◆ Nonprofits save 20% — $271/mo, every plan, every module, permanently.
⚡ Try GOVERNBOX free for 15 daysAll five modules · no credit card · nothing to cancelStart 15-Day Free Trial →
Colorado repealed its AI Act — the ADMT law that replaced it starts January 1, 2027See what changed →
⏱ Colorado + California duties begin January 1, 2027

1,561 AI bills.
45 states.
One deadline you can actually hit.

GOVERNBOX.ai is the governance system of record for the overlooked middle. Start free for 15 days with all five modules — AI Governance, Risk, IT, Data and Privacy — on one platform.

No consultant. No sales call. No specialist team. Plain-language, step-by-step, with every clause traced to a control you can hand an auditor — a defensible, board-ready package in about an hour.

Start for free — no credit card required

Every clause cites a real control
20% off for nonprofits
Four live modules, one login
The compliance clock

Until Colorado’s SB 26-189 and California’s CCPA ADMT rules take effect — January 1, 2027

Days
Hours
Mins
Secs
Notice before you use it. Tell people an automated system is involved in a decision about them.
Explain an adverse decision within 30 days, in plain language.
Offer human review and let people correct the data behind the decision.
Keep records for three years. Colorado's Attorney General can ask — up to $20,000 per violation.

Colorado is AG-enforced only, with no private right of action. California’s rules reach businesses already using automated decision-making technology for a significant decision.

🏛️ NONPROFIT
Nonprofits save 20%

Permanently — at signup and at every renewal. Just choose the rate at checkout.

$339/mo
$271/mo
1,561
AI bills introduced
Across 45 states, as of March 2026 — MultiState AI tracker
109
New AI laws already enacted
In the first half of 2026 alone — Tech Policy Press, July 6, 2026
Aug 2
EU transparency duties land
2026 — AI chatbots must disclose; synthetic content marked. High-risk duties: Dec 2, 2027
38%
of organizations have a formal AI policy
While 50% of employees already use AI at work — ISACA 2026 · Gallup 2026

Different states, different definitions, different deadlines — and the obligations attach to you as the deployer, not the vendor who built the tool.

Why this matters — read the 2026 briefing →
Why now

Four people are about to ask you the same question

Not eventually — on a schedule someone else set. Here is who asks, what they ask, and the five things you need to be able to answer.

Your board

“What's our AI policy?”

Usually followed, one meeting later, by “and how do we know it's working?” The second question is the hard one.

Funders and members

“How are you handling AI?”

Increasingly a line item in grant applications and renewal packets. A live trust page answers it without a scramble.

Customers and insurers

“Complete this AI questionnaire.”

Security reviews now carry AI sections. The answers come straight out of your inventory and crosswalk.

Regulators

“Show your assessment.”

State and international AI rules are arriving on a schedule. Where they apply, they ask for records you either have or don't.

The job, in five questions — strip the frameworks away and nothing else is left
  1. What AI are we using?

    Every tool, who owns it, and what data goes into it. Most organizations cannot answer this on the day they're asked.

  2. What are people allowed to do with it?

    A written policy and a practical standard, both short enough that staff will actually read them.

  3. What could go wrong, and who's watching?

    A named owner per risk, a sense of how likely and how bad, and a date you'll look again.

  4. Does everyone know the rules?

    Training, then a dated signature per person. Unsigned staff are the gap auditors find first.

  5. Can you prove all of the above?

    Dated records, a report each quarter, and a page you can send to anyone who asks. This is the part a template can't do.

What we’re not claiming

That you're already breaking the law

Most of these rules are new, and plenty may not apply to you. We'll tell you which ones do.

That software makes you compliant

It doesn't. It gives you a defensible starting point and the records to back it up. You review and approve everything.

That it's finished in one afternoon

The first package takes about an hour. Running the program is a rhythm, not an event, and that's the point.

This is the short version. Read the full 2026 executive briefing — the deadlines, the numbers and every primary source, last verified by a human on July 29, 2026.

Law coverage

The laws, everywhere you operate

AI law stopped being one deadline in one state. GOVERNBOX cites specific statutes from 28 U.S. states, covers 6 of those state AI laws with dedicated frameworks and crosswalks, and reaches U.S. federal law, the EU, the UK, Switzerland and Norway, Canada, the standards bodies and 21 countries in total — as selectable frameworks, not as a blog post. Pick the ones you operate under and every policy, crosswalk and gap report is generated and checked against exactly those.

28
U.S. states with statutes cited

6 of those laws go further, with their own controls and their own crosswalk report. New states are added as they pass.

21
countries covered

National AI law and guidance, plus the EU as a bloc and the international instruments.

39
frameworks, laws & standards

Selectable per organization — your documents are generated and checked against the ones you pick.

500+
controls in the library

Expert-written, versioned, and cited by ID in every clause we generate. Nothing is invented.

U.S. state AI law coverage

The library cites specific statutes from 28 states. 6 of those laws, across 5 states, go further and have their own framework, controls and crosswalk report. The rest are reached through the U.S. state law landscape framework, which tracks disclosure, chatbot, biometric, deepfake, health, insurance and employment-AI statutes as they pass — so a new law does not mean a new setting for you.

Alaska — covered by the U.S. state law landscape frameworkAKMaine — specific statutes cited in the U.S. state law landscape controlsMEWisconsin — covered by the U.S. state law landscape frameworkWIVermont — covered by the U.S. state law landscape frameworkVTNew Hampshire — specific statutes cited in the U.S. state law landscape controlsNHWashington — specific statutes cited in the U.S. state law landscape controlsWAIdaho — specific statutes cited in the U.S. state law landscape controlsIDMontana — specific statutes cited in the U.S. state law landscape controlsMTNorth Dakota — covered by the U.S. state law landscape frameworkNDMinnesota — specific statutes cited in the U.S. state law landscape controlsMNIllinois — specific statutes cited in the U.S. state law landscape controlsILMichigan — covered by the U.S. state law landscape frameworkMINew York — specific statutes cited in the U.S. state law landscape controlsNYMassachusetts — covered by the U.S. state law landscape frameworkMARhode Island — covered by the U.S. state law landscape frameworkRIOregon — specific statutes cited in the U.S. state law landscape controlsORNevada — specific statutes cited in the U.S. state law landscape controlsNVWyoming — covered by the U.S. state law landscape frameworkWYSouth Dakota — specific statutes cited in the U.S. state law landscape controlsSDIowa — covered by the U.S. state law landscape frameworkIAIndiana — specific statutes cited in the U.S. state law landscape controlsINOhio — covered by the U.S. state law landscape frameworkOHPennsylvania — covered by the U.S. state law landscape frameworkPANew Jersey — specific statutes cited in the U.S. state law landscape controlsNJConnecticut — dedicated framework: Connecticut SB 5 (PA 26-15)CTCalifornia — dedicated framework: California ADMT RegulationsCAUtah — specific statutes cited in the U.S. state law landscape controlsUTColorado — dedicated framework: Colorado ADMT Act (SB 26-189); Colorado Chatbot Safety (HB 26-1263)CONebraska — specific statutes cited in the U.S. state law landscape controlsNEMissouri — covered by the U.S. state law landscape frameworkMOKentucky — covered by the U.S. state law landscape frameworkKYWest Virginia — covered by the U.S. state law landscape frameworkWVVirginia — specific statutes cited in the U.S. state law landscape controlsVAMaryland — specific statutes cited in the U.S. state law landscape controlsMDDelaware — specific statutes cited in the U.S. state law landscape controlsDEArizona — specific statutes cited in the U.S. state law landscape controlsAZNew Mexico — covered by the U.S. state law landscape frameworkNMKansas — covered by the U.S. state law landscape frameworkKSArkansas — specific statutes cited in the U.S. state law landscape controlsARTennessee — specific statutes cited in the U.S. state law landscape controlsTNNorth Carolina — covered by the U.S. state law landscape frameworkNCSouth Carolina — covered by the U.S. state law landscape frameworkSCDistrict of Columbia — covered by the U.S. state law landscape frameworkDCOklahoma — covered by the U.S. state law landscape frameworkOKLouisiana — covered by the U.S. state law landscape frameworkLAMississippi — covered by the U.S. state law landscape frameworkMSAlabama — covered by the U.S. state law landscape frameworkALGeorgia — specific statutes cited in the U.S. state law landscape controlsGAHawaii — dedicated framework: Hawaii AI Acts (247 / 248)HITexas — dedicated framework: Texas TRAIGATXFlorida — specific statutes cited in the U.S. state law landscape controlsFL
Own framework + crosswalkSpecific statutes citedReached via the landscape framework
  • ColoradoColorado ADMT Act (SB 26-189) · Colorado Chatbot Safety (HB 26-1263)
  • ConnecticutConnecticut SB 5 (PA 26-15)
  • TexasTexas TRAIGA
  • CaliforniaCalifornia ADMT Regulations
  • HawaiiHawaii AI Acts (247 / 248)

Includes California's ADMT regulations. The CCPA privacy statute is a separate framework, available on Pro. All 51 jurisdictions shown are reachable through the U.S. state law landscape framework; 28 have their own statutes cited in it, and 5 go further with dedicated controls and a coverage report of their own. This map describes what GOVERNBOX covers — it is not a survey of which states have passed AI legislation, and it is not legal advice.

Regulatory jurisdictions — each enabled as one unit on your Organization Profile
  • U.S. State AI LawsStarter+

    Colorado ADMT Act (SB 26-189) · Colorado Chatbot Safety (HB 26-1263) · Connecticut SB 5 (PA 26-15) · Texas TRAIGA · California ADMT Regulations · Hawaii AI Acts (247 / 248)

  • United States — federal law & state landscapeStarter+

    Federal legislation, executive orders and agency regulation, plus a cross-state view of AI disclosure and training-data laws. Per-state statutes are the U.S. State AI Laws jurisdiction above.

  • CanadaPro+

    PIPEDA and provincial privacy law, the Directive on Automated Decision-Making, and the Canadian Human Rights Act as they apply to AI.

  • AI frameworks, standards & healthcare guidelinesPro+

    NIST profiles, ISO/IEC standards, IEEE, OECD and the healthcare AI reporting/assurance frameworks (FDA, WHO, CHAI, CONSORT-AI…).

  • Europe — EU regulation, UK, Switzerland, NorwayAgency

    EU regulation beyond the AI Act itself (GPAI code of practice, guidance), plus the UK, Swiss and Norwegian frameworks. The EU AI Act and GDPR remain separate frameworks.

  • Global — Americas, Middle East, Asia-Pacific & internationalAgency

    Sixteen further countries' AI laws and guidance plus the international instruments (Council of Europe, OECD, UNESCO, UN).

The EU AI Act, GDPR, HIPAA, CCPA, NIST AI RMF and ISO/IEC 42001 and 42005 are chosen individually alongside these. See coverage by plan for exactly what each plan can select. GOVERNBOX gives you a defensible starting point that you review and approve — it is not legal advice.

The overlooked middle

Too big to wing it. Too small to buy an enterprise GRC platform.

You were handed accountability for AI without a team, a budget line, or a compliance background. The market has an answer for the Fortune 500 and an answer for people who do nothing. GOVERNBOX is the answer for everyone in between.

Option 1

Hire a consultant

$15,000–$25,000 per engagement

  • A PDF that's stale in a quarter
  • Nothing you can run yourself
  • The next board cycle starts the meter again
You are here
The overlooked middle

GOVERNBOX.ai

$339/month · $271/month for nonprofits

  • One login, one shared object graph
  • One quarterly board report across all four domains
  • Plain language — no jargon, no framework fluency required
  • Every clause traced to a control you can show an auditor
  • You run it. Not a vendor, not a contractor.
Option 3

Enterprise GRC suite

$50,000–$100,000+ per year

  • Priced and staffed for a compliance department
  • Six-month implementation, consultant required
  • Built for auditors, not for the person who got handed this

15 days · AI governance, working

What your first hour actually looks like

The trial isn’t a tour. It’s the real product, on your real AI tools, producing a real board packet you could take into a meeting.

1

Answer the profile

Your sector, size, states you operate in, and whether AI touches a consequential decision. Plain questions, no framework vocabulary.

~8 minutes
2

Log your real AI tools

The chatbot in marketing. The résumé screener. The grant-writing assistant. The one nobody told you about. Each gets an owner and a risk tier.

~15 minutes
3

Run the impact assessment

Guided questions produce a risk register entry, not a blank template. Incidents and AI agents get inventoried the same way.

~20 minutes
4

Export the board report

A quarterly board chapter with your inventory, your risks, your gaps, and what you're doing about them. Defensible, cited, dated.

~5 minutes
Days 1–15 · your free trial

All five modules, running for real

AI Governance, Risk, IT and Data all unlock on day one — the whole system, one login, one shared object graph.

🤖
AI
⚠️
Risk
💻
IT
🗄️
Data
  • AI use case, IT asset, and data inventories
  • Risk register, impact assessments, incidents
  • AI agents inventory
  • Training module + project management
  • Quarterly board report across all four
  • Regulatory horizon feed — “What's Changing”
  • ·Limited access: up to 2 records per module.
  • ·No policy or document generator — all 10 are visible in preview and unlock when you subscribe.
Day 15 · your call

Pick any plan — and keep everything you built

Nothing auto-charges and nothing auto-selects. Every record you entered during the trial is still there, exactly as you left it.

  • Your trial data carries over — nothing lost, nothing re-entered
  • Record caps lift; all 10 policy and document generators unlock
  • Framework crosswalks, attestations, and the trust badge turn on
  • Starter, Pro or Agency — one core module or all four, your choice:
⚠️
Risk
the accidental risk manager
💻
IT
the accidental IT director
🗄️
Data
the accidental data steward

Add the remaining two whenever you’re ready — all four core modules for the price of two.

See it before you sign up

Two short films. No form, no card, no call.

Both are interactive — click through the real product at your own pace. Most people watch one, then start the trial.

Your New Governance & Management Partner
Film one

The Question

The whole program in one automated walkthrough — the AI Readiness Scorecard, AI inventory, risk register, grounded policies with human review, staff training, a board-ready report, and a live trust page.

Let's Talk AI Governance Programs
Film two

After the Applause

A closer look at the AI Governance module in action — inventory the tools, generate a cited policy, review and approve it, and land it in a board-ready report.

Explore the full interactive demo library →

Click through the real product, module by module. No form for the first two.

Pricing

What it costs after the 15 days

One price, printed here, before you ever start the trial. No “contact sales.”

Starter · AI Governance + one module
$339/month

or $3,500/year billed annually — about $292/month

🏛️ Nonprofit? Take 20% off — permanently.
$271/month  ·  $2,800/year

Applies to every tier and every module configuration, at signup and at every renewal. The nonprofit rate is public — just choose it at checkout.

Replaces a $15,000–$25,000 stack of point tools, spreadsheets, and consultant hours — with one login, one shared object graph, and one quarterly report across AI, Risk, IT, and Data.

Start for free — no credit card required · see all plans and modules

Ready by January 1

You didn’t ask to own this. You can still be the person who has it handled.

Fifteen days from now you’ll either have a board-ready AI governance package — or you’ll know exactly what it would have taken. Either way, you’ll have spent about an hour.

Start my 15-day free trial →

Prefer to look before you sign up? Take the free readiness scorecard — no account needed, no trial started.

Sources1,561 AI bills across 45 states, as of March 2026 — MultiState AI Legislation Tracker. · 109 state AI laws enacted as of July 1, 2026 — Tech Policy Press, July 6, 2026. · Colorado SB 26-189 (Automated Decision-Making Technology), signed May 14, 2026, operative January 1, 2027; AG-only enforcement — leg.colorado.gov, coag.gov. · California CCPA ADMT regulations: businesses already using ADMT for a significant decision must comply by January 1, 2027 — cppa.ca.gov. · EU AI Act as amended by Regulation (EU) 2026/1744: Article 50 transparency duties apply August 2, 2026; Annex III high-risk duties move to December 2, 2027 — EUR-Lex. · 38% of organizations have a formal AI policy — ISACA, 2026. 50% of employees use AI at work — Gallup, 2026.
GOVERNBOX.ai is a Gradient Descent LLC product. This page is information about a software product, not legal advice. Deadlines and duties described here are summaries of published law and regulation as of July 30, 2026; confirm your own obligations with counsel.
About the founder
Jim TunnessenFounder & CEO, GOVERNBOX.ai
Former 2× Federal CIO / CAIO / CTO / CPO

Two decades directing large-scale technology portfolios, enterprise risk management and applied machine learning — which is why the control library is authored and versioned the way it is, rather than assembled from templates.

Gradient Descent LLC is an independent company. GOVERNBOX.ai is not affiliated with, endorsed by, or produced on behalf of any government agency.

Coverage by plan

What’s covered on each plan

Each plan keeps everything below it and adds the frameworks listed. Free previews NIST AI RMF only. Every framework here is backed by controls in the library and verified on one of the crosswalk shelves (Frameworks / United States / European Union & Europe / Canada / Global).

Starter
Included on every paid plan:
  • NIST AI RMF
  • ISO/IEC 42001
  • U.S. state AI laws (6 today — added as they pass)
    Colorado ADMT Act (SB 26-189) · Colorado Chatbot Safety (HB 26-1263) · Connecticut SB 5 (PA 26-15) · Texas TRAIGA · California ADMT Regulations · Hawaii AI Acts (247 / 248). The U.S. state law landscape framework additionally cites specific statutes from 28 states.
  • United States — federal law & state landscape
    Federal legislation, executive orders and agency regulation, plus a cross-state view of AI disclosure and training-data laws. Per-state statutes are the U.S. State AI Laws jurisdiction above.
Pro
Everything in Starter, plus:
  • ISO/IEC 42005
  • CCPA
  • Canada
    PIPEDA and provincial privacy law, the Directive on Automated Decision-Making, and the Canadian Human Rights Act as they apply to AI.
  • AI frameworks, standards & healthcare guidelines
    NIST profiles, ISO/IEC standards, IEEE, OECD and the healthcare AI reporting/assurance frameworks (FDA, WHO, CHAI, CONSORT-AI…).
Agency
Everything in Pro, plus:
  • EU AI Act
  • HIPAA
  • GDPR
  • Europe — EU regulation, UK, Switzerland, Norway
    EU regulation beyond the AI Act itself (GPAI code of practice, guidance), plus the UK, Swiss and Norwegian frameworks. The EU AI Act and GDPR remain separate frameworks.
  • Global — Americas, Middle East, Asia-Pacific & international
    Sixteen further countries' AI laws and guidance plus the international instruments (Council of Europe, OECD, UNESCO, UN).

Jurisdictions (U.S. State Laws, U.S. National, Canada, AI Standards, Europe, Global) are each enabled as one unit on the Organization Profile; the standalone frameworks are chosen individually. New state laws are added as they pass. Not legal advice.

Transparent pricing

Simple, Honest Pricing

Start with the free Scorecard, then take the 15-day free trial — no credit card, nothing to cancel. On day 15 your workspace stays exactly as you left it until you pick a plan.

Prices below are for the AI Governance module — the first of four GOVERNBOX modules. See modular pricing →

💙 Nonprofits save 20% on every plan — enter code NONPROFIT20 at checkout

⚡ Not ready to pick a plan?

Test drive GOVERNBOX free for 15 days — no credit card needed.

Start 15-Day Free Trial →

Instant access  ·  15 days free  ·  Zero credit card required

Starter
$3,500/yr
or $339/mo billed monthly
🏛️ Nonprofit: $2,800/yr · code NONPROFIT20
  • The full AI Governance module
  • AI Use Policy + AI Acceptable Use Standard
  • NIST AI RMF + ISO 42001 crosswalks
  • Every U.S. state AI law, added as they pass — Colorado ADMT Act (SB 26-189), Colorado Chatbot Safety (HB 26-1263), Connecticut SB 5 (PA 26-15), Texas TRAIGA, California ADMT Regulations, Hawaii AI Acts (247 / 248)
  • Plus specific statutes from 28 states via the U.S. state law landscape
  • United States — federal law & state landscape (U.S. National)
  • Risk Register + Impact Assessments
  • Incident log, Training plan, full Board Report
  • AI Cost Tracking & Roll-Up (per use case + program office)
  • AI Agents inventory (basic registration)
  • AI Project Management — up to 2 concurrent projects
  • Governance Badge + live public Trust Page
  • Employee Attestation Portal — unlimited signers
  • Regulatory horizon feed
  • Word + PDF export
  • Staff AI-tool reporting portal — anonymous shadow-AI intake, no login
  • Unlimited staff participants — report AI tools, sign policies & complete training, no seat required
  • 10 admin seats
Try Starter free for 15 days →

Instant access  ·  15 days free  ·  Zero credit card required

Most popular
Pro
$12,000/yr
equates to $1,000 per month
🏛️ Nonprofit: $9,600/yr · code NONPROFIT20
  • Everything in Starter
  • + ISO/IEC 42005 · CCPA · Canada · AI frameworks, standards & healthcare guidelines
  • NIST SP 800-53 Rev. 5 / CSF 2.0 crosswalk
  • Risk heat map
  • Full Impact Assessments — auto-populates Risk Register
  • AI Project Management — up to 5 concurrent projects
  • AI Strategic Plan + CAIO Position Statement wizards
  • Privacy Policy (CCPA-grounded)
  • AI Incident Response Plan + Vendor AI Risk Assessment
  • Branded document exports
  • 15 admin seats
Try Pro free for 15 days →

Instant access  ·  15 days free  ·  Zero credit card required

Agency
$25,000/yr
🏛️ Nonprofit: $20,000/yr · code NONPROFIT20
  • Everything in Pro
  • + EU AI Act framework (risk tiering, Art. 5 & Art. 73 reporting)
  • + HIPAA & GDPR data-privacy frameworks
  • + Europe — EU regulation, UK, Switzerland, Norway
  • + Global — Americas, Middle East, Asia-Pacific & international (16 further countries + the international instruments)
  • White-labeled Trust Page & badge
  • OMB AI Compliance Plan (M-25-21/22)
  • AI Agents zero-trust checklist + scoring
  • AI Project Management — unlimited projects
  • Priority support
  • Enterprise SSO (SAML / OIDC)
  • Advisory session included
  • 20 admin seats
Try Agency free for 15 days →

Instant access  ·  15 days free  ·  Zero credit card required