Field note · 5 min read

    Don't make the model your safety system

    An AI coach should never recommend an exercise that hurts someone. Here's how to enforce that without trusting the model to remember.

    5 min read4 sectionsWritten from shipped code

    01Persuasive isn't the same as safe

    Language models are good at sounding right. They're not accountable for being right. For anything that could injure a user, Zabber treats the model's output as a suggestion that has to pass through hard rules.

    02Safety starts in the data

    The enrichment pipeline tags every exercise with the joints it loads. 339 of 1,324 exercises carry at least one injury flag, most often the shoulder, lower back or knee.

    When a user describes an injury in their own words, it's mapped to joints with keyword rules rather than another model call, so the mapping is predictable and testable.

    03Enforced in the query, not the prompt

    Exclusions run inside the database query that powers the coach's search. An exercise that loads an injured joint never reaches the model as an option, so there's nothing for the model to get wrong.

    Alternatives to push-up
    • push-up plusexcluded · shoulder0.944
    • clock push-up0.941
    • raise single arm push-up0.928
    • deep push upexcluded · shoulder0.909
    • wide hand push up0.909
    • push-up (wall)0.905
    • decline push-upexcluded · shoulder0.905

    Real nearest neighbours from Zabber's embeddings · 4 of 7 shown

    Live demo · Real nearest neighbours from Zabber's data, with the shoulder filter toggled

    04Check the plan after it's written

    Generated workout plans are validated too. If a plan includes something unsafe or above the user's level, it's swapped for the nearest safe exercise using the same embeddings.

    plan picksdecline push-up
    check shoulder injury
    swapped topush-up (wall)
    Live demo · An unsafe pick caught and replaced

    Everyday swaps, like easier, harder, no-equipment or joint-friendly alternatives, are computed from the enriched data with no model call at all, which also means they can't invent an exercise that doesn't exist.

    Rules before AI: only ask a model what code can't answer

    The cheapest, most testable enrichment step is the one that never calls a model. Here's where we draw that line.

    Read next