Skip to content
Sprint projectJun 20, 2026Falls Church, VA, USA

Salvaguarda

Tomás Mandl · Team Salvaguarda

Submitted to Global South AI Safety Hackathon. Sprint projects are early-stage work by participants, not Apart Research publications.

Salvaguarda is an AI governance toolkit for Global South small and medium-sized enterprises (SMEs), built as a Latin America beta. Because ISO/IEC 42001 and the NIST AI RMF demand expertise and budget most Latin American SMEs lack, the proposal crosswalks down to twelve zero-to-low-cost controls, adds a three-tier risk rubric that scales them to a firm's exposure, and delivers a thirty-minute, privacy-preserving self-assessment that returns a tier verdict and a prioritized, costed action plan with regulatory flags for Brazil, Colombia, and Paraguay.

Reviews

Judging this Sprint?

Review this project

Your public critique appears on this page without your name. Your private critique is not published; only the Apart team reads it. If you agree below, we share your review with grantmaking.ai (opens in new tab) and the Transformative AI Fund so strong projects can be funded.

Not shown on this page.

Shown on this page, without your name.

Only the Apart team reads this, and funders if you agree below.

Share my name publicly on grantmaking.ai *
Share my private critique with funders *

How much would this matter for AI safety if it worked? How innovative is it? For scores of 4-5: is this actually new to the field, or replicating recent work?

Scoring guide
  1. 1Negligible. No clear problem addressed, or no meaningful novelty.
  2. 2Limited. Addresses a real problem but with a generic or well-trodden approach. Incremental at best.
  3. 3Moderate. Clear problem with a reasonable approach; some novelty in framing or method beyond routine application of existing tools.
  4. 4Significant. Important problem with an original approach, or identifies a neglected problem area. A valuable contribution others could build on.
  5. 5Exceptional. Tackles a critical AI safety problem with a genuinely novel approach, or opens a new research direction. Clear theory of change. You'd be excited to share this with researchers in the area.

How sound are methodology, implementation, and findings?

Scoring guide
  1. 1Seriously flawed. Methodology broken, results uninterpretable, or implementation doesn't work.
  2. 2Weak. Approach has significant gaps: missing validation, flawed experimental design, or incomplete implementation.
  3. 3Competent. Technically solid given the short duration. Methodology makes sense, results are interpretable, limitations acknowledged, work builds toward clear conclusions.
  4. 4Strong. Thorough methodology with convincing validation. Results clearly support conclusions. Immediately useful for future work.
  5. 5Exceptional. Ambitious scope executed rigorously. Surprising findings, novel methods, or unusually robust validation.

How clearly are work, findings, and impact potential communicated?

Scoring guide
  1. 1Incomprehensible. Cannot determine what the project is actually claiming or doing.
  2. 2Hard to follow. Key information buried, missing, or diluted by excessive length. Significant effort to extract main points.
  3. 3Clear enough. Can understand the problem, approach, and results without undue effort. Core content clearly present: problem, method, findings, limitations.
  4. 4Well presented. Easy to follow, well-structured, appropriate level of detail. Target audience would get it quickly.
  5. 5Exceptionally clear. A pleasure to read. Complex ideas made accessible. Could serve as a model for how to present this type of work.

  1. The project addresses an important and underexplored AI safety challenge: helping SMEs in the Global South adopt practical AI governance despite limited resources. The motivation is compelling, and the proposed framework successfully translates comprehensive governance standards into a lightweight, actionable approach. The focus on localization, low-resource languages, and regional regulatory contexts is particularly valuable and distinguishes the work from generic governance checklists.

    What limits the current submission is that it primarily presents a well-reasoned framework rather than demonstrating that the framework works in practice. The evaluation relies on representative case studies and face-validity arguments, but there is little evidence that SMEs would complete the assessment, implement the recommended controls, or experience measurable improvements in governance or safety outcomes. The next stage of the project would benefit from pilot deployments with real organizations and observations of how the framework changes organizational practices over time.

    Several questions also remain about the design choices. Why are these twelve controls the appropriate minimum governance baseline? Are they derived systematically from existing frameworks, or could other subsets achieve similar outcomes? A clearer justification for why these controls—and not others—would strengthen confidence in the methodology.

    Similarly, while the three-tier risk model is intuitive, it would be useful to understand how robust it is across a wider variety of AI use cases. For example, are there deployments that fall between tiers or require different governance interventions? Additional validation with domain experts or comparisons against existing governance assessment methods would help establish that the proposed rubric generalizes beyond the illustrative examples presented.

    The localization component is one of the strongest aspects of the submission, but it currently remains largely conceptual. Demonstrating that localized language testing uncovers risks that existing governance guidance would otherwise miss would make the contribution considerably stronger and better establish its novelty.

    One possible direction for future work would be to structure the evaluation around one or two detailed organizational case studies. Showing how an SME initially assessed its AI use, implemented the recommended controls, encountered practical challenges, and changed its governance processes over time would provide stronger evidence of the framework's real-world value than hypothetical walkthroughs alone.

    Overall, this is a thoughtful and well-presented contribution that identifies a genuine gap in AI governance. With empirical validation, a working implementation, and evidence of organizational adoption, it has the potential to become a valuable practical resource for AI safety in resource-constrained environments.

    Read full reviewShow less
  2. 3/2/4

    Criteria 1 - Impact Potential & Innovation: 3.5

    Criteria 2 - Execution Quality: 2

    Criteria 3 - Presentation & Clarity: 4

    Identifies a genuinely under-attended problem , well-structured, cleanly enumerated threat model, useful tables, explicit tier logic with an appendix, and a thorough, helpful dual-use/limitations section. The crux of the problem is that the artifact does not exist.

  3. A sharp and well-framed project. The "long tail of small deployers" framing is compelling, and the writing is excellent. The only gap I see, which I believe can be quickly fixed, is that the actual tool has not beein built or tested. Building a reference implementation and piloting it with a couple of real SME's will substantially strengthen the work!

Cite this project

@misc{mandl2026salvaguarda,
  title = {{Salvaguarda}},
  author = {Tomás Mandl},
  year = {2026},
  month = jun,
  note = {Submitted to Global South AI Safety Hackathon, an Apart Research Sprint},
  howpublished = {\url{https://apartresearch.com/sprints/projects/savaguarda-07gk}},
  url = {https://apartresearch.com/sprints/projects/savaguarda-07gk}
}

Build something like this at the next Sprint

AI Collusion Research Sprint · Oct 23 - 25, 2026