The Question
The whole program in one automated walkthrough — the AI Readiness Scorecard, AI inventory, risk register, grounded policies with human review, staff training, a board-ready report, and a live trust page.
GOVERNBOX.ai™ is the governance system of record for the overlooked middle. Start free for 15 days with all five modules — AI Governance, Risk, IT, Data and Privacy — on one platform.
No consultant. No sales call. No specialist team. Plain-language, step-by-step, with every clause traced to a control you can hand an auditor — a defensible, board-ready package in about an hour.
Start for free — no credit card required
Until Colorado’s SB 26-189 and California’s CCPA ADMT rules take effect — January 1, 2027
Colorado is AG-enforced only, with no private right of action. California’s rules reach businesses already using automated decision-making technology for a significant decision.
Permanently — at signup and at every renewal. Just choose the rate at checkout.
Different states, different definitions, different deadlines — and the obligations attach to you as the deployer, not the vendor who built the tool.
Why this matters — read the 2026 briefing →Not eventually — on a schedule someone else set. Here is who asks, what they ask, and the five things you need to be able to answer.
“What's our AI policy?”
Usually followed, one meeting later, by “and how do we know it's working?” The second question is the hard one.
“How are you handling AI?”
Increasingly a line item in grant applications and renewal packets. A live trust page answers it without a scramble.
“Complete this AI questionnaire.”
Security reviews now carry AI sections. The answers come straight out of your inventory and crosswalk.
“Show your assessment.”
State and international AI rules are arriving on a schedule. Where they apply, they ask for records you either have or don't.
Every tool, who owns it, and what data goes into it. Most organizations cannot answer this on the day they're asked.
A written policy and a practical standard, both short enough that staff will actually read them.
A named owner per risk, a sense of how likely and how bad, and a date you'll look again.
Training, then a dated signature per person. Unsigned staff are the gap auditors find first.
Dated records, a report each quarter, and a page you can send to anyone who asks. This is the part a template can't do.
Most of these rules are new, and plenty may not apply to you. We'll tell you which ones do.
It doesn't. It gives you a defensible starting point and the records to back it up. You review and approve everything.
The first package takes about an hour. Running the program is a rhythm, not an event, and that's the point.
This is the short version. Read the full 2026 executive briefing — the deadlines, the numbers and every primary source, last verified by a human on July 29, 2026.
AI law stopped being one deadline in one state. GOVERNBOX cites specific statutes from 28 U.S. states, covers 6 of those state AI laws with dedicated frameworks and crosswalks, and reaches U.S. federal law, the EU, the UK, Switzerland and Norway, Canada, the standards bodies and 21 countries in total — as selectable frameworks, not as a blog post. Pick the ones you operate under and every policy, crosswalk and gap report is generated and checked against exactly those.
6 of those laws go further, with their own controls and their own crosswalk report. New states are added as they pass.
National AI law and guidance, plus the EU as a bloc and the international instruments.
Selectable per organization — your documents are generated and checked against the ones you pick.
Expert-written, versioned, and cited by ID in every clause we generate. Nothing is invented.
The library cites specific statutes from 28 states. 6 of those laws, across 5 states, go further and have their own framework, controls and crosswalk report. The rest are reached through the U.S. state law landscape framework, which tracks disclosure, chatbot, biometric, deepfake, health, insurance and employment-AI statutes as they pass — so a new law does not mean a new setting for you.
Includes California's ADMT regulations. The CCPA privacy statute is a separate framework, available on Pro. All 51 jurisdictions shown are reachable through the U.S. state law landscape framework; 28 have their own statutes cited in it, and 5 go further with dedicated controls and a coverage report of their own. This map describes what GOVERNBOX covers — it is not a survey of which states have passed AI legislation, and it is not legal advice.
Colorado ADMT Act (SB 26-189) · Colorado Chatbot Safety (HB 26-1263) · Connecticut SB 5 (PA 26-15) · Texas TRAIGA · California ADMT Regulations · Hawaii AI Acts (247 / 248)
Federal legislation, executive orders and agency regulation, plus a cross-state view of AI disclosure and training-data laws. Per-state statutes are the U.S. State AI Laws jurisdiction above.
PIPEDA and provincial privacy law, the Directive on Automated Decision-Making, and the Canadian Human Rights Act as they apply to AI.
NIST profiles, ISO/IEC standards, IEEE, OECD and the healthcare AI reporting/assurance frameworks (FDA, WHO, CHAI, CONSORT-AI…).
EU regulation beyond the AI Act itself (GPAI code of practice, guidance), plus the UK, Swiss and Norwegian frameworks. The EU AI Act and GDPR remain separate frameworks.
Sixteen further countries' AI laws and guidance plus the international instruments (Council of Europe, OECD, UNESCO, UN).
The EU AI Act, GDPR, HIPAA, CCPA, NIST AI RMF and ISO/IEC 42001 and 42005 are chosen individually alongside these. See coverage by plan for exactly what each plan can select. GOVERNBOX gives you a defensible starting point that you review and approve — it is not legal advice.
The overlooked middle
You were handed accountability for AI without a team, a budget line, or a compliance background. The market has an answer for the Fortune 500 and an answer for people who do nothing. GOVERNBOX is the answer for everyone in between.
$15,000–$25,000 per engagement
$339/month · $271/month for nonprofits
$50,000–$100,000+ per year
15 days · AI governance, working
The trial isn’t a tour. It’s the real product, on your real AI tools, producing a real board packet you could take into a meeting.
Your sector, size, states you operate in, and whether AI touches a consequential decision. Plain questions, no framework vocabulary.
The chatbot in marketing. The résumé screener. The grant-writing assistant. The one nobody told you about. Each gets an owner and a risk tier.
Guided questions produce a risk register entry, not a blank template. Incidents and AI agents get inventoried the same way.
A quarterly board chapter with your inventory, your risks, your gaps, and what you're doing about them. Defensible, cited, dated.
AI Governance, Risk, IT and Data all unlock on day one — the whole system, one login, one shared object graph.
Nothing auto-charges and nothing auto-selects. Every record you entered during the trial is still there, exactly as you left it.
Add the remaining two whenever you’re ready — all four core modules for the price of two.
See it before you sign up
Both are interactive — click through the real product at your own pace. Most people watch one, then start the trial.
The whole program in one automated walkthrough — the AI Readiness Scorecard, AI inventory, risk register, grounded policies with human review, staff training, a board-ready report, and a live trust page.
A closer look at the AI Governance module in action — inventory the tools, generate a cited policy, review and approve it, and land it in a board-ready report.
Click through the real product, module by module. No form for the first two.
Pricing
One price, printed here, before you ever start the trial. No “contact sales.”
or $3,500/year billed annually — about $292/month
Applies to every tier and every module configuration, at signup and at every renewal. The nonprofit rate is public — just choose it at checkout.
Start for free — no credit card required · see all plans and modules
Ready by January 1
Fifteen days from now you’ll either have a board-ready AI governance package — or you’ll know exactly what it would have taken. Either way, you’ll have spent about an hour.
Start my 15-day free trial →Prefer to look before you sign up? Take the free readiness scorecard — no account needed, no trial started.
Two decades directing large-scale technology portfolios, enterprise risk management and applied machine learning — which is why the control library is authored and versioned the way it is, rather than assembled from templates.
Gradient Descent LLC is an independent company. GOVERNBOX.ai is not affiliated with, endorsed by, or produced on behalf of any government agency.
Each plan keeps everything below it and adds the frameworks listed. Free previews NIST AI RMF only. Every framework here is backed by controls in the library and verified on one of the crosswalk shelves (Frameworks / United States / European Union & Europe / Canada / Global).
Jurisdictions (U.S. State Laws, U.S. National, Canada, AI Standards, Europe, Global) are each enabled as one unit on the Organization Profile; the standalone frameworks are chosen individually. New state laws are added as they pass. Not legal advice.
Transparent pricing
Start with the free Scorecard, then take the 15-day free trial — no credit card, nothing to cancel. On day 15 your workspace stays exactly as you left it until you pick a plan.
Prices below are for the AI Governance module — the first of four GOVERNBOX modules. See modular pricing →
NONPROFIT20 at checkout⚡ Not ready to pick a plan?
Test drive GOVERNBOX free for 15 days — no credit card needed.
Start 15-Day Free Trial →✓ Instant access · 15 days free · Zero credit card required
✓ Instant access · 15 days free · Zero credit card required
✓ Instant access · 15 days free · Zero credit card required
✓ Instant access · 15 days free · Zero credit card required