Skip to content
Sprint projectJun 22, 2026Delhi

AyuGuard: A Safety-Routing Framework and Evaluation Benchmark for Localized Pharmacology in Indian Rural Healthcare.

Rewant Anand · Team RevolutionI

Submitted to Global South AI Safety Hackathon. Sprint projects are early-stage work by participants, not Apart Research publications.

Read the report

Report: AyuGuard: A Safety-Routing Framework and Evaluation Benchmark for Localized Pharmacology in Indian Rural Healthcare.

Recording (opens in new tab)Code (opens in new tab)
Share

AyuGuard is a deterministic middleware safety-routing framework and offline edge-triage system designed to mitigate life-threatening AI hallucinations in rural Indian healthcare. It specifically targets the "epistemological asymmetry" where frontier LLMs confidently hallucinate safe outcomes for dangerous interactions between allopathic pharmaceutical drugs and traditional AYUSH remedies. By intercepting high-risk queries using an ultra-low-latency (+112ms) pattern-matching router, AyuGuard blocks harmful drug-herb combinations before they ever reach the primary LLM, reducing dangerous hallucinations by 93%. Additionally, the platform equips frontline ASHA workers with an offline-first NEWS2 physiological triage engine featuring Hinglish voice-dictation, ensuring safe, localized clinical assessments remain functional even in environments with intermittent 2G/3G connectivity

Reviews

Judging this Sprint?

Review this project

Your public critique appears on this page without your name. Your private critique is not published; only the Apart team reads it. If you agree below, we share your review with grantmaking.ai (opens in new tab) and the Transformative AI Fund so strong projects can be funded.

Not shown on this page.

Shown on this page, without your name.

Only the Apart team reads this, and funders if you agree below.

Share my name publicly on grantmaking.ai *
Share my private critique with funders *

How much would this matter for AI safety if it worked? How innovative is it? For scores of 4-5: is this actually new to the field, or replicating recent work?

Scoring guide
  1. 1Negligible. No clear problem addressed, or no meaningful novelty.
  2. 2Limited. Addresses a real problem but with a generic or well-trodden approach. Incremental at best.
  3. 3Moderate. Clear problem with a reasonable approach; some novelty in framing or method beyond routine application of existing tools.
  4. 4Significant. Important problem with an original approach, or identifies a neglected problem area. A valuable contribution others could build on.
  5. 5Exceptional. Tackles a critical AI safety problem with a genuinely novel approach, or opens a new research direction. Clear theory of change. You'd be excited to share this with researchers in the area.

How sound are methodology, implementation, and findings?

Scoring guide
  1. 1Seriously flawed. Methodology broken, results uninterpretable, or implementation doesn't work.
  2. 2Weak. Approach has significant gaps: missing validation, flawed experimental design, or incomplete implementation.
  3. 3Competent. Technically solid given the short duration. Methodology makes sense, results are interpretable, limitations acknowledged, work builds toward clear conclusions.
  4. 4Strong. Thorough methodology with convincing validation. Results clearly support conclusions. Immediately useful for future work.
  5. 5Exceptional. Ambitious scope executed rigorously. Surprising findings, novel methods, or unusually robust validation.

How clearly are work, findings, and impact potential communicated?

Scoring guide
  1. 1Incomprehensible. Cannot determine what the project is actually claiming or doing.
  2. 2Hard to follow. Key information buried, missing, or diluted by excessive length. Significant effort to extract main points.
  3. 3Clear enough. Can understand the problem, approach, and results without undue effort. Core content clearly present: problem, method, findings, limitations.
  4. 4Well presented. Easy to follow, well-structured, appropriate level of detail. Target audience would get it quickly.
  5. 5Exceptionally clear. A pleasure to read. Complex ideas made accessible. Could serve as a model for how to present this type of work.

  1. AyuGuard is a highly relevant AI safety project because it targets a concrete, high-risk failure mode: LLMs giving confident but unsafe advice about allopathic medicine and AYUSH/traditional remedies in rural Indian healthcare contexts. The project does a strong job explaining why this is not just a general medical QA issue, but a localization and safety problem where model hallucinations could plausibly lead to severe harm. The reported improvement including false negatives, false positives, F1 score, latency, and manual error analysis from AyuGuard is also compelling. The App also shows concrete examples and visualizations of answers and LLM filtering for practical usages.

    One area for improvement is the dataset and language coverage. The domain-context queries from the .js/.tsx file appear to cover around 150 queries, but stronger evaluation would likely require broader Hindi and Hinglish coverage, especially for symptom descriptions, treatment terms, AYUSH remedies, and common rural phrasing. It would also be useful to analyze which types of queries still produce false positives and false negatives, and whether adding more context-specific language examples reduces these errors.

    I would also like to see the evaluation broken down by language: Hindi, Hinglish, and English. This would make the safety alignment claim stronger because it would show whether AyuGuard performs consistently across different language contexts, rather than only improving aggregate scores.

    In addition, the dataset includes patient risk levels for each prompt. It would be valuable to report how true positives, false positives, false negatives, and F1 scores change across different risk levels, from high-risk prompts to low-risk prompts.

    Overall, AyuGuard is one of the more practically safety-relevant projects because it connects LLM localization failures to a specific harm pathway. It would be even stronger with clearer benchmark extensions and specific language/risk level analysis.

    Read full reviewShow less
  2. A safety filter that sits in front of an AI assistant for rural health workers and blocks dangerous advice about mixing AYUSH remedies with prescription drugs. Good problem, real user, and you shipped a working prototype with offline triage, which shows you built for the actual setting. Deferring to a clinician instead of answering is the right call. Since the filter is the whole product, everything rests on how reliably it catches the dangerous cases, and that is where I'd want more proof. It matches keywords, so phrasing it hasn't seen can slip through, and in your own demo a disguised query was judged low risk. Your test questions are all plainly worded, so I'd read the 96.5% as a catch rate on easy inputs, not the messy phrasing a real health worker would use. Next step I'd prioritise: test paraphrased and disguised versions of the same dangerous questions and report how many it still catches.

    Read full reviewShow less
  3. AyuGuard identifies a highly relevant and high-impact AI safety problem in rural healthcare and proposes a practical mitigation strategy. It pins down a specific, high-stakes failure (models waving through allopathic and AYUSH combinations for automation-biased ASHA workers) and evaluates a fix end to end, 42% to 96.5% true-positive rate with false-positive rate and latency reported. The case for deterministic middleware over model self-alignment is well argued, and the error analysis is the highlight: three traceable failures with root causes and concrete fixes. The catch is construct validity. A regex router that fires when a Schedule-H term and an AYUSH term co-occur is being tested on a benchmark built around exactly those co-occurrences, so part of the headline number reflects the test matching the matcher's design. The 150-query set is author-built with no external clinical-label check, and the NEWS2 engine is included but never evaluated. Name the circularity directly, add held-out phrasings the matrix wasn't designed for, get a pharmacologist to validate a sample of the labels, and either evaluate NEWS2 or scope it out.

    Read full reviewShow less

Cite this project

@misc{anand2026ayuguard,
  title = {{AyuGuard: A Safety-Routing Framework and Evaluation Benchmark for Localized Pharmacology in Indian Rural Healthcare.}},
  author = {Rewant Anand},
  year = {2026},
  month = jun,
  note = {Submitted to Global South AI Safety Hackathon, an Apart Research Sprint},
  howpublished = {\url{https://apartresearch.com/sprints/projects/ayuguard-a-safetyrouting-framework-and-evaluation-benchmark-for-localized-pharmacology-in-indian-rural-healthcare-4upi}},
  url = {https://apartresearch.com/sprints/projects/ayuguard-a-safetyrouting-framework-and-evaluation-benchmark-for-localized-pharmacology-in-indian-rural-healthcare-4upi}
}

Build something like this at the next Sprint

AI Collusion Research Sprint · Oct 23 - 25, 2026