# CARE Institute

Canonical: https://careinstitute.ai/
Published: 2026-09-28
Author: CARE Institute
Code licence: Apache 2.0 (https://github.com/CAREInst)

> We build open tools that check how private each AI request is, send it only to a model allowed to see it, and log every choice.

CARE Institute (Center of Agentic Research and Education) is an independent AI research nonprofit based in San Francisco.

## Classify, route, audit

An AI agent sends many requests a day. Some name a patient, a client, or a secret. Others name no one. Our methods check each request before it moves. The private ones go only where your rules allow. The rest can use the best model for the job. Some teams keep all data on their own machines. Others use cloud services under contract. Both are valid rules. Routing enforces the one you chose.

1. **Classify.** We label each request by how sensitive it is before it moves: health data, personal data, privileged, classified, or general.
2. **Route.** We send each request only to models cleared for its label, then pick the best one on cost and speed.
3. **Audit.** We log every choice so a reviewer can check what went where, and why.

What we measure: Security, Privacy, Cost, Speed.

## Four forces in tension

Every AI deployment already makes these four trade-offs, whether anyone measures them or not. We build the tools that let you see the trade-off instead of guessing at it.

- **Security vs. usability.** Agents that read outside content can be steered by what they read. We test what breaks them — prompt injection, data extraction, re-tokenization — and publish what holds.
- **Privacy vs. capability.** Health data, client files, and classified material each come with their own rules. We classify every request before it moves, so each class gets its own gate.
- **Cost vs. quality.** A safety layer that costs too much gets switched off. We are measuring what governance actually costs in latency and tokens, not asking you to take it on faith.
- **Speed vs. accuracy.** A slow check gets skipped when a deadline is close. On-device models answer in milliseconds; frontier models answer better. We help you route per query instead of picking one model for every case.

None of these forces wins by default. Routing is how you choose, on purpose, instead of by accident.

## Built for teams with rules to follow

### Health: Two questions, two routes

A nurse asks about a patient’s lab result. The request names the patient, so the hospital’s rules send it only to approved systems: a model on the device, or a cloud service under a signed business associate agreement. A follow-up about drug interactions names no one. It can go to the best model available. The router has to tell the two apart, every time.

### Legal: Split the privileged part

A lawyer asks for a summary of a deposition. The case facts are privileged. The firm’s rules keep them on approved systems unless the client has agreed to more. General legal reasoning can use a stronger model. The router splits the request and logs what went where.

### Defense: Hold the line on every call

An analyst on a secure network needs help with a signal pattern. Classified data may only go to systems accredited for its level. The router has to enforce that line on every call and still find the best model the analyst is allowed to use.

These cards show the routing problem. They are not deployments. Whether a setup meets HIPAA, a bar rule, or an accreditation is for each organization and its counsel to decide.

## Latest research

- [The Cost of Governance: Measuring Overhead in Toggleable LLM Agent Safety Layers](https://careinstitute.ai/research/cost-of-governance/): How much time governance checks add to each API call. Measured results will follow an archived replication run.
- [Beyond Cost-Quality: Privacy-Aware Routing for Local-to-Cloud LLM Escalation](https://careinstitute.ai/research/privacy-routing/): A five-class scheme for labelling how sensitive a request is, and routing it only to the set of models allowed to see it.
- [claw0: A Zero-Dependency Agent Governance Framework](https://careinstitute.ai/research/claw0/): One Python file that runs all five common agent patterns: tool use, ReAct, planning, reflection, and multi-agent. It needs no outside libraries.

Measured results will appear here once the replication run is archived (gate L12).

## What is privacy routing?

Privacy routing decides where an AI agent may send each request. It has three steps. Classify each request by how sensitive it is. Route it only to models cleared for that class, on a device or in the cloud. Audit every choice so a reviewer can check it later.

**What does CARE Institute do?** We work on one problem: where may an AI agent send each request? We build open tools that check how private each AI request is, send it only to a model allowed to see it, and log every choice.

**Does privacy routing mean data must stay on the device?** No. Some teams keep all data on their own machines. Others use cloud services under contract. Both are valid rules. Routing enforces the one you chose.

**What happens to a request that names a patient?** A nurse asks about a patient’s lab result. The request names the patient, so the hospital’s rules send it only to approved systems: a model on the device, or a cloud service under a signed business associate agreement. A follow-up about drug interactions names no one. It can go to the best model available. The router has to tell the two apart, every time.

**Can one request go to two places?** A lawyer asks for a summary of a deposition. The case facts are privileged. The firm’s rules keep them on approved systems unless the client has agreed to more. General legal reasoning can use a stronger model. The router splits the request and logs what went where.

**Does a routing setup meet HIPAA?** These cards show the routing problem. They are not deployments. Whether a setup meets HIPAA, a bar rule, or an accreditation is for each organization and its counsel to decide.

**Are the routes in the demo measured results?** No. Illustrative flow — not measured data. Measured results will follow an archived replication run.

## Research residency

Work with us for three to six months, remotely, on privacy routing, agent governance, or the economics of AI agents. Your name goes on what you publish. Everything we make together is released openly.

- Length: 3 to 6 months, remote
- Output: A paper, working paper, or open-source tool, with author credit
- Pay: Stipend for residents without institutional funding
- Status: Accepting applications

## Support CARE

CARE Institute is a 501(c)(3) public charity. Gifts pay for open research, open code, and open data. Research direction is not for sale: funders do not choose our questions or our results.

Get new research by email New papers, open tools, and short notes. Unsubscribe any time.
