🇪🇺 Regulation (EU) 2024/1689

Looking for EU AI Act readiness?
Most obligations apply August 2, 2026.

The Act reaches beyond Europe: if your AI touches people in the EU, you can be in scope as a deployer — with penalties up to €35M or 7% of global turnover for prohibited practices. Readiness starts with classifying every AI system you use.

Days
Hours
Minutes
Seconds

Until August 2, 2026 — when most EU AI Act obligations apply, including high-risk system requirements.

Step one: classify everything

Every AI system falls into one of four EU risk tiers

Your obligations depend entirely on the tier — which is why classification, driven from a complete inventory, is the first readiness task:

Unacceptable — prohibited

Social scoring, manipulative techniques, and other Article 5 practices are banned outright. GOVERNBOX.ai screens every use case at intake — an affirmative answer blocks approval and escalates for legal review.

🔴

High risk — heavy obligations

Systems making consequential decisions about people: hiring, credit, education, essential services. These carry risk management, logging, human oversight, and incident-reporting duties.

🟡

Limited — transparency duties

Chatbots and AI-generated content that influence people must be disclosed as AI. Your acceptable-use standard and disclosure language cover this tier.

🟢

Minimal — inventory it anyway

Everything else. No special obligations — but you still need it in your inventory to prove you classified it, and to catch it if its use changes.

Built into the Agency plan

EU AI Act readiness, operationalized

On the Agency plan, the EU AI Act runs through the whole platform — not a separate checklist you maintain by hand:

🏷️

Risk tiering at intake

Every use case gets an EU risk-tier classification and an Article 5 prohibited-use screen the moment it enters your inventory.

🚨

Article 73 incident flag

The incident log carries the serious-incident reportable flag, so a reportable event is marked — and surfaced on the board report — the day it happens.

🔗

A dedicated EU crosswalk

Generated policies cite controls mapped to specific EU AI Act articles; the crosswalk scores your approved documents against the Act and lists every gap.

The EU AI Act framework — with GDPR and HIPAA — is exclusive to the Agency plan. Every plan from Starter up includes NIST AI RMF, ISO/IEC 42001, and the Colorado AI Act, so your program is ready to add EU coverage when you are.

Transparent pricing

Simple, Honest Pricing

Start free. Upgrade when you’re ready to generate and export. Cancel anytime.

Prices below are for the AI Governance module — the first of four GOVERNBOX modules. See modular pricing →

💙 Verified nonprofits save 20% on Starter & Pro annual🚀 Founder pricing — first 10 companies — launch rates, locked
Free
$0/forever
No credit card needed
  • AI Readiness Scorecard
  • Gap report preview
  • NIST AI RMF preview
  • Preview AI Use Policy
  • Dashboard overview
Or try everything
15-Day Free Trial

Credit card required · $0 today · converts to Starter ($3,500/yr — $291.66/mo equivalent) on day 15 unless canceled

  • AI Use Case Inventory
  • Training Module + Project Management
  • Risk Register, Impact Assessments, Incidents
  • AI Agents inventory
  • Quarterly Board Report
  • Regulatory horizon feed ("What's Changing")
  • Organization Profile + dashboard
  • Up to 2 records per module (2 projects, unlimited board tasks)
  • Preview all 10 policy generators (locked until paid)
Starter
$3,500/yr
or $339/mo billed monthly
  • Everything in Free
  • AI Use Policy + AI Acceptable Use Standard
  • NIST AI RMF + ISO 42001 + Colorado AI Act crosswalk
  • Risk Register + Impact Assessments
  • Incident log, Training plan, full Board Report
  • AI Cost Tracking & Roll-Up (per use case + program office)
  • AI Agents inventory (basic registration)
  • AI Project Management — up to 2 concurrent projects
  • Governance Badge + live public Trust Page
  • Employee Attestation Portal — unlimited signers
  • Regulatory horizon feed
  • Word + PDF export
  • 3 seats (up to 5)
Most popular
Pro
$12,000/yr
equates to $1,000 per month
  • Everything in Starter
  • + CCPA data-privacy framework
  • NIST SP 800-53 Rev. 5 / CSF 2.0 crosswalk
  • Risk heat map
  • Full Impact Assessments — auto-populates Risk Register
  • AI Project Management — up to 5 concurrent projects
  • AI Strategic Plan + CAIO Position Statement wizards
  • Privacy Policy (CCPA-grounded)
  • AI Incident Response Plan + Vendor AI Risk Assessment
  • Branded document exports
  • 5 seats (up to 10)
Agency
$25,000/yr
  • Everything in Pro
  • + EU AI Act framework (risk tiering, Art. 5 & Art. 73 reporting)
  • + HIPAA & GDPR data-privacy frameworks
  • White-label exports, branding & badge
  • OMB AI Compliance Plan (M-25-21/22)
  • AI Agents zero-trust checklist + scoring
  • AI Project Management — unlimited projects
  • Priority support
  • Enterprise SSO (SAML / OIDC)
  • Advisory session included
  • 10 seats (up to 20)

EU AI Act questions

Frequently asked questions

When does the EU AI Act actually apply?
In phases. The prohibited-practices ban took effect February 2, 2025 and general-purpose AI model obligations on August 2, 2025. The date most organizations need to track is August 2, 2026 — when the bulk of the Act applies, including the Annex III high-risk AI system obligations most business AI use cases fall under. A narrow set of high-risk systems embedded in already-regulated products gets until August 2, 2027.
Does the EU AI Act apply to U.S. organizations?
Often, yes. The Act has extraterritorial reach: if your AI system's output is used in the EU, or you offer services to people in the EU — members, students, donors, customers — you can be in scope as a provider or deployer even with no EU office. Penalties for prohibited practices reach €35M or 7% of global turnover.
What are the EU AI Act risk tiers?
Four: unacceptable (prohibited outright — e.g. social scoring, manipulative techniques), high (systems making consequential decisions about people — hiring, credit, education, essential services), limited (transparency obligations — chatbots and AI-generated content must be disclosed), and minimal (everything else). Your first readiness task is classifying every AI system you use into one of these tiers — which requires a complete AI inventory first.
How does GOVERNBOX.ai handle EU AI Act readiness?
On the Agency plan, every AI use case gets an EU risk-tier classification and an Article 5 prohibited-use screen at intake (an affirmative answer blocks approval and escalates for legal review). The incident log carries the Article 73 serious-incident reportable flag, generated policies cite controls mapped to specific EU AI Act articles, and a dedicated crosswalk scores your approved documents against the Act's requirements — coverage and gaps, article by article.
Which GOVERNBOX.ai plan includes the EU AI Act?
The EU AI Act framework is exclusive to the Agency plan ($25,000/yr) — alongside HIPAA and GDPR, it is one of the highest-commitment frameworks we support, and Agency includes the full white-label and advisory package that organizations with EU exposure typically need. Every plan from Starter up covers NIST AI RMF, ISO/IEC 42001, and the Colorado AI Act.
What should we do before August 2, 2026?
Three things, in order: (1) build a complete AI inventory — you cannot classify systems you have not listed; (2) classify each system by risk tier and screen for prohibited practices; (3) put the operational evidence in place — human oversight, logging, incident response, and staff training — that the high-risk obligations require. The free Readiness Scorecard shows where you stand on all three in about ten minutes.

The clock is running. Start with your inventory today.

The free Readiness Scorecard shows where you stand in about ten minutes — no credit card, no sales call.