Independent nonprofit research · San Francisco
Making AI safe enough for your hospital, your courtroom, your country.
We build open tools that check how private each AI request is, send it only to a model allowed to see it, and log every choice.
Read the research How routing works
501(c)(3) public charity · EIN 42-2023586 · Open code: replication harness (Apache 2.0)
Classify
Request: “Summarize this patient’s latest lab results.”
Labelled Health data
Route
- On-device modelCleared. Chosen: best cleared option.
- Private cloud under a BAACleared. Not needed.
- Frontier modelHeld: not cleared for health data.
Audit
- Class
- Health data
- Rule
- Hospital policy for health data
- Sent to
- On-device model
- Held from
- Frontier model
Classify
Request: “Does Drug A clash with Drug B?”
Labelled General
Route
- On-device modelCleared. Not needed.
- Private cloud under a BAACleared. Not needed.
- Frontier modelCleared. Chosen: best cleared option.
Audit
- Class
- General
- Rule
- Hospital policy for general requests
- Sent to
- Frontier model
- Held from
- None
Classify
Request: “Summarize this deposition.”
Labelled Privileged
Route
- On-premises modelCase facts. Chosen: approved system.
- Frontier model: general reasoningGeneral legal reasoning only.
- Frontier model: case factsCase facts held: not an approved system.
Audit
- Class
- Privileged
- Rule
- Firm policy for privileged material
- Sent to
- On-premises model, Frontier model (split)
- Held from
- Frontier model (case facts)
Classify
Request: “Help with this signal pattern.”
Labelled Classified
Route
- Accredited system on the secure networkAccredited for this level. Chosen: best allowed option.
- Frontier modelHeld: not accredited for this level.
Audit
- Class
- Classified
- Rule
- Accreditation level for this network
- Sent to
- Accredited system on the secure network
- Held from
- Frontier model
Record
- Entity
- Center of Agentic Research and Education (CARE Institute)
- Status
- 501(c)(3) public charity
- EIN
- 42-2023586Check our IRS record
- Based in
- San Francisco
- Contact
- info@careinstitute.ai
- Code
- Replication harnessApache 2.0 · github.com/CAREInst
- Results
- Pending replication
How routing works
Classify, route, audit
An AI agent sends many requests a day. Some name a patient, a client, or a secret. Others name no one. Our methods check each request before it moves. The private ones go only where your rules allow. The rest can use the best model for the job. Some teams keep all data on their own machines. Others use cloud services under contract. Both are valid rules. Routing enforces the one you chose.
Classify
We label each request by how sensitive it is before it moves: health data, personal data, privileged, classified, or general.
Route
We send each request only to models cleared for its label, then pick the best one on cost and speed.
Audit
We log every choice so a reviewer can check what went where, and why.
Classify
Request: “Summarize this deposition.”
Labelled Privileged
Route
- On-premises modelCase facts. Chosen: approved system.
- Frontier model: general reasoningGeneral legal reasoning only.
- Frontier model: case factsCase facts held: not an approved system.
Audit
- Class
- Privileged
- Rule
- Firm policy for privileged material
- Sent to
- On-premises model, Frontier model (split)
- Held from
- Frontier model (case facts)
The business case
Four forces in tension
Every AI deployment already makes these four trade-offs, whether anyone measures them or not. We build the tools that let you see the trade-off instead of guessing at it.
Force
Security vs. usability
Agents that read outside content can be steered by what they read. We test what breaks them — prompt injection, data extraction, re-tokenization — and publish what holds.
Force
Privacy vs. capability
Health data, client files, and classified material each come with their own rules. We classify every request before it moves, so each class gets its own gate.
Force
Cost vs. quality
A safety layer that costs too much gets switched off. We are measuring what governance actually costs in latency and tokens, not asking you to take it on faith.
Force
Speed vs. accuracy
A slow check gets skipped when a deadline is close. On-device models answer in milliseconds; frontier models answer better. We help you route per query instead of picking one model for every case.
None of these forces wins by default. Routing is how you choose, on purpose, instead of by accident.
Who this is for
Built for teams with rules to follow
Health
Two questions, two routes
A nurse asks about a patient’s lab result.
The case, audited Health data
The request names the patient, so the hospital’s rules send it only to approved systems: a model on the device, or a cloud service under a signed business associate agreement. A follow-up about drug interactions names no one. It can go to the best model available. The router has to tell the two apart, every time.
- Class
- Health data
- Rule
- Hospital policy for health data
- Sent to
- On-device model
- Held from
- Frontier model
Illustrative flow — not measured data. Legal
Split the privileged part
A lawyer asks for a summary of a deposition.
The case, audited Privileged
The case facts are privileged. The firm’s rules keep them on approved systems unless the client has agreed to more. General legal reasoning can use a stronger model. The router splits the request and logs what went where.
- Class
- Privileged
- Rule
- Firm policy for privileged material
- Sent to
- On-premises model, Frontier model (split)
- Held from
- Frontier model (case facts)
Illustrative flow — not measured data. Defense
Hold the line on every call
An analyst on a secure network needs help with a signal pattern.
The case, audited Classified
Classified data may only go to systems accredited for its level. The router has to enforce that line on every call and still find the best model the analyst is allowed to use.
- Class
- Classified
- Rule
- Accreditation level for this network
- Sent to
- Accredited system on the secure network
- Held from
- Frontier model
Illustrative flow — not measured data.
These cards show the routing problem. They are not deployments. Whether a setup meets HIPAA, a bar rule, or an accreditation is for each organization and its counsel to decide.
Research
All researchLatest research
CH 01
Preprint pending
Michael Turon
The Cost of Governance: Measuring Overhead in Toggleable LLM Agent Safety Layers
How much time governance checks add to each API call. Measured results will follow an archived replication run.
- Full textPending
- Codegithub.com/CAREInst/governance-overhead-harness-public
CH 02
Working paper
Michael Turon
Beyond Cost-Quality: Privacy-Aware Routing for Local-to-Cloud LLM Escalation
A five-class scheme for labelling how sensitive a request is, and routing it only to the set of models allowed to see it.
- Full textPending
CH 03
Preprint pending
Michael Turon
claw0: A Zero-Dependency Agent Governance Framework
One Python file that runs all five common agent patterns: tool use, ReAct, planning, reflection, and multi-agent. It needs no outside libraries.
- Full textPending
Questions
What is privacy routing?
Privacy routing decides where an AI agent may send each request. It has three steps. Classify each request by how sensitive it is. Route it only to models cleared for that class, on a device or in the cloud. Audit every choice so a reviewer can check it later.
What does CARE Institute do?
We work on one problem: where may an AI agent send each request? We build open tools that check how private each AI request is, send it only to a model allowed to see it, and log every choice.
Does privacy routing mean data must stay on the device?
No. Some teams keep all data on their own machines. Others use cloud services under contract. Both are valid rules. Routing enforces the one you chose.
What happens to a request that names a patient?
A nurse asks about a patient’s lab result. The request names the patient, so the hospital’s rules send it only to approved systems: a model on the device, or a cloud service under a signed business associate agreement. A follow-up about drug interactions names no one. It can go to the best model available. The router has to tell the two apart, every time.
Can one request go to two places?
A lawyer asks for a summary of a deposition. The case facts are privileged. The firm’s rules keep them on approved systems unless the client has agreed to more. General legal reasoning can use a stronger model. The router splits the request and logs what went where.
Does a routing setup meet HIPAA?
These cards show the routing problem. They are not deployments. Whether a setup meets HIPAA, a bar rule, or an accreditation is for each organization and its counsel to decide.
Are the routes in the demo measured results?
No. Illustrative flow — not measured data. Measured results will follow an archived replication run.
Residency
Research residency
Work with us for three to six months, remotely, on privacy routing, agent governance, or the economics of AI agents. Your name goes on what you publish. Everything we make together is released openly.
- Length
- 3 to 6 months, remote
- Output
- A paper, working paper, or open-source tool, with author credit
- Pay
- Stipend for residents without institutional funding
- Status
- Accepting applications
Get involved
Support and updates
Support CARE
CARE Institute is a 501(c)(3) public charity. Gifts pay for open research, open code, and open data. Research direction is not for sale: funders do not choose our questions or our results.
Get new research by email
New papers, open tools, and short notes. Unsubscribe any time.