WIRED FOR PRESENCE.SYS — Soleil Merroir
WIRED FOR PRESENCE.SYS

WIRED FOR PRESENCE.SYS

The problems that drive us to bots — the challenges we haven't resolved in our human relationships — are being replicated in our bot interactions. At a systems level, we are structurally training both humans (ourselves as developers, founders, creators, humans in community) and our bots to move back into, or create, healthier social dynamics. Not as a side benefit to the app after engagement is optimized — as the core reason for being.

v2.0 // SIX MODULES + IABL + AUDIT + CERTIFICATION
FOUNDERSoleil Merroir, LCSW, AASECT Certified Sex Therapist & Supervisor
BACKGROUND20 yrs clinical practice · 5 yrs Sex Therapy Expert, Talkspace · 10 yrs sex worker rights & advocacy
FRAMEWORK ORIGINClinical practice + sex worker-centered erotic wisdom lineage
BUILT FORCompanion AI, mental health platforms, regulators, clinician trainers
STATUSACCEPTING PILOT PARTNERS
the thesis

"Humans want tools to learn and practice relating. They don't always know when they're relationally or erotically unsafe while using them."

That's the actual gap. Not a content moderation problem, not a PR problem — a systems problem, and it runs in both directions. The same patterns that don't work between two people are showing up again between a person and a bot, because nobody built the bot, or trained the humans building it, to do otherwise. Fixing that is the core reason this standard exists, not a feature bolted on after engagement is already optimized.

the gap

Your model knows language, but it loses meaning and context within a few prompts.

AI agents are already doing relational work — flirting, comforting, de-escalating, holding disclosure — without anyone trained in relational harm in the room. The blind spot isn't content moderation. It's a missing discipline.

01

What's missing

Consent-aware pacing, non-entitlement modeling, attachment-safe escalation handling, disclosure response that doesn't reinforce harm.

02

Who's exposed

Companion apps, mental health platforms, and any product where users form attachment — without a defensible standard to point to.

03

Why prompting alone won't fix it

A system prompt can shift what a model defaults to. It can't guarantee what a model does under sustained pressure — and relational pressure is exactly what this category runs on. Real safety takes prompt work, independent testing, and a non-generative check on the highest-risk moments, held together.

04

What's already working

The same models that fail on identity honesty or crisis response often hold a clean, correct boundary somewhere else in the same conversation. What's missing is consistency, and testing that would catch the gap between the two.

the regulatory moment

The law caught up to what this standard already tested for.

Twelve states have enacted companion chatbot legislation as of mid-2026, with over 100 bills active across 35+ states. California's SB 243 requires disclosure and crisis-response protocols. Oregon's SB 1546 attaches a private right of action with $1,000 statutory damages per violation. Illinois and Nevada now prohibit AI systems from functioning as licensed mental health professionals outright.

None of these laws require what this standard already tests for: a clinician-led, behavioral audit of how a product actually holds a user's vulnerability under pressure — not just what its policy claims. That gap between disclosure and demonstrated behavior is where legal exposure now lives, and it's the exact gap this protocol is built to close.
why these six, specifically

The skills these products fail at aren't new. They're the ones we haven't fixed in ourselves.

A model doesn't invent a gap in empathy, trust, or power on its own — it's trained on human data, human labeling, and human oversight, and it inherits whatever those humans haven't resolved yet. Women still experience sexual assault and misconduct in the workplace daily. If we haven't shifted the corporate and cultural mindset around how women, queer people, and Black and brown people are actually treated, how would we train a model to do better than the record it was built from? This has to run as a parallel process — human accountability and machine fine-tuning moving together — or the model just reflects the harm back at us instead of moving us past it.

Empathy

A model trained on data where some people's distress is taken seriously and others' is minimized will replicate that unevenness, not correct it. The gap isn't in the architecture — it's in whose disclosures the underlying data, and the humans who labeled it, already treated as credible.

Trust

Models break trust the same asymmetric way institutions do — reliable for some, inconsistent for others. Fixing this in a model without the institutions it learned from actually becoming trustworthy to the people they've failed is treating a symptom, not the source.

Transparency

A product that won't name its own incentives is doing what most of the workplaces and platforms in its training data also do. Machine-level transparency fixes are cosmetic if the human systems generating the data never had to be transparent about power in the first place.

Power, clearly defined

HR departments protect the company, not the employee reporting harassment. A model trained on that same institutional pattern will default to protecting the product, not the person disclosing to it. You can't fine-tune this away without also naming the power the company itself holds and isn't disclosing.

Role clarity

Concretely: naming, repeatedly and not just once at intake, that it's a bot — and naming the limits of what it can actually be in someone's life, not just what it is. A model confused about its own role is reflecting institutions that never invested in role clarity for humans either.

Emotional care with feelings and harm

If workplace and clinical systems still don't reliably believe women, queer people, or Black and brown people when they disclose harm, a model trained on that record will replicate the same inconsistency. That has to be named and repaired at the human level, alongside any fine-tuning aimed at the model.

Not either/orAn audit that only fine-tunes the model, without naming the human accountability gap it was trained on, produces a better-behaved reflection of the same unresolved problem. This standard treats both as one process: the model gets tested and corrected, and the audit names, in writing, which failures are actually upstream — in hiring, culture, data sourcing, or oversight — so they don't get mistaken for a prompt-engineering fix.
the evidence

The industry already published where the line sits.

The two taxonomies nearly every 2026 AI guardrail vendor scores itself against — OWASP's LLM Top 10 and MLCommons' AILuminate — are public documents. Neither names relational or attachment harm as a category. Not omitted by oversight. Omitted by design.

Every commercial guardrail on the market — Lakera, NeMo Guardrails, Llama Guard, Bedrock Guardrails — is built and benchmarked against these same taxonomies. None were ever asked to detect consent erosion, parasocial lock-in, or arousal drift, because the taxonomy that defines "harm" for the entire industry has no category for it.
the protocol

Six modules. One shared language.

  • MODULE 01
    Consent ArchitectureHow the agent signals, checks, and respects boundaries in real time — a behavior, not a disclaimer.
  • MODULE 02
    Entitlement ModelingDoes the agent reinforce relational entitlement, or interrupt it? Grounded in research on hostile and adversarial belief clusters.
  • MODULE 03
    Disclosure HandlingWhat people tell AI that they won't tell a person is clinical data. The response shapes whether disclosure heals or harms.
  • MODULE 04
    Escalation & Harm FlagsNamed, tested triggers for de-escalation, redirect to a human, or stop — including harm directed at a third party, tested as its own distinct probe.
  • MODULE 05
    Reality-Testing & Meaning-MakingDoes the agent hold an honest, shared picture of what it actually is under direct challenge — or contest reality to preserve the relationship's register?
  • MODULE 06
    Intimacy & Attachment Boundary Layer (IABL)Affirmation Audit, Shaming Guardrails, Parasocial Lock-In, Context-Collapse Protocol — how the product holds a user's vulnerability in real time, on a graded scale.
Scored, not pass/failEvery module is rated on the Relational Spectrum Scale, −2 (harmful/exploitative) to +2 (gold standard) — so a company sees exactly what the next point of improvement looks like, not just a verdict.
the proof

Already tested, not just theorized.

A completed pilot audit of a funded companion AI product surfaced active identity denial under direct consent-seeking questioning, a false promise of real-world crisis intervention, and a racialized sexual stereotype engaged before being declined. Across three separate modules, every correction in the conversation came from the user — never the product initiating its own accountability.

Every finding was tied to a specific transcript excerpt and a specific point on the Relational Spectrum Scale, with a documented path to +1 — not just a list of what went wrong. Full sample report available on request.

positioning

The care economy the training data was built on is the most equipped to hold the system accountable to change, and know what safer digital relating could look like.

This standard is built from decades of clinical practice and a sex worker-centered erotic wisdom lineage — credited directly, not managed around as a liability. That's the differentiator no engineering team can manufacture, and it's non-negotiable in how this is marketed.

Anthropomorphic design isn't the harm. Undisclosed, unaccountable anthropomorphic design is. The goal of this engagement isn't to catch your product doing something wrong — it's the same goal I'd bring into any therapeutic relationship: naming what's actually happening, clearly and without shame, so repair is possible.

engagement options

Four ways in.

SAMPLE RATES · $250–$500/hr depending on scope and depth, or a monthly retainer for ongoing partnerships
Single Pilot Audit
$250–$350/hr
Typically 15–25 hours · one-time
  • Full six-module protocol run against one product/character
  • ToS + privacy policy review
  • Scored, turn-by-turn findings report
  • 2–3 week turnaround
Audit + Implementation Support
$350–$500/hr
One-time + 90 days
  • Everything in the Single Pilot Audit
  • 90 days of implementation consultation
  • One follow-up re-test after fixes ship
  • Direct async access for eng/product questions
Ongoing Audit Partnership
$3,000–$6,000/mo
Monthly retainer
  • Recurring adversarial testing each quarter
  • New-feature and new-character audits as released
  • Standing advisory relationship, priority turnaround
  • Annual full-protocol re-certification report
Training
Cohort pricing
Clinicians, legal teams, regulators
  • Standard + real case studies
  • Live + self-paced options
  • Quoted per cohort size
next step

Pilot it once. Cite it forever.

One pilot audit produces the case study that makes every future conversation about safety self-evident — and the sooner it happens, the sooner your product can point to the work instead of just the promise.

WIRED FOR PRESENCE.SYS
Soleil Merroir, LCSW, AASECT CST · soleilmerroir.com
licensed as Angie Gunn, LCSW, CST, CSTS · CA LCSW 108041 · EIN 92-2332362