SAFE-CARE
SAFE-CARE develops AI-driven red-teaming of code and agentic healthcare assistants in a Sweden–USA collaboration, to find vulnerabilities before adversaries do.
SAFE-CARE is a bilateral innovation project led by AI Sweden, connecting Swedish industry, public-sector actors, and cybersecurity expertise with US research partners. The project builds a modular framework for AI-driven security assessment across two tracks: AI-SAST (Static Application Security Testing) in CI/CD pipelines for software codebases, and adversarial red-teaming of agentic healthcare assistants. Development takes place in isolated sandbox environments using synthetic or representative data—without exposing sensitive production systems.
AI Sweden serves as the ecosystem bridge: a dedicated ecosystem manager receives use-case inquiries, coordinates introductions, and disseminates results to Swedish organizations.
"The modernization of our healthcare system relies on the rapid adoption of AI, but this cannot happen without guaranteed security. We need innovation to understand the unique vulnerabilities inherent to AI systems, and we must leverage AI itself to identify these security holes before malicious actors are armed with the same capabilities." – VGR Sahlgrenska representative
What is red teaming?
It is a cybersecurity practice where a group of ethical hackers (the "red team") simulates real-world attacks on a system or organization to identify weaknesses so they can be fixed.
Challenges
Generative AI is rapidly reshaping the cybersecurity landscape. Attackers can increasingly use the same models as defenders to discover and exploit vulnerabilities in code and agentic systems. Swedish organizations—especially in healthcare, public administration, and software-intensive industry—lack repeatable methods for AI-driven security testing today.
Agentic healthcare assistants combine language models, sensitive personal data, and tool use, creating new risks such as prompt injection, unauthorized data access, and tool misuse. SAFE-CARE addresses this gap through controlled environments where new AI models can be safely tested, compared, and used as defensive "microscopes"—under Swedish requirements for privacy, digital sovereignty, and operational safety.
Project purpose and expected outcomes
The objective is to move from concept to validated proof-of-concept within twelve months. The project will deliver: (1) an AI-SAST pipeline integrated into a realistic CI/CD environment, (2) an autonomous red-teaming environment for agentic healthcare assistants, (3) a Security Assessment Guide with methodology, architecture, and adoption recommendations, and (4) reusable sandbox patterns and open-source components where appropriate. Success is measured by reduced false positives, verified vulnerabilities beyond baseline tools, and documented mitigations for agentic risks. In the longer term, the project strengthens Sweden's ability to assess AI-related cyber risk and builds a foundation for continued Sweden–USA innovation cooperation.
Facts
Funding: Vinnova
Participants:
- AI Sweden (project lead)
- VGR Sahlgrenska
- Omegapoint (advisory)
US collaboration partners:
- Brigham Young University (BYU)
- Oak Ridge National Laboratory (ORNL)
- University of Utah (UU).
Advisors:
- Recorded Future
Project period: July 2026 – June 2027
For more information, contact
Related projects
AI-Powered Honeypots