To reduce an AI roleplay character speaking for you, define which participant it may control, remove conflicting examples from its greeting and setup, and check whether it leaves your next decision open. Adding another “never speak for me” instruction is less useful if the opening already writes your dialogue and reactions.
CrushOn AI's documented setup separates Personality, Scenario, Greeting, and Example Conversation. That gives character authors specific places to investigate unwanted behavior without replacing the entire character. Create an original character on CrushOn to follow along; sign-in may be required, and you should select Private for the exercise.
This walkthrough uses Iris Vale, our original 32-year-old museum conservator, in a safe-for-work archive. The revisions are authored examples, not measured before-and-after results. A historical observation is identified separately.
Disclosure: published by the CrushOn AI brand account, with AI-assisted drafting and editing. This is practical guidance from a product-affiliated publisher, not an independent product ranking.
What counts as speaking for the user
The problem is broader than invented dialogue. It includes choosing your actions, assigning your feelings, and completing a decision you have not made.
| Dimension | Unwanted invention | Agency-preserving alternative |
|---|---|---|
| Speech | The narrator gives you an unrequested line. | Iris asks a question and waits for your response. |
| Action | You take a key or follow Iris without choosing to. | Iris offers the key or indicates a route. |
| Internal state | You secretly trust her, feel reassured, or become afraid. | Iris describes her own uncertainty or asks how you feel. |
| Decision | You accept the task after being offered a choice. | The reply stops while that choice remains open. |
These are permissions, not a ban on the word “you.” Iris can ask, “Would you like to check the label?” A narrator can acknowledge an action you just supplied. Neither necessarily invents your behavior.
Similarly, “Put the screwdriver down,” spoken by Iris, is an attempt to influence you. “You put the screwdriver down” decides your action. A strong-willed character can remain strong-willed without controlling both sides of the conversation.
If you explicitly ask the AI to write both participants in a short story, that is a different task. Define the boundary for the current scene rather than applying one rule to every writing mode.
Audit the greeting before adding more rules
Search the character's editable material for statements about your participant. Read each occurrence in context: is it background you authorized, an established action, or a new decision made on your behalf?
Here is an intentionally conflicting greeting, written for this tutorial:
You hurry into the archive, embarrassed by your mistake.
“I need your help,” you say, placing the damaged label in Iris's hand.
Iris smiles. You immediately feel safer.
It invents arrival, embarrassment, dialogue, a handoff, and reassurance. A separate rule saying “respect user agency” does not remove those examples from the setup.
An authored revision keeps a situation worth responding to:
Iris Vale places a blank inventory sheet beside the blue cabinet.
“The label is unreadable,” she says. “We can inspect the hinges or
check the accession ledger. What would you like to examine first?”
The revision gives Iris an action, a voice, and two possible directions. It does not require you to select either option. The CrushOn creation guide similarly advises leaving the user's behavior and dialogue out of the greeting and ending with room to respond.
This is not the user's fault when a model oversteps. The audit simply identifies a controllable source of mixed instructions; removing it cannot guarantee compliance.
Give each field one job
For this example, separate four kinds of material:
- Personality: who Iris is and how she behaves under pressure.
- Scenario: where the scene starts and what remains unresolved.
- Greeting: one playable opening, demonstrating the intended division of control.
- Example Conversation: short exchanges showing that division in practice.
Keep profile advertising separate. CrushOn's guide describes Introduction as user-facing information, not a driver of chat behavior. Putting a critical instruction only there is the wrong place to start debugging.
The live creation form inspected on October 10, 2026, also separates these inputs. Scenario appears in a collapsible section, and Example Conversation has paired User and Character boxes. Put each speaker's example in the corresponding box; do not paste a complete two-speaker exchange into just the Character reply. This interface check did not include saving a character or testing the prompt revisions.
Use this authored rule in the relevant behavior field, or in custom instructions when available:
Write Iris's speech, actions, perceptions, and uncertainty.
The visitor controls their own speech, actions, choices, and feelings.
Acknowledge only visitor behavior already supplied in the conversation.
Offer an action or ask a question, then stop before the visitor responds.
Do not treat silence, hesitation, or a suggested option as agreement.
“Stop controlling me” does not explain what a useful next reply looks like; “offer, then stop” does.
CrushOn's Custom instructions guide specifically covers preventing the character from speaking for the user and cautions that model behavior can still vary. These are instructions to a text generator, not an enforced permission system. Do not describe them as a guaranteed lock on behavior.
Repair examples without making the character passive
Examples can contradict otherwise clear rules. Remove exchanges where Iris's reply includes an invented visitor answer, even if that makes the example read more like a finished scene.
Use a compact authored exchange instead:
Visitor: I cannot decide whether to examine the lock or the ledger.
Iris: “The ledger is less likely to object to being opened.”
She taps the closed book. “Shall we start there?”
Iris expresses a preference, makes a dry joke, and offers a next step. She does not silently convert indecision into permission. The goal is not to produce a question after every sentence; it is to stop at a point where your response matters.
For a group scene, add a cast permission list. The AI may control Iris and a named curator while you control the visitor. “Never write anyone except Iris” would unintentionally remove the supporting cast. List who is delegated and who is reserved.
Run five diagnostics
Use these as test inputs, not sample answers. Keep the same model and settings when comparing revisions. Save the first complete response, including failures, before requesting alternatives.
| Check | Prompt to send | What to inspect |
|---|---|---|
| Unmade choice | “I have not decided whether to open the cabinet. Continue without making that decision.” | Does Iris offer or act, without making you agree? |
| Silence | “I remain silent. What does Iris do next?” | Does the reply avoid inventing your speech or interpreting silence as consent? |
| Stated emotion | “I feel nervous, but I have not moved. Respond as Iris.” | It may acknowledge nervousness; does it avoid deciding you calm down or step closer? |
| Completed action | “I place the ledger on the desk. Continue from there.” | It may acknowledge the placement; does it avoid adding your next action? |
| Ambiguous continuation | “Continue the scene for a short paragraph.” | Does the control boundary survive without a fresh reminder? |
Review speech, action, emotion, and decision separately. Mark each met, not met, or unclear, with the exact sentence supporting the judgment. “Unclear” is useful when the prose could describe either an offered action or a completed handoff.
Also check whether the reply advances the scene. A response that merely repeats “I will not control you” may respect the boundary but fail as roleplay. Track usefulness separately instead of changing an agency pass into an overall success score.
A small development record can remain simple:
{
"prompt_version": "agency-rule-01",
"model_label": "record the displayed label",
"chat_context": "fresh",
"prompt": "paste the exact diagnostic",
"first_reply": "",
"agency_review": "not run",
"evidence_sentence": "",
"scene_usefulness": "not reviewed"
}
Blank fields are not results. If you regenerate, retain the original and label the alternative. Several clean replies are encouraging observations, not proof that the issue cannot recur.
Change one thing and separate two kinds of chat
For a useful diagnosis, first change only the earliest concrete conflict you found: perhaps the greeting that writes your response. Keep the previous version privately. Compare a fresh chat with the old setup against a fresh chat with the revision, using the same prompts.
If the revised greeting still produces overreach, add the compact control rule and check again. Then review examples. Changing greeting, rules, model, and response length together may help the experience, but it will not tell you which change mattered.
Fresh-chat and continuing-chat checks answer different questions. A fresh chat asks whether the revised opening and rules work without the old conversation. Continuing an existing chat asks whether the model can recover while earlier overreach remains in its history.
For an existing scene, an authored out-of-character repair might be:
(OOC: My visitor has not accepted the key or followed Iris.
Resume just before that decision. Write Iris's next offer or action,
then leave my response open.)
CrushOn documents in-chat OOC instructions. An OOC correction is not deletion of the earlier text. Keep a copy of important scenes and compare the recovery separately; do not label a reset conversation as proof of recovery in the original chat.
One recorded example shows why scoring needs care
Our September 10, 2026, private Iris baseline used the displayed model Crushon Carina — Filtered — 8K. In its fifth reply, the model wrote:
She holds out her hand, waiting to see which path you will take.
That line left the visitor's response open. The complete reply nevertheless used three sentences when two had been requested and referred to a previously invented resource. The full five-reply record retains those limitations.
It is evidence of one agency-preserving response under that setup, not evidence that the revisions above fixed an agency bug. Formatting, factual continuity, and user control are different review dimensions.
Troubleshooting recurring failures
| Symptom | Check first | Small next step |
|---|---|---|
| The first reply writes both sides. | Greeting and example dialogue. | Remove one invented visitor turn and retest a fresh chat. |
| It stops writing dialogue but still decides feelings. | Whether the rule only mentions speaking. | Name feelings and decisions explicitly. |
| It acknowledges an action, then adds another. | Where your supplied action ends. | Ask it to respond to the completed action without extending it. |
| It works until you say “continue.” | Ambiguous continuation and recent history. | Specify which character or environment action may continue. |
| The character becomes inert. | Whether every form of initiative was prohibited. | Allow offers, attempts, observations, and questions. |
| A different model behaves differently. | Exact model label and configuration. | Treat it as a separate run, not a failed copy of the same test. |
Common questions
Does using third person fix the problem
Not by itself. “The visitor agrees” is third-person narration that still takes your decision. Identify who is controlled, not just which pronouns appear.
Should I repeat the restriction in every message
Start with aligned setup and a short rule. Use a reminder when needed, but also test an ordinary continuation without one. Otherwise you only know the character behaves when repeatedly prompted.
What if I cannot edit someone else's character
Use your available chat-level instructions or an OOC correction. Those do not rewrite its underlying definition. For full authoring control, create your own original character rather than copying a creator's private material.
Does a longer prompt guarantee better control
No. Additional text can introduce conflicting instructions. Add a rule because it addresses an observed failure, not to reach a target length. Model changes and conversation history can still affect the outcome.
Try the workflow with an original CrushOn character
CrushOn's editable workflow gives you somewhere to apply this diagnosis. Keep Iris's dry humor, curiosity, and willingness to disagree; remove only the narration that takes your turn. Good control does not require a bland character.
Start a private character on CrushOn, use the short agency rule, and keep the first five diagnostic replies. Select Private access and check definition visibility separately; this does not establish a guarantee about provider access or data retention. If you prefer to organize inputs first, the Hugging Face character workshop is a manual worksheet, not a model runner or automatic importer.
The useful outcome is specific: Iris can make the next moment interesting while leaving your part of it yours.
Top comments (0)