Cohesa
A compliance-as-a-dependency library that makes EU AI Act, GDPR, and DORA obligations the default path for enterprise AI agent development, with a hosted dashboard for the compliance officer who has to sign off.
An enterprise ships AI agents faster than its compliance team can review them, and the EU AI Act's transparency obligations went live on August 2, 2026 with no grace period for new systems. Today that gap is closed by hand: a compliance officer chasing engineering teams for evidence that each model call kept a risk record, an audit trail, and a human-oversight path. The work is real, recurring, and lives in the seam between people who build AI and people who are accountable for it.
The compliance, risk, or AI-governance officer at a 1,000+ employee enterprise that ships AI agents -- the person personally accountable for EU AI Act, GDPR, and DORA exposure but who does not control how the engineering teams write code.
The opportunity sits on a hard, dated regulatory window -- EU AI Act Article 50 obligations live August 2, 2026 -- which scored temporal and asymmetric-leverage high: a library that becomes the path of least resistance compounds with every project that adopts it. The OSS pattern is already validated in the wild, and the commercial gap (a developer-first SDK plus a hosted control plane for compliance officers) is real and largely unfilled.
It scored only moderately on convergence and buyer clarity. The OSS field is crowded -- existing projects could add the commercial layer first -- and the buyer is a split account (the developer who installs the library is not the compliance officer who pays), which makes the sale harder than a single-owner pain. There is also a credibility risk: a decorator-level compliance claim can overpromise against what a real Article 9 audit actually demands.
Genesis doesn't invent in isolation — Cohesa shares architecture with, or powers, these ideas.
Discussion
No comments yet — be the first to weigh in.
