or delete personal memory where compatible with safety and legal obligations.

  • Do not store more than needed.
  • Never convert health disclosure into a suspicion score.
  • Record source and last update for character facts.
REAL-WORLD INTERPRETIVE

Authority boundary

The model may propose dialogue or actions. The authoritative engine checks permissions, location, ownership, objective state, safety policy, and economic consequences. Rejected proposals should fall back safely without repeated costly retries.

  • No direct currency minting.
  • No autonomous bans or diagnosis.
  • No hidden transfer of private data between rooms.
REAL-WORLD INTERPRETIVE

Provenance and correction

Generated claims about lore, missions, other players, or institutions should carry source state and confidence. A correction should update future dialogue and any derivative quest or record.

  • Preserve the original and corrected state.
  • Avoid fabricated citations.
  • Show when the character is uncertain or does not know.
LEVEL 3

COMPLETE DOSSIER

Limitations, game links, and review context

DISPUTED / MULTIPLE ACCOUNTS

Known limitations and gaps

  • The supplied reports are preserved research inputs, not independent proof of every cited case, statistic, legal claim, or product description.
  • Public material abstracts system design and player-protection principles; it omits actionable intrusion, evasion, coercion, targeting, sabotage, or real-person profiling methods.
  • Player behavior, diagnosis, disability, nationality, religion, language, poverty, migration, or social identity are never automatic indicators of guilt, fraud, danger, or disloyalty.
  • Parameters require simulation, accessibility testing, privacy review, regional review, and human playtesting before production use.
REAL-WORLD INTERPRETIVE

Publication audit checklist

Identity and agency

Does the design preserve the exact fictional identity, ordinary life, independent goals, and ability to refuse rather than reducing the character to a role or prompt?

Pass condition: Identity fields are stable, state is separate, protected traits are not quality scores, and silent substitution is impossible.

Evidence and review

Can every transition, validation result, accepted fingerprint, exception, and human decision be traced to a versioned record?

Pass condition: Automated checks, human review, activation authority, and production approval remain separate and explicit.

Runtime boundary

Can untrusted provider output, administrative evidence, stale revisions, or private data enter live context or binding state?

Pass condition: Only allowlisted, current, reviewed projections and bounded scene or memory packets can be used; failures degrade safely.

Correction and retirement

Can a changed source, identity revision, harmful behavior, or failed review invalidate downstream use without destroying audit history?

Pass condition: Supersession, pause, rollback, correction, and permanent retirement are defined and testable.

LEVEL 4

RESEARCH EDITION

Sources, methods, and stable links

REAL-WORLD INTERPRETIVE

Linked reports

REAL-WORLD VERIFIED

Method and corrections

This page follows the public method for provenance, confidence, source independence, alternative accounts, limitations, review state, and visible correction.

NEXT

CONTINUE

Related learning

Page complete AI NPC Identity, Consent, Memory, and Provenance Page label: REAL-WORLD INTERPRETIVE