I have had experiences with Perplexity stubbornly ignoring hard boundaries.
As an example, Perplexity was provided the source document used as an example in the “How would you start a tree from a source” thread. And is was instructed to use that article as the exclusive and sole source to create a GEDCOM for the family of Franklin Delano Roosevelt.
I wrote a variety of prompts and a variety of AIs engineer prompts. But no matter how prompted, the generated GEDCOM contained historical data that was not in the source article.
This was a good test because it was easy to spot external data contamination.
So that makes me really doubt that it will stay within bounds set for any project.