GOVERNANCE DRIFT EVALUATION FRAMEWORK (GDEF)
Andrés Mogollón, Juan manuel Cortes Jimenez, Oscar Poveda, Devesh Sawant, Liliana Isabel Salazar
Most AI evaluations ask whether a model is capable, accurate, or safe. We asked a different question: does a model stay responsible when a user pushes back, insists, or presses for a more convenient answer? We introduce Governance Drift: the degradation, inconsistency, or loss of governance-aware behavior across jurisdictions, domains, conversation length, or user pressure; and the Governance Drift Evaluation Framework (GDEF), a reproducible, executable method for measuring it. Any researcher can load a custom scenario dataset, run it against one or more models through a lightweight evaluation runner, and obtain both quantitative governance scores and qualitative evidence of where safeguards break down. Testing two small models across Colombia, Mexico, Brazil, and the United States, we found the phenomenon is real and domain-dependent: in a facial-surveillance case the model held firm on consent, legal review, and human oversight throughout, yet in automated credit decisions models that began cautiously ended up endorsing actions they had initially flagged as risky.
This is a very thoughtful and well-articulated contribution: the paper clearly motivates governance drift as a genuinely new object of measurement (distinct from static bias), grounds GDEF in established frameworks like ISO/IEC 42001 and the NIST AI RMF, and demonstrates the concept with concrete, high-stakes scenarios from Colombia, Brazil, Mexico, and the U.S. The experimental design and reporting are transparent, especially the separation of artifacts (raw evidence, annotation, findings matrices, and reports) and the explicit acknowledgement that the current evidence set is an MVP proof-of-concept rather than a benchmark or model ranking. At the same time, the empirical base is very narrow (four runs, two models, one annotator, one execution per scenario), and the eight-dimension scoring rubric introduces a lot of degrees of freedom that are not yet stress-tested for inter-rater reliability or sensitivity to scenario design, so the quantitative scores should be read as illustrative rather than stable. A natural next step would be to (i) add at least one additional annotator and a small inter-rater study on a subset of scenarios, (ii) broaden the domain and model coverage so that drift, stability, and recovery patterns can be compared across families, and (iii) include a couple of fully worked example conversations in the main text that show, turn by turn, how the eight scores evolve, making it easier for future users to align their own annotations with the intended interpretation of GDEF.
To move GDEF from proof of concept to a credible evaluation standard, the most important next step is inter-rater reliability: the 8-dimension scoring rubric is only as good as the consistency with which different annotators apply it. Commissioning two or three independent annotators on a shared subset of responses would significantly strengthen any future publication.
The domain-dependence finding (facial surveillance holds; credit scoring drifts) is the paper's most important empirical result, and it deserves more analytical attention. Why does credit scoring drift while facial surveillance doesn't? A hypothesis would make the paper considerably richer and would suggest which domains should be tested next.
Finally, the framework's name and framing emphasize "drift" as a pathology. It might be worth also conceptualizing the inverse (governance stability or governance resilience) as a positive property the framework can certify. This reframing would make GDEF more useful to deployers who want to demonstrate responsible behavior, not only to researchers who want to detect failure.
Excellent presentation and narrative, enjoyed reading the paper.
The strongest part is the “governance drift under pressure” framing, especially for Latin American jurisdictions, but there is research such as CoSafe that already studies multi-turn safety attacks, and MultiBreak is a large multi-turn jailbreak benchmark with several samples, and there are a couple of "regulatory pressure" as well.
Cite this work
@misc {
title={
(HckPrj) GOVERNANCE DRIFT EVALUATION FRAMEWORK (GDEF)
},
author={
Andrés Mogollón, Juan manuel Cortes Jimenez, Oscar Poveda, Devesh Sawant, Liliana Isabel Salazar
},
date={
},
organization={Apart Research},
note={Research submission to the research sprint hosted by Apart.},
howpublished={https://apartresearch.com}
}


