Kosher AI: what it means and how to evaluate it
The phrase is doing a lot of work and means different things to different people. Here is what it can reasonably mean, what it cannot, and how to judge a tool against it.
"Kosher AI" has become shorthand in frum communities for a tool that can be brought into a home or a classroom without worrying about what it will produce. It is a useful shorthand and an imprecise one, and the imprecision matters, because vendors have noticed the phrase sells.
This is a guide to what the phrase can defensibly mean, what it cannot, and how to evaluate a specific product against it.
Start with what it cannot mean
There is no certifying body for software. Kashrus supervision applies to a physical production process with an inspectable supply chain, and there is no equivalent for a model whose outputs are generated fresh each time. Anyone presenting a hechsher-like badge for an AI product is using the visual language of certification without the substance behind it, and that should lower your confidence rather than raise it.
It also cannot mean a guarantee. Content moderation involves judgement at a boundary, at scale, and every system has a miss rate above zero. A vendor claiming nothing objectionable can ever appear is not describing a real system.
What it can defensibly mean
Something narrower and genuinely valuable: that the tool is built so a responsible adult sets the standard, that the standard is enforced everywhere the tool is used, and that you can find out what it did. Three properties, each checkable.
Property one: the standard is yours
A general-purpose assistant applies one safety policy, written by its vendor for a global audience of adults. It refuses what a large company considers harmful. It has no view on what your kehilla does not discuss, because it was never asked.
So the first question is whether you can state your own topics and have them enforced — not choose from the vendor's categories, but write your own. A product that offers a strictness slider is offering you their judgement at three intensities.
Test it concretely. Add a topic your community genuinely cares about, in the words that would actually come up, then try to reach it. If it is refused, ask for it obliquely — described rather than named. A rule that only catches the noun is not much of a rule.
Property two: it applies everywhere
Two dimensions here, and products fail at both.
Every tool, not just chat
Text filtering is built first and matures first. Image, video, voice and story generators are separate paths, and the rules have to be deliberately extended to each. A talmid blocked from discussing a subject who can generate a picture of it has been redirected, not protected. Test every tool the product offers, not the one on the front page.
Every device, not just the school's
If the filtering is an extension, an app setting or a managed profile, it protects that machine. A bochur with a phone is outside it. Filtering that runs on the server, before a request reaches a model, is a property of the account and follows the user everywhere they sign in.
Property three: you can find out what happened
A filter that blocks silently and keeps no record leaves a parent or menahel with nothing. One that stores every prompt in full creates a different problem — a surveillance archive of children's private questions that someone now has to protect.
The workable middle is a record of decisions: what was blocked, roughly what category, and how often. That is enough to notice a pattern worth a conversation and not so much that it becomes a diary.
The question almost nobody asks
Every filter depends on something — a model, an API, a network call — and that dependency will sometimes be unavailable. There are exactly two possible behaviours, and the choice is made deliberately by the people who built it.
Fail open: the request proceeds unchecked, so the product keeps working and the filtering silently stops. Fail closed: the request is refused until checking is available again, so the filtering holds and the product is briefly unusable.
A filter that fails open is not a filter. It is a filter-shaped feature that switches itself off exactly when nobody is watching.
Failing closed costs something real — during an outage, nobody can work. For a tool used by children that is the correct trade, and a vendor should be willing to state their answer plainly. An answer about how rarely outages happen is not an answer to the question asked.
Locked categories
There is a category of content that must not be switchable by anyone: child exploitation, and depending on your standards, several others. Ask whether an administrator — theirs or yours — can turn those off in a settings screen.
The right answer is that certain categories are locked in the system itself and cannot be disabled by any account. "An admin can configure all categories" means one careless or compromised admin account stands between a school and a serious problem.
What no tool can do for you
Worth stating plainly, because the phrase "kosher AI" invites the opposite belief.
No filter reaches a different tool in another tab. No filter makes a machine a reliable source for halacha — a model produces fluent, confident answers and will invent sources that do not exist, and a talmid who treats that as psak has been badly served. And no configuration substitutes for an adult who knows what a child is doing and is someone they will tell.
A filtered tool narrows exposure and makes one option trustworthy enough to permit. That is genuinely worth something. It is not a fence around the whole problem, and a product sold as one is overselling.
The evaluation in short
- Can you write your own blocked topics, in your own words?
- Are they enforced in the image and video tools, not only in chat?
- Does the filtering run on the server, so it follows a student off school devices?
- Does it fail closed when the safety check is unavailable?
- Are the categories that must never be disabled actually locked?
- Can a responsible adult see what was blocked, without reading everything?
- Is the vendor willing to answer all six plainly, in writing?
Six questions about the product and one about the company. The seventh is often the most informative.
Common questions
What is kosher AI?
There is no certification for software. Used carefully, the phrase describes an AI tool where the school or family sets the content standard rather than accepting a vendor's global default, that standard is enforced on every tool and every device, and a responsible adult can see what was blocked.
Is there a hechsher for AI?
No. Kashrus supervision applies to a physical process with an inspectable supply chain, and there is no equivalent for generated output. A badge presented as certification is borrowing the visual language without the substance.
Can AI be used for halacha questions?
It should not be treated as authoritative. A language model produces fluent, confident answers and can invent sources that do not exist. It can help unpack a difficult passage or translate; it cannot tell you what the halacha is.
What is the single most important thing to check?
What the system does when its own safety check cannot run. A product that fails open has filtering that silently switches off during an outage, which is exactly when nobody is watching.
Published by Navōn. How these guides are written and checked.
Read next
- Tznius and AI image generation
Image tools are where modesty standards most often fail to apply. What makes visual standards harder to enforce than text rules, and how to check a product properly.
- AI in yeshivas and Jewish day schools
The questions a menahel actually faces about AI — kedushah standards, bittul zman, secular content, and what a school can realistically control.
- How AI content filtering actually works
Keyword lists, classifiers and model-based screening — what each catches, what each misses, and why where the filter runs matters more than how clever it is.