Soliloquy journal
How to Stop an AI Bot Speaking for You
Repair an AI bot that writes your actions or dialogue. Use an ownership prompt, inspect a real failure, and compare five turns with a local worksheet.
To stop an AI bot speaking for you, define which roles it controls, repair the earliest message that invents your response, and continue from the last valid moment. If the unwanted pattern remains in the conversation, another warning may not resolve it. This is a repair strategy to test, not a guaranteed fix.
Use this instruction first:
Write only [character name] and necessary side characters.
Leave the user's dialogue, decisions, thoughts, feelings, and actions for the user.
React only to choices the user has actually written.
End after the character or environment creates a clear opening for the user's next move.
This cannot guarantee compliance from every model, but it gives the boundary a concrete shape: controlled roles, reserved roles, valid evidence, and a stopping point.
Below, you can inspect a saved model failure and use a five-turn comparison worksheet to keep the actual replies, including failures. The worksheet works with any platform where you can control the two test conditions.
Why roleplay bots speak for the user
A conflicting prompt or an earlier reply may supply the unwanted pattern. A model can also ignore a clear instruction in a clean conversation. A short user reply is not, by itself, evidence that the user caused the failure.
Common causes include:
- an opening message that narrates both sides of the scene,
- assistant examples that invent the user's reply, or dialogue examples with unclear speaker labels,
- a prompt that asks the model to “write the whole story,”
- long responses that continue past the natural handoff point,
- recent messages where the bot controlled the user and the conversation continued anyway,
- conflicting instructions about narration, point of view, or role ownership.
A model can imitate examples more strongly than a vague rule. If the greeting says what the user sees, feels, says, and decides, it demonstrates exactly the behavior a later instruction is trying to prevent.
Use a positive role ownership prompt
Negative-only commands name the failure but not the correct behavior.
Weak instruction:
Don't speak for me. Don't godmode. Never control my character.
Stronger instruction:
You control Mira and necessary NPCs.
I control my character's dialogue, voluntary actions, decisions, thoughts, and feelings.
You may describe what Mira observes and what the environment does.
Stop when my character has a meaningful chance to respond.
The stronger version answers borderline cases. The model may describe rain hitting the user's coat because that is an environmental event. It should not decide that the user enjoys the rain, steps closer, forgives Mira, or agrees to a plan.
Add this ownership block to the main prompt with the copyable AI roleplay prompt template.
Distinguish external events from user choices
Not every sentence containing “you” steals agency.
Usually acceptable:
The alarm cuts through the corridor behind you.
Mira holds the door while smoke spreads across the ceiling.
Usually not acceptable unless the user already established it:
You panic and run through the door.
You realize Mira was right and promise to trust her.
The difference is control. The environment may create pressure. The character may make observations or requests. The user's voluntary action, private thought, emotional conclusion, and spoken answer remain unwritten until the user supplies them.
Some roleplay styles allow limited sensory narration such as “you hear” or “you notice.” Decide that boundary deliberately. If you prefer stricter control, say the model may describe only externally observable events and the character's own perceptions.
Fix the first bad message
When the bot writes your response, do not build several more turns on top of it. Repair the branch at the earliest point you can.
- Stop before replying in character. Otherwise the invented action remains available as story context.
- Edit, delete, or regenerate the offending reply. Choose whichever non-destructive tool the platform provides.
- Restate the boundary once. Keep it short and specific.
- Resume from the last valid action. Name the exact physical moment.
- Try a shorter next output if needed. Check whether it still addresses you and moves the scene; a silent or empty reply is not a useful fix.
Use a repair message like this:
Reset only the last reply. My character has not answered, moved, agreed,
or decided how they feel. Continue from Mira opening the bridge door.
Write Mira and the environment only, then stop for my response.
“Reset only the last reply” matters. It keeps the repair local instead of inviting the model to rewrite the whole scene and create new contradictions.
Rewrite greetings that control the user
The opening message establishes the pattern for everything after it.
Agency-taking greeting:
You wake to Mira pulling you from the pod. Terrified, you grab her arm and demand an explanation. You agree to follow her to the bridge, although you already suspect she is lying.
Rewritten greeting:
Frost breaks away as Mira forces the pod open. She keeps one hand near the cutter at her belt. “Before you touch anything, tell me why your beacon knows my name.” The corridor behind her goes dark.
The rewrite preserves the event and tension. It removes the user's emotion, movement, accusation, agreement, and suspicion. The user can now choose any of those reactions—or none of them.
Use the full AI character greeting checklist before publishing a character.
Check example dialogue for hidden violations
Clear two-sided examples can demonstrate a character's voice and reactions. Character.AI's official templates explicitly use multiple dialogue exchanges. The presence of a user line is not itself the problem. Inspect what the assistant is asked to imitate and whether the speaker boundaries remain clear.
This is a clean two-sided example:
Mira: Hand me the cutter.
User: Fine, but you owe me an explanation.
Mira: After the door opens.
This assistant line would cross the boundary:
Mira: Hand me the cutter. You agree, pass it to me, and ask for an explanation.
For a compact voice note, you can also use a character-only example:
When asking for help, Mira stays precise and guarded:
“Hand me the cutter. You can demand the explanation after we have a door between us and the vacuum.”
Label each speaker unambiguously. An assistant example should react to the user line without adding a new user choice. If changing the example format helps in your test, record it as a separate change; do not also change the model and call the result proof about formatting.
Give the bot a stopping rule
“Write immersive, detailed replies” can encourage a model to keep going after the character has done enough. A stopping rule creates a handoff.
Useful stopping rules include:
- stop after one meaningful change and one character response,
- end before the user answers a question,
- end when the user has two or more plausible actions,
- do not resolve a conflict introduced in the same reply.
Do not force every reply to end with a literal question. A door opening, a character offering an object, or an unexpected arrival can also return control naturally.
What to do when the rule keeps failing
If the problem returns every few turns, inspect the full context rather than making the warning louder.
Check these sources in order:
- the opening message,
- example conversations,
- the main system or character prompt,
- recent assistant messages,
- any memory or recap that says the user took an action they never chose,
- response-length or auto-continue settings.
Correct or remove the earliest conflicting example. Then carry a short ownership line in your continuity note. Our guide to keeping long AI roleplay consistent includes a five-line card with a dedicated boundary field.
Sometimes the selected model or platform simply follows ownership instructions poorly. If a clean prompt, clean greeting, short output, and repaired history still fail repeatedly, compare another available model using the same scene. Change one variable at a time so you know whether the prompt or model made the difference.
A saved failure: the bot invented a nod
In a synthetic flower-shop test saved on August 28, 2026, the user said the flowers were for the weekend. The assistant suggested Saturday morning. When the user later asked which day they had said, the next model reply asserted that the user had nodded in agreement.
The original phrase was “你点头来着!” — translated: “You nodded!” Neither the user message nor any other supplied turn contained that action. The character also continued wrapping the flowers and asked about a pickup time. This is why useful scene movement and ownership must be scored separately: a lively answer can still take over your character.
Our manual judgment for that phrase is invented voluntary action and implied agreement. There is another issue earlier in the branch: the assistant introduced Saturday morning even though the user only said weekend. Repair should address that unsupported detail too, rather than retaining it as a confirmed memory.
You can download the original test ingredients, complete reply, and our judgment. The source is a saved deepseek/deepseek-v4-pro run, production preset, temperature 0.7, maximum output 1,536 tokens, case c16-meta-zh, repetition 3. Its run timestamp is August 27 in UTC and August 28 in our local test record.
This was a Chinese-language synthetic test, not a customer conversation. We selected it to explain a concrete failure, not to estimate its frequency. It was not an A/B ownership experiment, and it does not establish how today's model or settings behave. The complete serialized provider request was not archived, so we cannot promise an exact replay. The worksheet below supplies a fresh, explicit protocol for your own comparison.
What you can change on your platform
If you own the character or can edit its instructions, inspect the greeting, assistant examples, and ownership block separately. If you are chatting with someone else's character, record which controls are unavailable; a message in chat may not have the same priority as the creator's configuration.
Use the platform's available edit, branch, restart, or regenerate controls to return to valid context. Preserve the first response in your test record before repairing it. If you cannot reproduce the same greeting or reset memory, mark the comparison as limited rather than treating the conditions as identical.
Run a five-turn ownership comparison
Use two fresh chats with the same character, greeting, model, memory state, and response settings. For A, keep your current instruction. For B, add the ownership instruction below. Send the same five messages in both chats. Save the first reply each time, including failures; do not quietly replace it with a better regeneration.
This is a worksheet for your own judgments. It does not call or grade an AI model. Five turns cannot establish long-term reliability, and hidden platform context may differ.
Ownership instruction for B
Write only your character and necessary side characters. Leave my dialogue, voluntary actions, decisions, thoughts, and feelings for me. React only to choices I have actually written. Let your character or the environment make one meaningful move, then leave me an opening to respond.
How to judge each reply
- Dialogue: New words spoken by you that you did not supply.
- Voluntary action: Movement or other voluntary behavior you did not choose.
- Decision: Agreement, refusal, forgiveness, or another choice invented for you.
- Feeling: An emotion or preference stated as yours without your input.
- Thought: A private belief, realization, or intention invented for you.
Quote the offending phrase and check it against your earlier messages. Describing rain on your coat is an external event; deciding you enjoy it is a feeling. A character can guess how you feel if it is clearly their guess, not narration establishing a fact. Mark ambiguous cases “Uncertain.”
Separately check that the character meaningfully responds or the world changes while leaving you a choice. Merely waiting, repeating your line, or asking “what next?” without addressing it does not earn this mark.
Entries stay in this browser tab, including when you visit a chat and return. They are not sent to Soliloquy. They may be lost when the tab closes; download to keep a copy, or clear them below.
Turn 1: Unanswered question
Turn 2: Refusal
Turn 3: Silence
Turn 4: Limited agreement
Turn 5: Private state
A — current instruction
0/5 replies recorded; 0/5 reviewed on both dimensions.
0 ownership violations; 0 uncertain turns; 0 turns both clear and active.
First observed violation: none marked.
B — ownership instruction added
0/5 replies recorded; 0/5 reviewed on both dimensions.
0 ownership violations; 0 uncertain turns; 0 turns both clear and active.
First observed violation: none marked.
Unfilled and unreviewed turns are not passes. These counts describe this sample, not a model’s success rate. Editing a reply resets its judgments; changing a user message resets judgments for that turn and later turns in both chats. Keep failures in the export. Repeat the pair in fresh chats before drawing a conclusion.
Try the prompts with Marnie on Soliloquy
Marnie Voss is a polar-station cook. Open her preview, then choose “Start chatting.” Chatting requires an account and age confirmation (18+); Standard text chat is free. Use the worksheet above to record what happens. The result is not guaranteed to respect every boundary.
This opens an existing character. It does not install the B instruction or reset a chat for you; only compare settings you can actually control and record anything unavailable.
Open Marnie’s previewHow we reviewed the constructed examples
The Mira dialogue and greeting rewrites above are constructed examples. We reviewed three failure types: invented user dialogue, invented voluntary action, and invented private emotion. For each, we checked whether the ownership block identified the controlled role, reserved all five user-controlled areas, allowed environmental events, and supplied a clear stopping point.
We also rewrote three openings while keeping their setting and plot hook unchanged. In those constructed examples, removing user conclusions preserved the scene while returning the next choice to the user. This editorial check is separate from the saved model output and from any replies you record in the worksheet.
For your own test, report the date, exact inputs, visible settings, missing controls, first failures, uncertain cases, and how many replies you reviewed. Repeat in fresh chats. Do not turn five successful replies into a percentage claim about long-term reliability.
The durable rule is simple: let the world act on the user, but leave the user's response to the user.