⚡ Try GOVERNBOX free for 15 daysAll five modules · no credit card · nothing to cancelStart 15-Day Free Trial →
Regulation (EU) 2024/1689

Looking for EU AI Act readiness?
Its obligations are phasing in now.

The Act reaches beyond Europe: if your AI touches people in the EU, you can be in scope as a deployer — with penalties up to €35M or 7% of global turnover for prohibited practices. Readiness starts with classifying every AI system you use.

Taking effect now
Transparency for AI-generated content

Organizations must disclose when people are interacting with AI, and mark or label AI-generated and manipulated content — chatbots, synthetic media, and deepfakes.

Phasing in
Obligations roll out by risk level

The Act applies in stages over the next several years, scaling what's required to how much risk an AI system carries — from minimal to high.

Timelines extended
More runway for high-risk systems

The compliance timelines for high-risk AI systems have been extended, giving organizations more time to build and document their programs before those duties apply.

The EU AI Act applies to any organization whose AI output is used in the EU — not just EU-based companies. GOVERNBOX helps you get ready before its duties reach you.

Step one: classify everything

Every AI system falls into one of four EU risk tiers

Your obligations depend entirely on the tier — which is why classification, driven from a complete inventory, is the first readiness task:

Unacceptable — prohibited

Social scoring, manipulative techniques, and other Article 5 practices are banned outright. GOVERNBOX.ai screens every use case at intake — an affirmative answer blocks approval and escalates for legal review.

🔴

High risk — heavy obligations

Systems making consequential decisions about people: hiring, credit, education, essential services. These carry risk management, logging, human oversight, and incident-reporting duties.

🟡

Limited — transparency duties

Chatbots and AI-generated content that influence people must be disclosed as AI. Your acceptable-use standard and disclosure language cover this tier.

🟢

Minimal — inventory it anyway

Everything else. No special obligations — but you still need it in your inventory to prove you classified it, and to catch it if its use changes.

Built into the Agency plan

EU AI Act readiness, operationalized

On the Agency plan, the EU AI Act runs through the whole platform — not a separate checklist you maintain by hand:

🏷️

Risk tiering at intake

Every use case gets an EU risk-tier classification and an Article 5 prohibited-use screen the moment it enters your inventory.

🚨

Article 73 incident flag

The incident log carries the serious-incident reportable flag, so a reportable event is marked — and surfaced on the board report — the day it happens.

🔗

A dedicated EU crosswalk

Generated policies cite controls mapped to specific EU AI Act articles; the crosswalk scores your approved documents against the Act and lists every gap.

The EU AI Act framework — with GDPR and HIPAA — is exclusive to the Agency plan, which also unlocks the Europe jurisdiction: EU regulation beyond the Act itself, plus the UK, Swiss and Norwegian frameworks, enabled as one unit. Every plan from Starter up includes NIST AI RMF, ISO/IEC 42001, every U.S. state AI law (Colorado’s ADMT and Chatbot Safety Acts among them) and U.S. federal law, so your program is ready to add EU coverage when you are.

Transparent pricing

Simple, Honest Pricing

Start with the free Scorecard, then take the 15-day free trial — no credit card, nothing to cancel. On day 15 your workspace stays exactly as you left it until you pick a plan.

Prices below are for the AI Governance module — the first of four GOVERNBOX modules. See modular pricing →

💙 Nonprofits save 20% on every plan — enter code NONPROFIT20 at checkout

⚡ Not ready to pick a plan?

Test drive GOVERNBOX free for 15 days — no credit card needed.

Start 15-Day Free Trial →

Instant access  ·  15 days free  ·  Zero credit card required

Starter
$3,500/yr
or $339/mo billed monthly
🏛️ Nonprofit: $2,800/yr · code NONPROFIT20
  • The full AI Governance module
  • AI Use Policy + AI Acceptable Use Standard
  • NIST AI RMF + ISO 42001 crosswalks
  • Every U.S. state AI law, added as they pass — Colorado ADMT Act (SB 26-189), Colorado Chatbot Safety (HB 26-1263), Connecticut SB 5 (PA 26-15), Texas TRAIGA, California ADMT Regulations, Hawaii AI Acts (247 / 248)
  • Plus specific statutes from 27 states via the U.S. state law landscape
  • United States — federal law & state landscape (U.S. National)
  • Risk Register + Impact Assessments
  • Incident log, Training plan, full Board Report
  • AI Cost Tracking & Roll-Up (per use case + program office)
  • AI Agents inventory (basic registration)
  • AI Project Management — up to 2 concurrent projects
  • Governance Badge + live public Trust Page
  • Employee Attestation Portal — unlimited signers
  • Regulatory horizon feed
  • Word + PDF export
  • Staff AI-tool reporting portal — anonymous shadow-AI intake, no login
  • Unlimited staff participants — report AI tools, sign policies & complete training, no seat required
  • 10 admin seats
Try Starter free for 15 days →

Instant access  ·  15 days free  ·  Zero credit card required

Most popular
Pro
$12,000/yr
equates to $1,000 per month
🏛️ Nonprofit: $9,600/yr · code NONPROFIT20
  • Everything in Starter
  • + ISO/IEC 42005 · CCPA · Canada · AI frameworks, standards & healthcare guidelines
  • NIST SP 800-53 Rev. 5 / CSF 2.0 crosswalk
  • Risk heat map
  • Full Impact Assessments — auto-populates Risk Register
  • AI Project Management — up to 5 concurrent projects
  • AI Strategic Plan + CAIO Position Statement wizards
  • Privacy Policy (CCPA-grounded)
  • AI Incident Response Plan + Vendor AI Risk Assessment
  • Branded document exports
  • Pay by card or ACH bank transfer
  • 15 admin seats
Try Pro free for 15 days →

Instant access  ·  15 days free  ·  Zero credit card required

Starting at
Agency / Enterprise
$25,000/yr
🏛️ Nonprofit: $20,000/yr · code NONPROFIT20
  • Everything in Pro
  • + EU AI Act framework (risk tiering, Art. 5 & Art. 73 reporting)
  • + HIPAA & GDPR data-privacy frameworks
  • + Europe — EU regulation, UK, Switzerland, Norway
  • + Global — Americas, Middle East, Asia-Pacific & international (16 further countries + the international instruments)
  • White-labeled Trust Page & badge
  • OMB AI Compliance Plan (M-25-21/22)
  • AI Agents zero-trust checklist + scoring
  • AI Project Management — unlimited projects
  • Priority support
  • Enterprise SSO (SAML / OIDC)
  • Advisory session included
  • Pay by card or ACH bank transfer
  • 20 admin seats

Agency / Enterprise includes one advisory session with the founder. Working sessions, half-day module training and a guided program launch can also be bought on their own, on any plan — see GOVERNBOX.ai Advisory Services →

See plans & get started →

Instant access  ·  15 days free  ·  Zero credit card required

EU AI Act questions

Frequently asked questions

When does the EU AI Act actually apply?
In phases, over several years, scaled to how much risk an AI system carries. The prohibited-practices ban and the general-purpose AI model rules came first. The transparency duties for AI-generated content — disclosing chatbots and labeling synthetic media — are the piece taking effect now, and the compliance timelines for high-risk AI systems have been extended. Because the Act arrives in stages rather than all at once, the organizations that fare best build their inventory and evidence before the duties that apply to them take effect.
Does the EU AI Act apply to U.S. organizations?
Often, yes. The Act has extraterritorial reach: if your AI system's output is used in the EU, or you offer services to people in the EU — members, students, donors, customers — you can be in scope as a provider or deployer even with no EU office. Penalties for prohibited practices reach €35M or 7% of global turnover.
What are the EU AI Act risk tiers?
Four: unacceptable (prohibited outright — e.g. social scoring, manipulative techniques), high (systems making consequential decisions about people — hiring, credit, education, essential services), limited (transparency obligations — chatbots and AI-generated content must be disclosed), and minimal (everything else). Your first readiness task is classifying every AI system you use into one of these tiers — which requires a complete AI inventory first.
How does GOVERNBOX.ai handle EU AI Act readiness?
On the Agency plan, every AI use case gets an EU risk-tier classification and an Article 5 prohibited-use screen at intake (an affirmative answer blocks approval and escalates for legal review). The incident log carries the Article 73 serious-incident reportable flag, generated policies cite controls mapped to specific EU AI Act articles, and a dedicated crosswalk scores your approved documents against the Act's requirements — coverage and gaps, article by article.
Which GOVERNBOX.ai plan includes the EU AI Act?
The EU AI Act framework is exclusive to the Agency plan ($25,000/yr) — alongside HIPAA and GDPR, it is one of the highest-commitment frameworks we support. Agency also unlocks the Europe jurisdiction: EU regulation beyond the Act itself (the General-Purpose AI Code of Practice and Commission guidance) plus the UK, Swiss and Norwegian frameworks, enabled as one unit — and includes the white-labeled Trust Page & badge, Enterprise SSO, and one advisory session with the founder — the entry point to GOVERNBOX.ai Advisory Services, whose engagements are separately available on any plan at published fees (governbox.ai/advisory). Every plan from Starter up covers NIST AI RMF, ISO/IEC 42001, every U.S. state AI law (Colorado's ADMT and Chatbot Safety Acts among them) and U.S. federal law.
What should we do to get ready?
Three things, in order: (1) build a complete AI inventory — you cannot classify systems you have not listed; (2) classify each system by risk tier and screen for prohibited practices; (3) put the operational evidence in place — human oversight, logging, incident response, and staff training — that the high-risk obligations require. The free Readiness Scorecard shows where you stand on all three in about ten minutes.

EU exposure and no one internally to own it? GOVERNBOX.ai Advisory Services — fixed scope, published fees →

The clock is running. Start with your inventory today.

The free Readiness Scorecard shows where you stand in about ten minutes — no credit card, no sales call.

Following the timeline? Why AI Governance? — every deadline that applies to you, in one place →