OpenAI 2026 hackathon

BOSAI — The Control Plane for AI Work

AI can propose. Humans authorize. BOSAI governs execution and proves what happened through dry-runs, approval gates, execution permits, and audit evidence.

Solo project by Arthur Franck · 1 likes · 0 comments

Archive position — measured, not model output

1 like on Devpost

506 of the 7,856 archived projects have more likes, and 1,758 share exactly 1 — so this project's #721 place in the like-ranked listing is a tie-break inside that group, not a ranking.

Projects (log scale)

1
10
100
1k
10k
05,592
11,758
2285
3–4132
5–975
10+14

Likes on Devpost. ▲ marks this project's group.

Show the figures
LikesProjectsShare of archive
05,59271.2%
11,75822.4%
22853.6%
3–41321.7%
5–9751.0%
10+140.2%
Devpost like counts for all 7,856 archived projects, captured when this archive was built.

Executive Summary

What the company appears to be

BOSAI is a self-reported control plane for AI-assisted work, designed to govern AI reasoning and execution authority. The project is described as a system that separates AI intelligence from operational authority, requiring explicit human approval before any action is taken. It uses deterministic fallbacks and structured governance to ensure that AI can diagnose but not execute.

What changed

The author states that BOSAI was built for the OpenAI Build Week hackathon using synthetic data and a fictional operational scenario. The system includes dry-run execution, single-use permits, audit evidence generation, and policy enforcement via GPT-5.6 (or deterministic fallback). It is presented as an experimental demonstration of AI governance.

Single most important open question

Is there any evidence that BOSAI has moved beyond a proof-of-concept or hackathon prototype into real-world use cases or customer adoption?

Back to contents

What The Product Actually Is

The description states that BOSAI is a governed control plane for AI-assisted work. It is built to separate AI intelligence from operational authority, requiring human approval before execution.

Key technical elements include:

  • Use of GPT-5.6 (or deterministic fallback) for diagnosis
  • Structured output validation using JSON Schema and Zod
  • Dry-run execution with no-mutation testing
  • Single-use execution permits valid for five minutes
  • HMAC-SHA256 workflow signing
  • Server-side execution only
  • Audit packet generation from actual workflow history

The system is described as not allowing AI to:

  • Approve actions
  • Issue permits
  • Expand scope
  • Bypass governance
  • Execute operations directly

Inference The product appears to be a software control layer that enforces governance rules over AI-assisted workflows, particularly in environments where execution must be authorized and auditable.

Back to contents

Positioning & Claim Evolution

The description states that BOSAI is built on the belief that “AI needs a control plane”, separating intelligence from authority. It positions itself as a solution to the problem of AI being able to recommend changes but not being allowed to act without explicit human authorization.

Key claims:

  • “AI can propose. Humans authorize.”
  • “BOSAI governs execution and proves what happened through dry-runs, approval gates, execution permits, and audit evidence.”
  • “Instead of asking ‘Can AI do this?’ BOSAI asks: ‘Should this be allowed, under what conditions, and how do we prove exactly what happened?’”

Inference The positioning is focused on trustworthy AI governance, emphasizing accountability, verifiability, and human oversight. It is not a general-purpose AI tool but a specialized control layer.

Back to contents

Target Customer & ICP

The description does not name specific customers or target industries. However, it implies that BOSAI is aimed at organizations where:

  • AI-assisted decision-making exists
  • Operational execution requires governance
  • Auditability and accountability are critical

Inference The likely ICP includes enterprises or teams managing sensitive systems (e.g., DevOps, cybersecurity, compliance) where AI can assist in diagnosis but not in execution without human authorization.

Back to contents

Business Model & Pricing Evidence

There is no evidence of a business model or pricing structure in the description. The project is described as a hackathon submission with no mention of monetization, subscriptions, or sales.

Inference No commercial traction or revenue model is evident from the self-reported content.

Back to contents

Technical & Delivery Signals

The system is built using:

  • Next.js, React, TypeScript
  • OpenAI Responses API
  • Docker, Caddy reverse proxy
  • Node.js cryptography, HMAC-SHA256 signing
  • Vitest for testing
  • Zod for validation
  • Synthetic data and deterministic fallbacks

Notable features:

  • Server-side execution only
  • No-mutation dry-run
  • Five-minute single-use permits
  • Audit packet generation
  • Fail-closed behavior
  • Isolated judging environment on OVHcloud

Inference The technical stack suggests a secure, isolated, and auditable system, built with governance in mind. It is not described as scalable or production-ready beyond the demo.

Back to contents

Traction & Maturity Signals

The project is explicitly described as:

  • A hackathon submission
  • Built for OpenAI Build Week 2026
  • Using synthetic data
  • Deployed in a judge-only environment
  • Not connected to any real production systems or customer integrations

There is no evidence of:

  • Revenue
  • Customers
  • Product adoption
  • Live usage
  • Scaling beyond the demo

Inference The project is at an early stage, likely a prototype or proof-of-concept. No traction or maturity indicators are evident.

Back to contents

Competitive Context

The description does not mention any competitors. It is unclear whether BOSAI is positioned against other AI governance tools, control planes, or workflow automation platforms.

Inference No competitive landscape is described. The project appears to be in a niche or emerging space with no known direct competitors mentioned.

Back to contents

Key Risks & Red Flags

  • No real-world use case: The system is built for a demo and not demonstrated in production.
  • No customer data or integrations: All execution is synthetic, isolated, and non-production.
  • Unproven scalability: No evidence of how the system would scale beyond a single scenario.
  • Self-reported only: No third-party validation, audit, or performance data.
  • Founder-only team: Only one member (Arthur Franck) is listed.

Inference The project lacks commercial viability or traction. It is not yet a product, but a demonstration of a concept.

Back to contents

Diligence Questions To Ask The Founders

  1. What real-world scenarios are you planning to apply this control plane to?
  2. How would BOSAI integrate with existing operational tools or platforms (e.g., CI/CD, DevOps systems)?
  3. Have you tested the system with actual users or stakeholders in a non-demo setting?
  4. What is your roadmap for moving beyond the current prototype into a production-ready product?
  5. Are there any known limitations of the deterministic fallback approach that could affect real-world reliability?

Back to contents

Investment/Partnership Verdict

The description states that BOSAI is a hackathon project with no evidence of revenue, customers, or traction.

Inference At this stage, BOSAI is not a viable investment or partnership opportunity. It is a concept demonstration, not a product in the market.

Confidence level Low — based on self-reported evidence only, with no external validation or commercial indicators.

Back to contents

Source

Submitted to the OpenAI 2026 hackathon on Devpost. Project home on DevPost.

The analysis above was generated by a language model from the project's own one-line description. It is not independent research and contains no verified traction, revenue or customer data.