Skip to content
Sprint projectJun 21, 2026Bindura

Data safety for institutions

Vincent marezva · Team OFFRUITY

Submitted to Global South AI Safety Hackathon. Sprint projects are early-stage work by participants, not Apart Research publications.

Read the report

Report: Data safety for institutions

Presentation

Presentation: Data safety for institutions

Share

An overview of today’s existing institutions data safety strategy and how it can be transformed to protection within AI age

Reviews

Judging this Sprint?

Review this project

Your public critique appears on this page without your name. Your private critique is not published; only the Apart team reads it. If you agree below, we share your review with grantmaking.ai (opens in new tab) and the Transformative AI Fund so strong projects can be funded.

Not shown on this page.

Shown on this page, without your name.

Only the Apart team reads this, and funders if you agree below.

Share my name publicly on grantmaking.ai *
Share my private critique with funders *

How much would this matter for AI safety if it worked? How innovative is it? For scores of 4-5: is this actually new to the field, or replicating recent work?

Scoring guide
  1. 1Negligible. No clear problem addressed, or no meaningful novelty.
  2. 2Limited. Addresses a real problem but with a generic or well-trodden approach. Incremental at best.
  3. 3Moderate. Clear problem with a reasonable approach; some novelty in framing or method beyond routine application of existing tools.
  4. 4Significant. Important problem with an original approach, or identifies a neglected problem area. A valuable contribution others could build on.
  5. 5Exceptional. Tackles a critical AI safety problem with a genuinely novel approach, or opens a new research direction. Clear theory of change. You'd be excited to share this with researchers in the area.

How sound are methodology, implementation, and findings?

Scoring guide
  1. 1Seriously flawed. Methodology broken, results uninterpretable, or implementation doesn't work.
  2. 2Weak. Approach has significant gaps: missing validation, flawed experimental design, or incomplete implementation.
  3. 3Competent. Technically solid given the short duration. Methodology makes sense, results are interpretable, limitations acknowledged, work builds toward clear conclusions.
  4. 4Strong. Thorough methodology with convincing validation. Results clearly support conclusions. Immediately useful for future work.
  5. 5Exceptional. Ambitious scope executed rigorously. Surprising findings, novel methods, or unusually robust validation.

How clearly are work, findings, and impact potential communicated?

Scoring guide
  1. 1Incomprehensible. Cannot determine what the project is actually claiming or doing.
  2. 2Hard to follow. Key information buried, missing, or diluted by excessive length. Significant effort to extract main points.
  3. 3Clear enough. Can understand the problem, approach, and results without undue effort. Core content clearly present: problem, method, findings, limitations.
  4. 4Well presented. Easy to follow, well-structured, appropriate level of detail. Target audience would get it quickly.
  5. 5Exceptionally clear. A pleasure to read. Complex ideas made accessible. Could serve as a model for how to present this type of work.

  1. I want to be honest and useful rather than just polite, because that's more respectful of the work you put in. The underlying instinct that African institutions should control their own data infrastructure rather than depend on foreign cloud providers, and that data sovereignty is a real governance concern is sound and worth writing about. The case framing (a specific university making a specific decision to in-source its infrastructure) is also a good choice in principle, because concrete cases are more useful than abstract argument.

    But as a research submission this isn't there yet, and I'd be doing you a disservice to pretend otherwise. The first two-thirds reads as a generic IT-infrastructure checklist — acquire servers and domains, classify data, set up encryption and backups, train staff, partner with local firms. That's reasonable institutional practice, but it's not a research finding: there's no research question, no method, and the "Outcomes" (increased security, enhanced trust, cost savings) are stated as results without any measurement, baseline, or evidence behind them. Nothing here is verifiable by a reader.The bigger problem is the final section. From "artificial neuroscience" onward, the argument stops being checkable — the claims about quantum computing defeating all classical firewalls, "AI data loggers," and detecting computer-generated versus natural data aren't supported and don't connect logically to the BUSE case that came before. And the "Youth Opportunities" recommendation — giving free data access so young developers can run data-mining tools for passive income — cuts directly against the data-sovereignty and privacy argument the rest of the piece is making. That's a real internal contradiction, not a small one.

    If you want to develop this, my honest advice: drop the quantum/AI-superintelligence material entirely and write the paper that's actually underneath this — a focused case study of one institution choosing data sovereignty, with the real numbers (what it cost, what was previously outsourced, what specifically changed), the actual security controls adopted, and an honest account of the skills-gap and cost challenges. There's a genuine and publishable story in the data-sovereignty decision alone. The connection to AI safety also needs to be made explicit and argued, not assumed. There's a foundation here, but it needs to be rebuilt around evidence and kept to claims the BUSE case can actually support.

    Read full reviewShow less
  2. From an AI and data governance perspective in Africa, this case study addresses an important and practical challenge by strengthening institutional data sovereignty through local server infrastructure at BUSE. The implementation components - data classification, access controls, backups, disaster recovery, and staff training - are well aligned with common infrastructure security priorities for higher education institutions.

    The main weakness is a loss of focus in the later sections, which shift from the BUSE case study toward speculative discussion of quantum computing, advanced AI threats, and broader governance issues not clearly connected to the implemented system. Maintaining a tighter focus on the case study, with a clearer distinction between demonstrated outcomes and future directions, would strengthen both the technical coherence and credibility of the work.

  3. The manifesto is good but needs to presented well

Cite this project

@misc{marezva2026data,
  title = {{Data safety for institutions}},
  author = {Vincent marezva},
  year = {2026},
  month = jun,
  note = {Submitted to Global South AI Safety Hackathon, an Apart Research Sprint},
  howpublished = {\url{https://apartresearch.com/sprints/projects/data-safety-for-institutions-1d30}},
  url = {https://apartresearch.com/sprints/projects/data-safety-for-institutions-1d30}
}

Build something like this at the next Sprint

AI Collusion Research Sprint · Oct 23 - 25, 2026