The Act reaches beyond Europe: if your AI touches people in the EU, you can be in scope as a deployer — with penalties up to €35M or 7% of global turnover for prohibited practices. Readiness starts with classifying every AI system you use.
Organizations must disclose when people are interacting with AI, and mark or label AI-generated and manipulated content — chatbots, synthetic media, and deepfakes.
The Act applies in stages over the next several years, scaling what's required to how much risk an AI system carries — from minimal to high.
The compliance timelines for high-risk AI systems have been extended, giving organizations more time to build and document their programs before those duties apply.
The EU AI Act applies to any organization whose AI output is used in the EU — not just EU-based companies. GOVERNBOX helps you get ready before its duties reach you.
Step one: classify everything
Your obligations depend entirely on the tier — which is why classification, driven from a complete inventory, is the first readiness task:
Social scoring, manipulative techniques, and other Article 5 practices are banned outright. GOVERNBOX.ai screens every use case at intake — an affirmative answer blocks approval and escalates for legal review.
Systems making consequential decisions about people: hiring, credit, education, essential services. These carry risk management, logging, human oversight, and incident-reporting duties.
Chatbots and AI-generated content that influence people must be disclosed as AI. Your acceptable-use standard and disclosure language cover this tier.
Everything else. No special obligations — but you still need it in your inventory to prove you classified it, and to catch it if its use changes.
Built into the Agency plan
On the Agency plan, the EU AI Act runs through the whole platform — not a separate checklist you maintain by hand:
Every use case gets an EU risk-tier classification and an Article 5 prohibited-use screen the moment it enters your inventory.
The incident log carries the serious-incident reportable flag, so a reportable event is marked — and surfaced on the board report — the day it happens.
Generated policies cite controls mapped to specific EU AI Act articles; the crosswalk scores your approved documents against the Act and lists every gap.
The EU AI Act framework — with GDPR and HIPAA — is exclusive to the Agency plan, which also unlocks the Europe jurisdiction: EU regulation beyond the Act itself, plus the UK, Swiss and Norwegian frameworks, enabled as one unit. Every plan from Starter up includes NIST AI RMF, ISO/IEC 42001, every U.S. state AI law (Colorado’s ADMT and Chatbot Safety Acts among them) and U.S. federal law, so your program is ready to add EU coverage when you are.
Transparent pricing
Start with the free Scorecard, then take the 15-day free trial — no credit card, nothing to cancel. On day 15 your workspace stays exactly as you left it until you pick a plan.
Prices below are for the AI Governance module — the first of four GOVERNBOX modules. See modular pricing →
NONPROFIT20 at checkout⚡ Not ready to pick a plan?
Test drive GOVERNBOX free for 15 days — no credit card needed.
Start 15-Day Free Trial →✓ Instant access · 15 days free · Zero credit card required
✓ Instant access · 15 days free · Zero credit card required
✓ Instant access · 15 days free · Zero credit card required
Agency / Enterprise includes one advisory session with the founder. Working sessions, half-day module training and a guided program launch can also be bought on their own, on any plan — see GOVERNBOX.ai Advisory Services →
✓ Instant access · 15 days free · Zero credit card required
EU AI Act questions
EU exposure and no one internally to own it? GOVERNBOX.ai Advisory Services — fixed scope, published fees →
The free Readiness Scorecard shows where you stand in about ten minutes — no credit card, no sales call.
Following the timeline? Why AI Governance? — every deadline that applies to you, in one place →