/ /

FAQ: AI Roleplay Security Privacy & Compliance

Updated 29 days ago

Updated August 20, 2026

Purpose: This article answers common questions about AI Roleplay for customers who are evaluating the feature or navigating an internal security, privacy, or AI governance review. For a structured summary formatted for internal committee review, see the companion document: AI Roleplay Security Review Summary.

How does AI Roleplay work?

AI Roleplay gives learners simulated conversational practice with an AI-powered character, with performance feedback tied to defined scenario objectives and your learning content. During a session, AI is used to generate the character's responses, track progress toward scenario goals, assess learner performance, and produce end-of-session feedback. Voice Roleplay or the use of dictation with Text Roleplay additionally converts learner speech to text and generates spoken responses from the character.

What AI model and infrastructure does it use?

AI Roleplay uses Anthropic Claude models through AWS Bedrock and Inworld AI STT and TTS models when voice or dictation are used. Customer data is processed within this environment–not through any consumer-facing AI service. NovoEd's AI subprocessors, including Anthropic, are documented in the NovoEd Compliance Center.

What data is processed during a session?

When a Learning Experience Designer creates a scenario, the inputs they provide and the learning content in the course are processed to generate the scenario structure. No learner data is involved at this stage.

During a learner's roleplay session, the AI processes the learner's conversation turns and the context needed to conduct the session, assess progress, and generate feedback. NovoEd applies the principle of using only the data minimally necessary for the specific being performed.

For Voice Roleplay, the learner's audio is additionally processed for speech recognition, and the AI character's generated dialogue is processed to produce spoken responses.

What information does the AI character use to respond to learners?

AI Roleplay responds primarily using scenario and associated course content your organization provides, such as lesson materials, transcripts, scenario instructions, frameworks, terminology, and supporting resources. This keeps the experience grounded in what your organization intends learners to practice.

When the supplied content doesn’t cover something needed to conduct the conversation, the underlying model may draw on its general training knowledge. Providing a thorough scenario and course content minimizes the modal drawing on such general training knowledge.

Is our data used to train AI models?

No. Customer data is not used to train or develop AI models, by NovoEd or by any of its AI subprocessors. Anthropic and Inworld AI process customer data in real time, within the scope of the requested task only. NovoEd is not developing its own large language model and will not use customer data for general model development.

What security controls apply to AI roleplay?

AI roleplay operates under the same security and privacy framework as all other NovoEd capabilities. Controls include:

  • SOC 2 Type II certification

  • Encryption of data in transit and at rest

  • Logical separation of customer data

  • GDPR-aligned privacy practices

  • Documented review of AI services used as subprocessors

NovoEd’s AI subprocessors are listed in the NovoEd Compliance Center.

Who controls access to AI Roleplay?

AI Roleplay access is managed through AI Roleplay Usage Management, a dedicated control available to Organization Administrators. It offers two modes:

  • All Courses (default): roleplay is available across all courses

  • Require approval per course: each course must be explicitly approved before learners can access roleplay activities

Administrators can filter the course list to see exactly which courses have roleplay enabled, which modality types (Text, Audio, Video) are approved per course, and enable or disable access at the individual course level without additional navigation. 

This structure supports phased and controlled-audience deployments, giving organizations meaningful governance over how and where AI Roleplay is introduced.

What about sensitive, confidential, or regulated information?

Scenarios should be designed so that learners do not enter real personal, confidential, or regulated information, such as actual patient names, account numbers, or genuine PII. Fictional or simulated information is fine to use; in fact, most well-designed scenarios rely on it. A healthcare training scenario, for example, can and should simulate a patient conversation using a made-up name and fictional details.

Organizations with specific regulatory or compliance requirements, including those in healthcare or financial services, should work with their NovoEd Customer Success Manager to engage NovoEd's compliance team before deploying AI Roleplay for those use cases.

What safeguards help prevent inappropriate use?

AI Roleplay is designed for focused practice within the context of the configured learning scenario. Sessions may be terminated when a learner provides irrelevant or inappropriate input. These safeguards operate at the platform level and do not require an administrator to monitor individual sessions in real time.

Organizations should also establish appropriate learner guidance for AI-enabled activities, particularly regarding confidential, sensitive, or regulated information.

How long is roleplay data retained?

Roleplay conversations and feedback are retained for the duration of the customer's active contract and deleted upon a submitted deletion request, in accordance with NovoEd’s platform data retention policies.

Was this article helpful?
Subscribe to receive updates on this article