Independent nonprofit research · San Francisco

Making AI safe enough for your hospital, your courtroom, your country.

We build open tools that check how private each AI request is, send it only to a model allowed to see it, and log every choice.

Read the research How routing works

501(c)(3) public charity · EIN 42-2023586 · Open code: replication harness (Apache 2.0)

Pick a sample request
Illustrative flow — not measured data.
  1. Classify

    Request: “Summarize this patient’s latest lab results.”

    Labelled Health data

  2. Route

    • On-device modelCleared. Chosen: best cleared option.
    • Private cloud under a BAACleared. Not needed.
    • Frontier modelHeld: not cleared for health data.
  3. Audit

    Class
    Health data
    Rule
    Hospital policy for health data
    Sent to
    On-device model
    Held from
    Frontier model
Illustrative flow — not measured data.
  1. Classify

    Request: “Does Drug A clash with Drug B?”

    Labelled General

  2. Route

    • On-device modelCleared. Not needed.
    • Private cloud under a BAACleared. Not needed.
    • Frontier modelCleared. Chosen: best cleared option.
  3. Audit

    Class
    General
    Rule
    Hospital policy for general requests
    Sent to
    Frontier model
    Held from
    None
  1. Classify

    Request: “Summarize this deposition.”

    Labelled Privileged

  2. Route

    • On-premises modelCase facts. Chosen: approved system.
    • Frontier model: general reasoningGeneral legal reasoning only.
    • Frontier model: case factsCase facts held: not an approved system.
  3. Audit

Illustrative flow — not measured data.
  1. Classify

    Request: “Help with this signal pattern.”

    Labelled Classified

  2. Route

    • Accredited system on the secure networkAccredited for this level. Chosen: best allowed option.
    • Frontier modelHeld: not accredited for this level.
  3. Audit

    Class
    Classified
    Rule
    Accreditation level for this network
    Sent to
    Accredited system on the secure network
    Held from
    Frontier model

How routing works

Record

Entity
Center of Agentic Research and Education (CARE Institute)
Status
501(c)(3) public charity
Based in
San Francisco
Code
Replication harnessApache 2.0 · github.com/CAREInst

How routing works

Classify, route, audit

An AI agent sends many requests a day. Some name a patient, a client, or a secret. Others name no one. Our methods check each request before it moves. The private ones go only where your rules allow. The rest can use the best model for the job. Some teams keep all data on their own machines. Others use cloud services under contract. Both are valid rules. Routing enforces the one you chose.

  1. Classify

    We label each request by how sensitive it is before it moves: health data, personal data, privileged, classified, or general.

  2. Route

    We send each request only to models cleared for its label, then pick the best one on cost and speed.

  3. Audit

    We log every choice so a reviewer can check what went where, and why.

  1. Classify

    Request: “Summarize this deposition.”

    Labelled Privileged

  2. Route

    • On-premises modelCase facts. Chosen: approved system.
    • Frontier model: general reasoningGeneral legal reasoning only.
    • Frontier model: case factsCase facts held: not an approved system.
  3. Audit

The business case

Four forces in tension

Every AI deployment already makes these four trade-offs, whether anyone measures them or not. We build the tools that let you see the trade-off instead of guessing at it.

  • Force

    Security vs. usability

    Agents that read outside content can be steered by what they read. We test what breaks them — prompt injection, data extraction, re-tokenization — and publish what holds.

  • Force

    Privacy vs. capability

    Health data, client files, and classified material each come with their own rules. We classify every request before it moves, so each class gets its own gate.

  • Force

    Cost vs. quality

    A safety layer that costs too much gets switched off. We are measuring what governance actually costs in latency and tokens, not asking you to take it on faith.

  • Force

    Speed vs. accuracy

    A slow check gets skipped when a deadline is close. On-device models answer in milliseconds; frontier models answer better. We help you route per query instead of picking one model for every case.

None of these forces wins by default. Routing is how you choose, on purpose, instead of by accident.

Who this is for

Built for teams with rules to follow

  • Health

    Two questions, two routes

    A nurse asks about a patient’s lab result.

    The case, audited Health data

    The request names the patient, so the hospital’s rules send it only to approved systems: a model on the device, or a cloud service under a signed business associate agreement. A follow-up about drug interactions names no one. It can go to the best model available. The router has to tell the two apart, every time.

    Class
    Health data
    Rule
    Hospital policy for health data
    Sent to
    On-device model
    Held from
    Frontier model
    Illustrative flow — not measured data.
  • Legal

    Split the privileged part

    A lawyer asks for a summary of a deposition.

    The case, audited Privileged

    The case facts are privileged. The firm’s rules keep them on approved systems unless the client has agreed to more. General legal reasoning can use a stronger model. The router splits the request and logs what went where.

    Class
    Privileged
    Rule
    Firm policy for privileged material
    Sent to
    On-premises model, Frontier model (split)
    Held from
    Frontier model (case facts)
  • Defense

    Hold the line on every call

    An analyst on a secure network needs help with a signal pattern.

    The case, audited Classified

    Classified data may only go to systems accredited for its level. The router has to enforce that line on every call and still find the best model the analyst is allowed to use.

    Class
    Classified
    Rule
    Accreditation level for this network
    Sent to
    Accredited system on the secure network
    Held from
    Frontier model
    Illustrative flow — not measured data.

These cards show the routing problem. They are not deployments. Whether a setup meets HIPAA, a bar rule, or an accreditation is for each organization and its counsel to decide.

Research

All research

Latest research

  1. CH 01

    Preprint pending

    Michael Turon

    The Cost of Governance: Measuring Overhead in Toggleable LLM Agent Safety Layers

    How much time governance checks add to each API call. Measured results will follow an archived replication run.

    Measured results Pending replication

    Pending replication

    Measured results will appear here once the replication run is archived (gate L12).

    What we don’t know yet: How much time a classifier model adds when it runs on the same device. We have not measured that yet.

    Source: CARE, “The Cost of Governance” (preprint pending). Replication code: github.com/CAREInst/governance-overhead-harness-public (Apache-2.0).

  2. CH 02

    Working paper

    Michael Turon

    Beyond Cost-Quality: Privacy-Aware Routing for Local-to-Cloud LLM Escalation

    A five-class scheme for labelling how sensitive a request is, and routing it only to the set of models allowed to see it.

    • Full textPending
  3. CH 03

    Preprint pending

    Michael Turon

    claw0: A Zero-Dependency Agent Governance Framework

    One Python file that runs all five common agent patterns: tool use, ReAct, planning, reflection, and multi-agent. It needs no outside libraries.

    • Full textPending

Questions

What is privacy routing?

Privacy routing decides where an AI agent may send each request. It has three steps. Classify each request by how sensitive it is. Route it only to models cleared for that class, on a device or in the cloud. Audit every choice so a reviewer can check it later.

What does CARE Institute do?

We work on one problem: where may an AI agent send each request? We build open tools that check how private each AI request is, send it only to a model allowed to see it, and log every choice.

About CARE

Does privacy routing mean data must stay on the device?

No. Some teams keep all data on their own machines. Others use cloud services under contract. Both are valid rules. Routing enforces the one you chose.

How routing works

What happens to a request that names a patient?

A nurse asks about a patient’s lab result. The request names the patient, so the hospital’s rules send it only to approved systems: a model on the device, or a cloud service under a signed business associate agreement. A follow-up about drug interactions names no one. It can go to the best model available. The router has to tell the two apart, every time.

Can one request go to two places?

A lawyer asks for a summary of a deposition. The case facts are privileged. The firm’s rules keep them on approved systems unless the client has agreed to more. General legal reasoning can use a stronger model. The router splits the request and logs what went where.

Does a routing setup meet HIPAA?

These cards show the routing problem. They are not deployments. Whether a setup meets HIPAA, a bar rule, or an accreditation is for each organization and its counsel to decide.

Are the routes in the demo measured results?

No. Illustrative flow — not measured data. Measured results will follow an archived replication run.

The Cost of Governance

Residency

Research residency

Work with us for three to six months, remotely, on privacy routing, agent governance, or the economics of AI agents. Your name goes on what you publish. Everything we make together is released openly.

About the residency

Length
3 to 6 months, remote
Output
A paper, working paper, or open-source tool, with author credit
Pay
Stipend for residents without institutional funding
Status
Accepting applications

Get involved

Support and updates

Support CARE

CARE Institute is a 501(c)(3) public charity. Gifts pay for open research, open code, and open data. Research direction is not for sale: funders do not choose our questions or our results.

Ways to give

Get new research by email

New papers, open tools, and short notes. Unsubscribe any time.

Our email provider sends the list. Your address is used only for this list.