OpenAI 2026 hackathon

AiGov: Human-Governed GDPR Audits

A Codex-built GDPR audit workbench where AI proposes scope, evidence requests, obligations, and checks; human auditors control every decision, with the case reconstructed from records.

Solo project by Marius Moldovan · 0 likes · 0 comments

Archive position — measured, not model output

0 likes on Devpost

2,264 of the 7,856 archived projects have more likes, and 5,592 share exactly 0 — so this project's #2,578 place in the like-ranked listing is a tie-break inside that group, not a ranking.

Projects (log scale)

1
10
100
1k
10k
05,592
11,758
2285
3–4132
5–975
10+14

Likes on Devpost. ▲ marks this project's group.

Show the figures
LikesProjectsShare of archive
05,59271.2%
11,75822.4%
22853.6%
3–41321.7%
5–9751.0%
10+140.2%
Devpost like counts for all 7,856 archived projects, captured when this archive was built.

Executive Summary

What the company appears to be

AiGov is a self-reported project that describes itself as a "human-governed GDPR audit workbench" built using AI agents (specifically Codex) and human-in-the-loop design. It aims to support professional GDPR auditing of customer-service chatbots by structuring an AI agent as the working environment for audit tasks, while maintaining human control over all major decisions.

What changed

The author reports a shift from initial attempts at deterministic workflows or independent agent applications to a new architecture where the coding agent (e.g., Codex) becomes the core of the audit environment. The system is designed to store and reconstruct audit cases from durable records, with human auditors controlling every decision.

Single most important open question

Is there evidence that this approach can scale beyond a demonstrator or prototype, and whether it can meaningfully integrate AI reasoning into professional auditing without losing defensibility?

Back to contents

What The Product Actually Is

The description states that AiGov is a human-governed GDPR audit workbench where:

  • An AI agent (specifically Codex) proposes scope, evidence requests, obligations, and checks.
  • Human auditors control every decision.
  • The case is reconstructed from records.

It uses:

  • A coding agent as the main audit environment.
  • SQLite for durable case storage.
  • A web UI for auditor interaction.
  • Python for backend services.
  • HTML/CSS/JS for frontend.
  • REST API for communication.

The system is described as not replacing the auditor, but rather supporting substantial audit work while keeping human authority over decisions.

Inference This is a prototype or demonstrator, not a production-ready product. It focuses on architecture and interaction patterns rather than full functionality.

Back to contents

Positioning & Claim Evolution

The author states:

  • Initially, they thought GDPR auditing could be done by summarizing documents using AI.
  • Later, they realized this approach was flawed because professional audits require case-specific reasoning.
  • They evolved toward a model where the coding agent is structured as the audit environment, not just a tool.
  • The goal is to build an executable, human-governed audit methodology that integrates legal and methodological sources with AI-driven proposals.

Inference The positioning has shifted from a generic document summarizer to a specialized, human-in-the-loop auditing framework. However, the claim of being a "workbench" or "framework" is not substantiated by evidence of adoption or usage beyond the author’s own development.

Back to contents

Target Customer & ICP

The description states:

  • The target use case is auditing customer-service chatbots.
  • It is intended for professional GDPR auditors who need to understand systems, actors, purposes, data flows, and available evidence.
  • The system supports case-specific reasoning, which implies a niche audience with deep domain expertise.

Inference The ICP appears to be GDPR compliance professionals or auditors working in regulated environments, particularly those dealing with digital services like chatbots. No explicit customer names or segments are provided.

Back to contents

Business Model & Pricing Evidence

Not evidenced.

The description does not mention:

  • Revenue streams
  • Pricing models
  • Customers or clients
  • Monetization strategy

Inference There is no evidence of a business model or pricing structure beyond the author’s own development efforts. The project is presented as a hackathon submission, not a commercial offering.

Back to contents

Technical & Delivery Signals

The description states:

  • Built with Codex, Python, SQLite, HTML/CSS/JS, REST API
  • Uses record-based reconstruction instead of browser or conversation state
  • Implements durable case objects, provenance tracking, and versioning
  • Supports human decision gates and reconstruction mechanisms
  • Demonstrator proves:
    • Opening audit cases
    • Navigating through a Decision Navigator
    • Accepting, amending, or rejecting proposals
    • Reconstructing decisions from stored records

Inference The technical stack suggests a lightweight, local-first approach with strong emphasis on durability and traceability. The architecture is described as human-in-the-loop, but no evidence of scalability or integration into existing tools is given.

Back to contents

Traction & Maturity Signals

Not evidenced.

The description does not include:

  • Customers
  • Revenue
  • Usage metrics
  • Product adoption
  • Market traction

Inference This is a prototype or proof-of-concept, likely built during a hackathon. There is no evidence of real-world deployment or user feedback.

Back to contents

Competitive Context

The author states:

  • They researched assurance-case tools, legal workbenches, audit-management systems, evidence-review platforms, and workflow engines.
  • Found individual patterns but no open-source solution combining:
    • Coding-agent reasoning
    • Executable audit methodology
    • Legal and evidential provenance
    • Human decision authority
    • Durable case state
    • Reconstruction and selective reconsideration

Inference There is a perceived gap in the market for such a hybrid system. However, no competitors are named or described in detail.

Back to contents

Key Risks & Red Flags

  1. Unproven scalability: The system is described as a demonstrator; no evidence of handling large-scale audits.
  2. No commercial traction: No customers, revenue, or product usage data.
  3. Limited scope: Focuses only on chatbot auditing; unclear if it generalizes to other domains.
  4. Dependency on author’s expertise: The project is built by one person with no coding or audit experience initially — raises questions about long-term maintainability and team capacity.
  5. Unclear integration with external tools: While the system supports telemetry analysis, there's no mention of how it connects to real-world systems or platforms.

Back to contents

Diligence Questions To Ask The Founders

  1. What specific legal and methodological sources are used to guide the AI agent’s reasoning?
  2. How does the system handle uncertainty or missing information in a way that is defensible for audit purposes?
  3. Has the prototype been tested with actual auditors or compliance professionals?
  4. What are the plans for expanding beyond chatbot auditing?
  5. Is there any plan to integrate with existing audit management systems or platforms?
  6. How will the system scale to support multiple concurrent audits or users?
  7. What is the roadmap for moving from a demonstrator to a production-ready tool?

Back to contents

Investment/Partnership Verdict

Not evidenced.

There is no evidence of:

  • Funding rounds
  • Valuation
  • Partnerships
  • Commercial interest

Inference This appears to be an early-stage prototype submitted as part of a hackathon. It shows architectural ambition and some technical feasibility, but lacks any commercial or traction signals. It may have potential for further development, but there is no basis for investment or partnership considerations at this time.

Back to contents

Source

Submitted to the OpenAI 2026 hackathon on Devpost. Project home on DevPost.

The analysis above was generated by a language model from the project's own one-line description. It is not independent research and contains no verified traction, revenue or customer data.