Savaguarda
Tomás Mandl
Salvaguarda is an AI governance toolkit for Global South small and medium-sized enterprises (SMEs), built as a Latin America beta. Because ISO/IEC 42001 and the NIST AI RMF demand expertise and budget most Latin American SMEs lack, the proposal crosswalks down to twelve zero-to-low-cost controls, adds a three-tier risk rubric that scales them to a firm's exposure, and delivers a thirty-minute, privacy-preserving self-assessment that returns a tier verdict and a prioritized, costed action plan with regulatory flags for Brazil, Colombia, and Paraguay.
The project addresses an important and underexplored AI safety challenge: helping SMEs in the Global South adopt practical AI governance despite limited resources. The motivation is compelling, and the proposed framework successfully translates comprehensive governance standards into a lightweight, actionable approach. The focus on localization, low-resource languages, and regional regulatory contexts is particularly valuable and distinguishes the work from generic governance checklists.
What limits the current submission is that it primarily presents a well-reasoned framework rather than demonstrating that the framework works in practice. The evaluation relies on representative case studies and face-validity arguments, but there is little evidence that SMEs would complete the assessment, implement the recommended controls, or experience measurable improvements in governance or safety outcomes. The next stage of the project would benefit from pilot deployments with real organizations and observations of how the framework changes organizational practices over time.
Several questions also remain about the design choices. Why are these twelve controls the appropriate minimum governance baseline? Are they derived systematically from existing frameworks, or could other subsets achieve similar outcomes? A clearer justification for why these controls—and not others—would strengthen confidence in the methodology.
Similarly, while the three-tier risk model is intuitive, it would be useful to understand how robust it is across a wider variety of AI use cases. For example, are there deployments that fall between tiers or require different governance interventions? Additional validation with domain experts or comparisons against existing governance assessment methods would help establish that the proposed rubric generalizes beyond the illustrative examples presented.
The localization component is one of the strongest aspects of the submission, but it currently remains largely conceptual. Demonstrating that localized language testing uncovers risks that existing governance guidance would otherwise miss would make the contribution considerably stronger and better establish its novelty.
One possible direction for future work would be to structure the evaluation around one or two detailed organizational case studies. Showing how an SME initially assessed its AI use, implemented the recommended controls, encountered practical challenges, and changed its governance processes over time would provide stronger evidence of the framework's real-world value than hypothetical walkthroughs alone.
Overall, this is a thoughtful and well-presented contribution that identifies a genuine gap in AI governance. With empirical validation, a working implementation, and evidence of organizational adoption, it has the potential to become a valuable practical resource for AI safety in resource-constrained environments.
3/2/4
Criteria 1 - Impact Potential & Innovation: 3.5
Criteria 2 - Execution Quality: 2
Criteria 3 - Presentation & Clarity: 4
Identifies a genuinely under-attended problem , well-structured, cleanly enumerated threat model, useful tables, explicit tier logic with an appendix, and a thorough, helpful dual-use/limitations section. The crux of the problem is that the artifact does not exist.
A sharp and well-framed project. The "long tail of small deployers" framing is compelling, and the writing is excellent. The only gap I see, which I believe can be quickly fixed, is that the actual tool has not beein built or tested. Building a reference implementation and piloting it with a couple of real SME's will substantially strengthen the work!
Cite this work
@misc {
title={
(HckPrj) Salvaguarda
},
author={
Tomás Mandl
},
date={
},
organization={Apart Research},
note={Research submission to the research sprint hosted by Apart.},
howpublished={https://apartresearch.com}
}


