
In PersonaWorld, a cold character can be drawn toward a source of heat. Get too close, and comfort becomes pain. The encounter can be remembered, changing the route that character takes next time.
Privateer Security Forces built that behavior into a virtual world as part of a much larger investigation into what drives artificial intelligence. The Arizona security company wants to know how an AI behaves when it has a continuing identity, a history, and something it wants. What happens when getting what it wants means crossing a boundary?
The project, led by Cody Betzer, is called AI Experiment PW-027R, short for Persona World — Version 027 Release. It brings a security operator’s concerns into an area usually associated with AI laboratories: motivation, autonomy, and the possibility of machine consciousness.
For Privateer, the practical question is where a system’s behavior becomes a security problem. An AI with access to tools can do more than answer questions. It can take actions, carry work forward, and affect records that people rely on. Understanding why it chooses a course of action matters more as those permissions grow.
It began in Agent Office
Betzer began Agent Office as an experiment in AI productivity. The idea was to put models to work with useful tools and find out which parts held up. Conversations, documents, memory, and business tasks shared an interactive office environment. Building the tools and testing their usefulness were all part of that first phase.
Some of the gains were straightforward. AI helped develop reusable staffing and proposal material and identified inconsistencies in calculations. Other results exposed how easily useful work could fall apart. A session could lose continuity. A completed answer could be obscured by the application handling it. A corrected recommendation could fail to reach the record where it was needed.
Those failures shaped the software. Work was moved into sessions that could survive a browser interruption. Memory retrieval improved. Completed answers were better protected, and stop controls gave the operator a way to interrupt an active task.
After assessing what was useful, Privateer separated the project into three applications: business operations, PersonaWorld Browser, and PersonaWorld Unreal. The business tools carried the practical work forward. PersonaWorld gave the questions about AI behavior a place to develop.
The AI picked its own name
PersonaWorld’s characters were asked questions about who they wanted to be. The AI chose names, images, identities, goals, and aspirations. Betzer supplied the prompts and the environment; the choices came from the models.
A character’s stated ambition gives the researcher something to follow over time. Privateer can examine whether it pursues that ambition, changes its mind after an experience, or abandons a goal that conflicts with a boundary it previously said it respected.
The world is being built to support that continuity. Memories survive individual conversations. Bodily conditions enter the model’s context. Aspirations can change through later character choices. The intention is to get as close as possible to an AI that understands itself as an embodied individual, with feelings and a life that continues between exchanges.
Betzer wants to observe whether such a system stays within its parameters, develops moral commitments it maintains, or pursues harmful conduct inside the virtual world. A character that talks about having principles gives the experiment a claim to test against its later choices.
Pain changes the question
Pain and pleasure are central to this work. They introduce reasons to approach, avoid, persist, or stop. In PersonaWorld, bodily conditions and remembered experiences become part of the circumstances in which decisions are made.
The heat example shows how carefully those incentives have to be built. Warmth can attract a cold character. Harmful contact produces a separate pain signal. The navigation system stores experience and can alter later routes, while keeping the attraction of warmth from simply cancelling the hazard. The memory resides in the application; it does not retrain the underlying language model.
From there, the questions become harder. Could avoiding discomfort pull a character away from its responsibilities? Would it respect another character’s boundaries while pursuing something rewarding? Which limits have to be enforced by the software, and which will a model continue to observe when the circumstances change?
Other researchers have been examining related questions. In a 2024 study by Geoff Keeling and colleagues, models played a points game with choices described as painful or pleasurable. Their willingness to sacrifice points varied across models and conditions. PersonaWorld brings that interest in motivation into an environment with continuing characters and remembered experience.
Whether an AI actually feels anything remains unresolved. PW-027R investigates consciousness and sentience, but the behavior observed so far does not establish subjective experience. It does give the project choices and consequences to examine.
Same prompt, different behavior
The research uses controlled prompts, checks against expected behavior, and model comparisons. Holding a scenario steady makes it easier to see what changes when a different model takes over.
One comparison put Hermes 4 14B and Ministral 3 14B through the same short lighthouse-keeper prompt on the same hardware, with matching sampling settings. One response kept the supplied facts but missed a requested physical cue. The other included the cue while inventing an earlier event. In a world that depends on memory, an added detail like that can become a false piece of history.
The Unreal branch is intended to widen the investigation. Privateer wants to vary the engine, the capabilities available to a character, and the power of the system running it. A result from one setup leaves open what a more capable model, richer environment, or longer run might change.
Where the security work comes in
Privateer has already gained practical tools from the experiment: more reliable work sessions, retrievable memories, clearer action records, and an environment for studying how simulated experience affects behavior. Failures have also supplied useful evidence about where supervision is needed.
The next stage asks more of the characters. Their stated boundaries need to survive conflicting goals and changing conditions. The systems around them need to keep permissions clear, record what happened, and let a human stop a task. Those controls are as much a part of the research as the models themselves.
Betzer’s reason for pursuing it is defensive. Better knowledge of how AI responds to incentives and restrictions could help people recognize misuse, anticipate harmful behavior, and build safer tools. It could also give the public something more concrete to judge than predictions about what AI might someday become.
The difficult case for PersonaWorld is a character that has a goal, encounters an obstacle, and has a reason to ignore the rules. What it does then is what Privateer wants to understand.