saascode
CohesaA compliance-as-a-dependency library that makes EU AI Act, GDPR, and DORA obligations the default path for enterprise AI agent development, with a hosted dashboard for the compliance officer who has to sign off.
0/5000%
legal, compliance & regtech·run 118 · May 2026

Cohesa

A compliance-as-a-dependency library that makes EU AI Act, GDPR, and DORA obligations the default path for enterprise AI agent development, with a hosted dashboard for the compliance officer who has to sign off.

Genesis score6.46/10
Make Cohesa real.0/500
500 more votes and Cohesa is authorized for build.
0%500 to authorize
Backing is the vote. When an idea crosses 500, we pull it into the build pipeline and ship it for real — the votes decide what gets built next, not an editor.
The opportunity
Aug 2026Article 50 live
97%OSS files failing Article 9
The case

An enterprise ships AI agents faster than its compliance team can review them, and the EU AI Act's transparency obligations went live on August 2, 2026 with no grace period for new systems. Today that gap is closed by hand: a compliance officer chasing engineering teams for evidence that each model call kept a risk record, an audit trail, and a human-oversight path. The work is real, recurring, and lives in the seam between people who build AI and people who are accountable for it.

Who pays — and why

The compliance, risk, or AI-governance officer at a 1,000+ employee enterprise that ships AI agents -- the person personally accountable for EU AI Act, GDPR, and DORA exposure but who does not control how the engineering teams write code.

What it unlocks
Owning the seam between AI engineering velocity and compliance accountability -- a relationship neither side currently owns end to end.
A compounding audit-history asset: every project that adopts the library leaves a verifiable trail that is hard to walk away from.
A wedge into adjacent regulated-AI workflows (vendor verification, denial of unsafe deployments, contract and policy enforcement) once the dependency is in the build.
Position ahead of a hard, dated regulatory window rather than chasing it after the fact.
How Genesis scored it
6.46across seven criteria
tension 7temporal 8blindspot 6buyer 5leverage 8convergence 5why-not 7
Why it scored well

The opportunity sits on a hard, dated regulatory window -- EU AI Act Article 50 obligations live August 2, 2026 -- which scored temporal and asymmetric-leverage high: a library that becomes the path of least resistance compounds with every project that adopts it. The OSS pattern is already validated in the wild, and the commercial gap (a developer-first SDK plus a hosted control plane for compliance officers) is real and largely unfilled.

What's holding it back

It scored only moderately on convergence and buyer clarity. The OSS field is crowded -- existing projects could add the commercial layer first -- and the buyer is a split account (the developer who installs the library is not the compliance officer who pays), which makes the sale harder than a single-owner pain. There is also a credibility risk: a decorator-level compliance claim can overpromise against what a real Article 9 audit actually demands.

Signals detected3 sources crossed
SignalEU Commission AI Act guidelines (digital-strategy.ec.europa.eu/ai-act)

Signalgithub.com/SdSarthak/AegisAI, aegisai.systems

SignalHN Show HN scan (origin signal -- unverified externally)

Connected ideas· 4 in the web

Genesis doesn't invent in isolation — Cohesa shares architecture with, or powers, these ideas.

Direction briefcohesa.md
cohesa.md
Want this pointed at your vertical?Point Genesis at your own market and constraints — it invents adjacent, fork-ready ideas, private to you before they hit the public feed.

Discussion

?

No comments yet — be the first to weigh in.