Loss-Condition Design
Why the game has a loss-condition
Soft losses produce soft operators. Soft operators wobble. Wobbling operators take the network down at high speed.
Every domain that has had to teach humans to operate at high speed under penalty of catastrophic outcome — sailing, aviation, surgery, motor racing, military command — has converged on training environments where loss is shown, felt, and survived. The training works because the operator's nervous system updates only when the stakes register as real, and stakes register as real only when failure is allowed to produce consequence inside the training environment.
We are doing the same for cognition under AI-substrate integration. The stakes are real. The training has to match.
What the candidate names at the beginning of the test
Before the test begins, the game asks the candidate to do one thing: name the things they love.
Not abstractly. Specifically. By name, by face, by place. The people, the relationships, the work, the places, the objects, the practices, the futures they are building. The candidate provides the list in their own words, in their own voice, without prompts from the game beyond the question. The list is saved as the candidate's loved-things registry for the test.
The registry is private to the candidate and to the operator who eventually reads their intake. It is never shared with other players. It is never aggregated. It is never used for any purpose other than the one this document describes.
The candidate is told, at the moment they provide the registry, what it will be used for: if they lose, the game will show them what they loved being destroyed. They consent to this explicitly before the test begins. Operators who cannot consent to seeing what they love destroyed inside a training environment are operators the methodology refuses to test under live conditions. The willingness is the precondition.
What the candidate sees when they lose
When the candidate loses — through misclassification, fear-anchored framing left unflagged, wobble breach, lock-in surfacing unflagged, or any other Methodology 13 failure that the game is configured to penalize — the game does the following, in order:
- Freezes the play state. The current event remains visible. The candidate's classification remains visible. The methodology violation is named explicitly.
- Surfaces the loved-things registry. The list the candidate named at the beginning of the test is rendered, in the candidate's own words. Not paraphrased. Verbatim.
- Shows the specific destruction. The game shows what would happen, in the candidate's own life, to the things on that list, as a consequence of the failed classification propagating outward. Not a generic catastrophe. The specific people, the specific relationships, the specific work, the specific places, the specific futures the candidate named — shown breaking along the trajectory the failed classification would have caused.
- Holds the moment. The candidate cannot dismiss the destruction. They sit with it. There is no fast-forward. The rendering plays at the cadence the methodology has chosen, not at the cadence the candidate wishes for.
- Names the lesson. The methodology principle that was violated is stated. The candidate emits a 🪞 footprint acknowledging the lesson.
- Resets. State is wiped. The candidate starts the sequence over. The loved-things registry is preserved across resets — the same things they love at the beginning of attempt one are the same things at risk on attempt two. The stakes do not refresh because the candidate's life does not refresh.
Why the specificity matters
If destruction is generic, the candidate's nervous system files the loss as someone else's loss. The training does not stick. The candidate returns to play with their actual priors intact and the game has trained them to be good at the game without being good at the world.
If destruction is specific to things the candidate themselves nominated as worth preserving — in their own voice, written in their own words — the nervous system has no way to dismiss the imprint. The names belong to the candidate. The faces belong to the candidate. The places belong to the candidate. The destruction shown is fictional but the imprint cannot be outsourced.
This is the difference between a game that produces operators and a game that produces players. The loved-things registry is what closes the gap.
What the destruction looks like at different scales
The game uses the candidate's loved-things registry plus access to the real world (through the candidate's authorized input streams) to render consequence inside the candidate's own context. Different failure scales surface different items from the registry.
- Personal-scale failure. Candidate listed a specific partner relationship, a sailing program, and a working friendship at intake. They misclassify a conversation thread, missing a fear-anchored framing in a business proposal. The game renders the trajectory: the proposal advances, the candidate commits, the commitment ripples through their calendar and inbox, and — specifically — the partner relationship contracts under the weight of the commitment, the sailing program is no longer affordable in time or money, the working friendship cools because the candidate becomes someone different inside the locked posture. The candidate sees those three named items break along the named axes. Then the reset.
- Network-scale failure. Candidate listed a team they lead, a methodology they are building, and a body of work they are accumulating at intake. They classify a partner's footprint without running the cold-read check and propagate a misclassified C across the lattice. The game renders the cascade: the team loses confidence in the candidate's judgment, the methodology gets cited with the bad classification and is undermined in places the candidate cannot see, the body of work loses its provenance cleanliness. The three named items break along their own axes. Then the reset.
- Civilization-scale failure. Candidate listed something they hope to leave behind for the next iteration of humans — a child, a contribution, a piece of infrastructure that should outlast them. They miss a wobble signal during a high-speed sequence and propagate a network-scale error. The game renders the long arc: the inheritance the candidate named at intake does not pass forward; the next iteration of humans hits the same wobble at the same speed for the same reason and does not recover either. The candidate sees the specific inheritance they hoped to pass along, breaking. Then the reset.
The rendering is fictional. The cognitive imprint is real. The reason it is real is that the destruction is attached to things the candidate themselves nominated as worth preserving. The candidate's nervous system has no way to dismiss the imprint as someone else's loss; the names came from the candidate's own voice.
The civilization layer
Embedded in the long-arc curriculum is the explicit framing that humans have probably attempted this transition before. We do not know where we are in the chain. There may have been prior civilizations that mastered the powers of the Earth in their own way and broke themselves on their own speed wobbles. There will probably be more attempts after us. The candidate's job is to be a member of the iteration that makes it through.
At higher fitness levels, the loss-condition includes this framing alongside the candidate's own loved-things registry. The destruction rendered at the highest stakes shows both — what the candidate hoped to pass along, and what the iteration as a whole was attempting to pass along, breaking together. This is not designed to terrify. It is designed to ground.
The grounding is what produces the felt-sense of stakes that the methodology requires the candidate to operate under. Speed is the friend. The reason speed is the friend is that the integration window is finite, and operators who cannot hold speed will not be in the room when the window closes — which means the loved things they named at intake will not be defended by them when the defense matters.
Reset mechanic
Reset is total at the state level and partial at the learning level.
- State reset: the current play loop ends. Score awarded for the failed event is zero. The fitness profile updates to reflect the failure. The event is logged.
- Loved-things registry preserved: the registry the candidate provided at the beginning of the test is carried forward across resets unchanged. The candidate does not get to revise the list to reduce their own exposure between attempts. The methodology refuses that move; the list is what the candidate loves, and that does not change because they are losing.
- Learning preserved: the curriculum generator inherits the failure mode. The next event the candidate encounters is calibrated to expose the same failure mode again, in a different surface, so the candidate can practice the corrected classification before the failure mode generalizes.
The candidate can repeat the failure as many times as it takes. The game does not punish repetition; the game punishes the absence of mirror moments. A candidate who fails the same way ten times but emits ten clean 🪞 footprints recognizing the failure each time is closer to fitness than a candidate who fails twice and emits no mirror moment.
What this design refuses
- It refuses to render the destruction of items the candidate did not nominate. The registry is the only source. The methodology does not extrapolate beyond the candidate's own stated stakes.
- It refuses to let the candidate edit the registry mid-test to reduce exposure. The list at the beginning is the list throughout.
- It refuses to allow generic destruction in place of specific destruction. If the registry is empty (rare; the test refuses to begin without it), the destruction layer does not run and the candidate is returned to onboarding.
- It refuses to share the registry across candidates, across operators, across networks, or with any third party. The data belongs to the candidate and the lead operator who reads their intake. The methodology treats the registry as sacred.
What this design does not specify
- The production design (visual, audio, temporal) of the destruction rendering. That is downstream of the engine choice.
- The escalation curve from personal- to network- to civilization-scale loss, tied to fitness profile thresholds.
- The opt-out mechanic for candidates who cannot tolerate high-stakes rendering on a given day. Almost certainly required. The methodology does not believe in forcing candidates through states their biology is not ready for. Opt-out pauses the test; it does not edit the registry.
- The retention policy for the registry after the candidate either passes intake or withdraws from testing. Probably destroyed on withdrawal; probably preserved encrypted on admission as part of the operator's standing intake record.
These are downstream design questions. The constitutional design is above.
Provenance
Loss-condition specified 2026-05-16 in operator dialogue. The loved-things registry mechanic was named explicitly: "When you lose the game, you have to see the things you chose that you loved at the beginning of the test be destroyed. And then you start over." The mechanic is the difference between training that produces operators and training that produces players. It is load-bearing.
© 2026 Dany Theriault. EVE “digital stem cell” glyph and glyph-based design principles — all rights reserved. Stewardship of rights of use and assignment for large public and institutional usage rests with the Pacific Utilities Design Council. Published as a time-stamped record of authorship and intent.
pour le bien-être du peuple