Fifteen days with all five modules open: AI Governance — the AI tools your team uses, the policies staff sign, and the board report; Enterprise Risk — the risks you’re watching, scored plainly; IT — devices, software, systems, and who has access; Data Management — what you hold, where it flows, and how long you keep it; and Privacy — what you owe the people your data is about. No credit card, and nothing to cancel: on day 15 your workspace goes read-only until you pick a plan, and nothing is deleted.

GOVERNBOX is one place that keeps track of how your organization uses AI — and, if you want, your wider risks, technology, data, and privacy duties too. It holds the list of AI tools your team uses (each with a named owner), the policies your staff actually sign, the risks you’re watching, and the report your board reads each quarter.
Every policy it writes cites a real control from an expert-written library — nothing is invented — and nothing counts until you’ve reviewed and approved it. During the trial the policy generators stay in preview — creating and approving policies unlocks with a paid plan — but everything else is the real system on your own organization, not a demo with fake data: your tools, your risks, your board report.
ChatGPT and tools like it are already inside your organization, whether or not anyone approved them. The first question boards, funders, and insurers ask is “who’s keeping track?” — and for most organizations the honest answer today is nobody.
State AI laws in Colorado and California take effect January 1, 2027, Texas is already live, and the EU’s AI Act is in force. GOVERNBOX covers those individually — alongside U.S. federal law, the UK, Canada and 21 countries in total — so you pick the ones you operate under. They expect plain-language notice, human review, and records — things you can’t produce the week someone asks for them.
When a funder’s questionnaire or a board member asks “who owns this tool, what data does it touch, and what happens when it fails,” you open a page instead of scheduling a meeting.
Not eventually — on a schedule someone else set. Here is who asks, what they ask, and the five things you need to be able to answer.
“What's our AI policy?”
Usually followed, one meeting later, by “and how do we know it's working?” The second question is the hard one.
“How are you handling AI?”
Increasingly a line item in grant applications and renewal packets. A live trust page answers it without a scramble.
“Complete this AI questionnaire.”
Security reviews now carry AI sections. The answers come straight out of your inventory and crosswalk.
“Show your assessment.”
State and international AI rules are arriving on a schedule. Where they apply, they ask for records you either have or don't.
Every tool, who owns it, and what data goes into it. Most organizations cannot answer this on the day they're asked.
A written policy and a practical standard, both short enough that staff will actually read them.
A named owner per risk, a sense of how likely and how bad, and a date you'll look again.
Training, then a dated signature per person. Unsigned staff are the gap auditors find first.
Dated records, a report each quarter, and a page you can send to anyone who asks. This is the part a template can't do.
Most of these rules are new, and plenty may not apply to you. We'll tell you which ones do.
It doesn't. It gives you a defensible starting point and the records to back it up. You review and approve everything.
The first package takes about an hour. Running the program is a rhythm, not an event, and that's the point.
This is the short version. Read the full 2026 executive briefing — the deadlines, the numbers and every primary source, last verified by a human on July 29, 2026.
AI law stopped being one deadline in one state. GOVERNBOX cites specific statutes from 28 U.S. states, covers 6 of those state AI laws with dedicated frameworks and crosswalks, and reaches U.S. federal law, the EU, the UK, Switzerland and Norway, Canada, the standards bodies and 21 countries in total — as selectable frameworks, not as a blog post. Pick the ones you operate under and every policy, crosswalk and gap report is generated and checked against exactly those.
6 of those laws go further, with their own controls and their own crosswalk report. New states are added as they pass.
National AI law and guidance, plus the EU as a bloc and the international instruments.
Selectable per organization — your documents are generated and checked against the ones you pick.
Expert-written, versioned, and cited by ID in every clause we generate. Nothing is invented.
The library cites specific statutes from 28 states. 6 of those laws, across 5 states, go further and have their own framework, controls and crosswalk report. The rest are reached through the U.S. state law landscape framework, which tracks disclosure, chatbot, biometric, deepfake, health, insurance and employment-AI statutes as they pass — so a new law does not mean a new setting for you.
Includes California's ADMT regulations. The CCPA privacy statute is a separate framework, available on Pro. All 51 jurisdictions shown are reachable through the U.S. state law landscape framework; 28 have their own statutes cited in it, and 5 go further with dedicated controls and a coverage report of their own. This map describes what GOVERNBOX covers — it is not a survey of which states have passed AI legislation, and it is not legal advice.
Colorado ADMT Act (SB 26-189) · Colorado Chatbot Safety (HB 26-1263) · Connecticut SB 5 (PA 26-15) · Texas TRAIGA · California ADMT Regulations · Hawaii AI Acts (247 / 248)
Federal legislation, executive orders and agency regulation, plus a cross-state view of AI disclosure and training-data laws. Per-state statutes are the U.S. State AI Laws jurisdiction above.
PIPEDA and provincial privacy law, the Directive on Automated Decision-Making, and the Canadian Human Rights Act as they apply to AI.
NIST profiles, ISO/IEC standards, IEEE, OECD and the healthcare AI reporting/assurance frameworks (FDA, WHO, CHAI, CONSORT-AI…).
EU regulation beyond the AI Act itself (GPAI code of practice, guidance), plus the UK, Swiss and Norwegian frameworks. The EU AI Act and GDPR remain separate frameworks.
Sixteen further countries' AI laws and guidance plus the international instruments (Council of Europe, OECD, UNESCO, UN).
The EU AI Act, GDPR, HIPAA, CCPA, NIST AI RMF and ISO/IEC 42001 and 42005 are chosen individually alongside these. See coverage by plan for exactly what each plan can select. GOVERNBOX gives you a defensible starting point that you review and approve — it is not legal advice.
Your organization profile, your readiness score, and a preview of the AI use policy you'd approve on a paid plan — the generators themselves stay locked during the trial.
Add the AI tools your team uses, assign owners, and score the handful of risks that matter. This is the part boards ask about.
Generate the board report and see your maturity score with your own data in it — the thing you walk into the next board meeting holding.
Five minutes, no sign-up: your maturity score, your gaps ranked, and a NIST AI RMF preview.
Take the scorecardEvery module open, so you can build the real thing on your own organization. No credit card.
Start the trial →Unlimited records, exports, the trust page, and the framework maps your sector needs.
See the plansIt stays in your account. If you subscribe later, you pick up where you left off rather than starting again.
Your workspace goes read-only until you pick a plan. There is no card on file, nothing to cancel, and nothing is deleted.
No. The questions are about your organization, not about models or code.
Yes. Seats depend on the plan you choose afterwards, and staff signatures are unlimited on paid plans.
No — all ten policy and document generators are visible in preview, but creating and approving policies unlocks with a paid plan, along with the framework crosswalks and staff attestations. Everything you do build during the trial carries over.
Two decades directing large-scale technology portfolios, enterprise risk management and applied machine learning — which is why the control library is authored and versioned the way it is, rather than assembled from templates.
Gradient Descent LLC is an independent company. GOVERNBOX.ai is not affiliated with, endorsed by, or produced on behalf of any government agency.
Build the real package on your own organization and decide from there.
Start the 15-day trial →GOVERNBOX.ai gives you a defensible starting point that you review and approve. It is not legal or compliance advice, and we don’t promise audit outcomes.