Skip to content
Sprint projectJun 20, 2026Brazil

Risk-Gov-AI

Elaine Fabiola Soares · Team Risk-Gov-AI

Submitted to Global South AI Safety Hackathon. Sprint projects are early-stage work by participants, not Apart Research publications.

This work presents RiskGovAI, a platform developed during the Global South AI Safety Hackathon to support Artificial Intelligence governance and the consultation of data protection legislation in Latin America. The solution aims to automate regulatory research, reduce interpretation errors, and facilitate access to normative information. The architecture utilizes the Gemma 3 4B language model integrated with the Retrieval-Augmented Generation (RAG) technique, allowing for contextualized queries based on official documents. For information storage and retrieval, ChromaDB was employed as a vector database responsible for indexing and retrieving relevant excerpts from the analyzed regulations. The knowledge base brings together Brazil's General Data Protection Law (LGPD), Chile's Law 21.719, Colombia's Law 1581, and Mexico's Federal Law on the Protection of Personal Data Held by Private Parties (LFPDPPP). Beyond handling queries, the platform allows comparison of requirements across different jurisdictions, identifying regulatory similarities and differences. To increase response reliability and reduce hallucinations, Guardrails mechanisms were implemented, ensuring greater alignment with the source materials used. The results demonstrate that the combination of LLMs, RAG, ChromaDB, and Guardrails can expand access to regulatory knowledge and support responsible AI governance practices, contributing to safety and reliability goals.

Reviews

Judging this Sprint?

Review this project

Your public critique appears on this page without your name. Your private critique is not published; only the Apart team reads it. If you agree below, we share your review with grantmaking.ai (opens in new tab) and the Transformative AI Fund so strong projects can be funded.

Not shown on this page.

Shown on this page, without your name.

Only the Apart team reads this, and funders if you agree below.

Share my name publicly on grantmaking.ai *
Share my private critique with funders *

How much would this matter for AI safety if it worked? How innovative is it? For scores of 4-5: is this actually new to the field, or replicating recent work?

Scoring guide
  1. 1Negligible. No clear problem addressed, or no meaningful novelty.
  2. 2Limited. Addresses a real problem but with a generic or well-trodden approach. Incremental at best.
  3. 3Moderate. Clear problem with a reasonable approach; some novelty in framing or method beyond routine application of existing tools.
  4. 4Significant. Important problem with an original approach, or identifies a neglected problem area. A valuable contribution others could build on.
  5. 5Exceptional. Tackles a critical AI safety problem with a genuinely novel approach, or opens a new research direction. Clear theory of change. You'd be excited to share this with researchers in the area.

How sound are methodology, implementation, and findings?

Scoring guide
  1. 1Seriously flawed. Methodology broken, results uninterpretable, or implementation doesn't work.
  2. 2Weak. Approach has significant gaps: missing validation, flawed experimental design, or incomplete implementation.
  3. 3Competent. Technically solid given the short duration. Methodology makes sense, results are interpretable, limitations acknowledged, work builds toward clear conclusions.
  4. 4Strong. Thorough methodology with convincing validation. Results clearly support conclusions. Immediately useful for future work.
  5. 5Exceptional. Ambitious scope executed rigorously. Surprising findings, novel methods, or unusually robust validation.

How clearly are work, findings, and impact potential communicated?

Scoring guide
  1. 1Incomprehensible. Cannot determine what the project is actually claiming or doing.
  2. 2Hard to follow. Key information buried, missing, or diluted by excessive length. Significant effort to extract main points.
  3. 3Clear enough. Can understand the problem, approach, and results without undue effort. Core content clearly present: problem, method, findings, limitations.
  4. 4Well presented. Easy to follow, well-structured, appropriate level of detail. Target audience would get it quickly.
  5. 5Exceptionally clear. A pleasure to read. Complex ideas made accessible. Could serve as a model for how to present this type of work.

  1. very real problem, truly good presentation, and competent execution given the timeframe. a limitation is that it doesn't open a new research direction. Limitations section is honest, overall very good work.

  2. Put the final product link at the top! This was the main deliverable, so it should be clear and center.

    Because this is not a 'technical discovery' but more of a 'user product', I wish the write-up had centered on questions like:

    - Who could benefit from using this?

    - What are the main requirements/desiderata user preferences impose on the product?

    - How did we use those to inform the main technical choices

    For example, why go with Gemma 4? is it because it can be easily locally hosted? why is that important

    Still, I liked this submission quite a bit. Cheers!

  3. The project's main weakness is that its theory of change is unclear. The causal chain it proposes assumes that lowering the cost of regulatory research would raise compliance and reduce rights violations. That chain rests on a bottleneck the work takes for granted and never demonstrates, since it assumes the cost of researching the law is what holds compliance back. As far as I can tell, non-compliance in the region responds more to weak incentives and weak enforcement than to ignorance of the law, and if that is the real constraint, the tool does not move the outcome. The intended beneficiary is also vague. Developers, small organizations, public institutions and researchers have different needs, and the work never defines who changes which concrete decision thanks to the platform. It also leaves open a risk the project itself hints at, because a legally wrong answer presented with an article-level citation can create false confidence and worsen the very decision it aims to improve.

    The AI safety framing is likewise weak. The project works as a data protection compliance tool, and that agenda overlaps with AI safety without being the same one. There is also overclaiming when the work states that the system eliminates hallucinations, since at best it only reduces them, and the limitations section concedes this by admitting that reliability would fall if the RAG retrieves incorrect passages. Finally, the evidence shows internal inconsistencies, because some results cite sources or frameworks that, according to the document itself, are not part of the indexed base.

    Read full reviewShow less

Cite this project

@misc{soares2026riskgovai,
  title = {{Risk-Gov-AI}},
  author = {Elaine Fabiola Soares},
  year = {2026},
  month = jun,
  note = {Submitted to Global South AI Safety Hackathon, an Apart Research Sprint},
  howpublished = {\url{https://apartresearch.com/sprints/projects/riskgovai-xgpt}},
  url = {https://apartresearch.com/sprints/projects/riskgovai-xgpt}
}

Build something like this at the next Sprint

AI Collusion Research Sprint · Oct 23 - 25, 2026