NONPROFITNonprofits: 20% off, permanently$271/monthinstead of $339. Every plan, every module, every renewal.
⚡ Try GOVERNBOX free for 15 daysAll five modules · no credit card · nothing to cancelStart 15-Day Free Trial →
Colorado repealed its AI Act — the ADMT law that replaced it starts January 1, 2027See what changed →
💠 GRC for the overlooked middle · 15 days free

$15,000–$25,000
Or $339 a month.

That’s the actual choice. A fragmented stack of point tools, spreadsheets, and consultant hours — or one governance system of record you run yourself.

Start free for 15 days with all five modules open. Build a defensible, board-ready package in about an hour — on one platform, one login, one shared object graph.

Start for free — no credit card required

No consultant, no sales call
20% off for nonprofits
Every clause cites a real control
What you’re paying for today
The typical middle-market governance stack, assembled one panic at a time
AI policy engagement
Consultant, one-time deliverable
$8,000–12,000
Risk register build
Contractor + spreadsheet template
$3,000–6,000
IT asset & renewal tracking
Point tool subscription
$1,800–3,600
Data inventory / retention mapping
Contractor hours
$2,000–4,000
Board reporting
Your own nights and weekends
unbilled
The four of them talking to each other
Nothing on the market does this
Typical first year
$15K–$25K
↓ Replaced by
GOVERNBOX.ai Starter
$339/mo
🏛️ Nonprofit? $271/month — 20% off, permanently.

Line by line

What comes out of the stack, and what replaces it

Four programs a middle-market organization can never staff separately — run by one accountable person, on one shared object graph.

AI governance consultant
Scoping call, interviews, a PDF, an invoice
$8K–12K
one-time, stale in a quarter
AI Governance moduleuse-case inventory, impact assessments, incident log, AI agent registry, 10 grounded policy generators with human review, framework crosswalks, employee attestations.
Risk register project
A contractor and a spreadsheet nobody maintains
$3K–6K
plus your time forever
Enterprise Risk moduleguided discovery, plain-language scoring, org-wide register, and a quarterly board chapter that writes itself from the records you already keep.
IT asset & subscription tracker
Another login, another bill
$1.8K–3.6K
per year
IT Inventory moduleevery device, subscription, and system with a named owner and a renewal date. The answers your insurer and auditor actually ask for.
Data inventory & retention mapping
Contractor hours, then drift
$2K–4K
and it drifts immediately
Data Management modulewhat data you hold, where it lives, how long you keep it, and proof you can answer a privacy request on time.
Making all four agree
Reconciling four sources of truth by hand
Not for sale
at any price
One shared object graphan AI tool logged once shows up as a risk, an IT asset, and a data flow. One login, one quarterly report across all four domains — the thing a stack of point tools structurally cannot do.
All five modules, one platform
Starter Complete — all four core modules for the price of two
$600/month

Stack costs are typical middle-market ranges for comparable scope, not quotes. Your consultant may be cheaper. They will not be a system of record.

1,561
AI bills introduced across 45 states
As of March 2026 — MultiState AI Legislation Tracker
109
New state AI laws already enacted
First half of 2026 alone — Tech Policy Press, Jul 6, 2026
38%
of organizations have a formal AI policy
ISACA, 2026
50%
of employees already use AI at work
Gallup, 2026

Why this line item exists at all

The law moved. The bill for ignoring it is not $339.

Fifty state legislatures spent 2026 writing AI rules, and the duties land on the organization that deploys the tool — not the vendor who built it. New Jersey’s Attorney General put it plainly: buying a third-party tool does not shield you from liability for what it decides.

⏱ Two dated deadlines · January 1, 2027

Colorado’s SB 26-189 and California’s CCPA rules on automated decisionmaking both begin: notice before use, a plain-language explanation of an adverse decision within 30 days, human review and data correction, and three years of records. Colorado’s Attorney General enforces it — up to $20,000 per violation.

Fifteen days is enough to know whether you’re covered. The gap list you don’t have is the one that gets discovered for you.

Why now

Four people are about to ask you the same question

Not eventually — on a schedule someone else set. Here is who asks, what they ask, and the five things you need to be able to answer.

Your board

“What's our AI policy?”

Usually followed, one meeting later, by “and how do we know it's working?” The second question is the hard one.

Funders and members

“How are you handling AI?”

Increasingly a line item in grant applications and renewal packets. A live trust page answers it without a scramble.

Customers and insurers

“Complete this AI questionnaire.”

Security reviews now carry AI sections. The answers come straight out of your inventory and crosswalk.

Regulators

“Show your assessment.”

State and international AI rules are arriving on a schedule. Where they apply, they ask for records you either have or don't.

The job, in five questions — strip the frameworks away and nothing else is left
  1. What AI are we using?

    Every tool, who owns it, and what data goes into it. Most organizations cannot answer this on the day they're asked.

  2. What are people allowed to do with it?

    A written policy and a practical standard, both short enough that staff will actually read them.

  3. What could go wrong, and who's watching?

    A named owner per risk, a sense of how likely and how bad, and a date you'll look again.

  4. Does everyone know the rules?

    Training, then a dated signature per person. Unsigned staff are the gap auditors find first.

  5. Can you prove all of the above?

    Dated records, a report each quarter, and a page you can send to anyone who asks. This is the part a template can't do.

What we’re not claiming

That you're already breaking the law

Most of these rules are new, and plenty may not apply to you. We'll tell you which ones do.

That software makes you compliant

It doesn't. It gives you a defensible starting point and the records to back it up. You review and approve everything.

That it's finished in one afternoon

The first package takes about an hour. Running the program is a rhythm, not an event, and that's the point.

This is the short version. Read the full 2026 executive briefing — the deadlines, the numbers and every primary source, last verified by a human on July 29, 2026.

Law coverage

The laws, everywhere you operate

AI law stopped being one deadline in one state. GOVERNBOX cites specific statutes from 28 U.S. states, covers 6 of those state AI laws with dedicated frameworks and crosswalks, and reaches U.S. federal law, the EU, the UK, Switzerland and Norway, Canada, the standards bodies and 21 countries in total — as selectable frameworks, not as a blog post. Pick the ones you operate under and every policy, crosswalk and gap report is generated and checked against exactly those.

28
U.S. states with statutes cited

6 of those laws go further, with their own controls and their own crosswalk report. New states are added as they pass.

21
countries covered

National AI law and guidance, plus the EU as a bloc and the international instruments.

39
frameworks, laws & standards

Selectable per organization — your documents are generated and checked against the ones you pick.

500+
controls in the library

Expert-written, versioned, and cited by ID in every clause we generate. Nothing is invented.

U.S. state AI law coverage

The library cites specific statutes from 28 states. 6 of those laws, across 5 states, go further and have their own framework, controls and crosswalk report. The rest are reached through the U.S. state law landscape framework, which tracks disclosure, chatbot, biometric, deepfake, health, insurance and employment-AI statutes as they pass — so a new law does not mean a new setting for you.

Alaska — covered by the U.S. state law landscape frameworkAKMaine — specific statutes cited in the U.S. state law landscape controlsMEWisconsin — covered by the U.S. state law landscape frameworkWIVermont — covered by the U.S. state law landscape frameworkVTNew Hampshire — specific statutes cited in the U.S. state law landscape controlsNHWashington — specific statutes cited in the U.S. state law landscape controlsWAIdaho — specific statutes cited in the U.S. state law landscape controlsIDMontana — specific statutes cited in the U.S. state law landscape controlsMTNorth Dakota — covered by the U.S. state law landscape frameworkNDMinnesota — specific statutes cited in the U.S. state law landscape controlsMNIllinois — specific statutes cited in the U.S. state law landscape controlsILMichigan — covered by the U.S. state law landscape frameworkMINew York — specific statutes cited in the U.S. state law landscape controlsNYMassachusetts — covered by the U.S. state law landscape frameworkMARhode Island — covered by the U.S. state law landscape frameworkRIOregon — specific statutes cited in the U.S. state law landscape controlsORNevada — specific statutes cited in the U.S. state law landscape controlsNVWyoming — covered by the U.S. state law landscape frameworkWYSouth Dakota — specific statutes cited in the U.S. state law landscape controlsSDIowa — covered by the U.S. state law landscape frameworkIAIndiana — specific statutes cited in the U.S. state law landscape controlsINOhio — covered by the U.S. state law landscape frameworkOHPennsylvania — covered by the U.S. state law landscape frameworkPANew Jersey — specific statutes cited in the U.S. state law landscape controlsNJConnecticut — dedicated framework: Connecticut SB 5 (PA 26-15)CTCalifornia — dedicated framework: California ADMT RegulationsCAUtah — specific statutes cited in the U.S. state law landscape controlsUTColorado — dedicated framework: Colorado ADMT Act (SB 26-189); Colorado Chatbot Safety (HB 26-1263)CONebraska — specific statutes cited in the U.S. state law landscape controlsNEMissouri — covered by the U.S. state law landscape frameworkMOKentucky — covered by the U.S. state law landscape frameworkKYWest Virginia — covered by the U.S. state law landscape frameworkWVVirginia — specific statutes cited in the U.S. state law landscape controlsVAMaryland — specific statutes cited in the U.S. state law landscape controlsMDDelaware — specific statutes cited in the U.S. state law landscape controlsDEArizona — specific statutes cited in the U.S. state law landscape controlsAZNew Mexico — covered by the U.S. state law landscape frameworkNMKansas — covered by the U.S. state law landscape frameworkKSArkansas — specific statutes cited in the U.S. state law landscape controlsARTennessee — specific statutes cited in the U.S. state law landscape controlsTNNorth Carolina — covered by the U.S. state law landscape frameworkNCSouth Carolina — covered by the U.S. state law landscape frameworkSCDistrict of Columbia — covered by the U.S. state law landscape frameworkDCOklahoma — covered by the U.S. state law landscape frameworkOKLouisiana — covered by the U.S. state law landscape frameworkLAMississippi — covered by the U.S. state law landscape frameworkMSAlabama — covered by the U.S. state law landscape frameworkALGeorgia — specific statutes cited in the U.S. state law landscape controlsGAHawaii — dedicated framework: Hawaii AI Acts (247 / 248)HITexas — dedicated framework: Texas TRAIGATXFlorida — specific statutes cited in the U.S. state law landscape controlsFL
Own framework + crosswalkSpecific statutes citedReached via the landscape framework
  • ColoradoColorado ADMT Act (SB 26-189) · Colorado Chatbot Safety (HB 26-1263)
  • ConnecticutConnecticut SB 5 (PA 26-15)
  • TexasTexas TRAIGA
  • CaliforniaCalifornia ADMT Regulations
  • HawaiiHawaii AI Acts (247 / 248)

Includes California's ADMT regulations. The CCPA privacy statute is a separate framework, available on Pro. All 51 jurisdictions shown are reachable through the U.S. state law landscape framework; 28 have their own statutes cited in it, and 5 go further with dedicated controls and a coverage report of their own. This map describes what GOVERNBOX covers — it is not a survey of which states have passed AI legislation, and it is not legal advice.

Regulatory jurisdictions — each enabled as one unit on your Organization Profile
  • U.S. State AI LawsStarter+

    Colorado ADMT Act (SB 26-189) · Colorado Chatbot Safety (HB 26-1263) · Connecticut SB 5 (PA 26-15) · Texas TRAIGA · California ADMT Regulations · Hawaii AI Acts (247 / 248)

  • United States — federal law & state landscapeStarter+

    Federal legislation, executive orders and agency regulation, plus a cross-state view of AI disclosure and training-data laws. Per-state statutes are the U.S. State AI Laws jurisdiction above.

  • CanadaPro+

    PIPEDA and provincial privacy law, the Directive on Automated Decision-Making, and the Canadian Human Rights Act as they apply to AI.

  • AI frameworks, standards & healthcare guidelinesPro+

    NIST profiles, ISO/IEC standards, IEEE, OECD and the healthcare AI reporting/assurance frameworks (FDA, WHO, CHAI, CONSORT-AI…).

  • Europe — EU regulation, UK, Switzerland, NorwayAgency

    EU regulation beyond the AI Act itself (GPAI code of practice, guidance), plus the UK, Swiss and Norwegian frameworks. The EU AI Act and GDPR remain separate frameworks.

  • Global — Americas, Middle East, Asia-Pacific & internationalAgency

    Sixteen further countries' AI laws and guidance plus the international instruments (Council of Europe, OECD, UNESCO, UN).

The EU AI Act, GDPR, HIPAA, CCPA, NIST AI RMF and ISO/IEC 42001 and 42005 are chosen individually alongside these. See coverage by plan for exactly what each plan can select. GOVERNBOX gives you a defensible starting point that you review and approve — it is not legal advice.

Two short films

Watch it work before you spend a dollar

Both are interactive — click through the real product at your own pace. No form, no card, no call.

Your New Governance & Management Partner
Film one

The Question

The whole program in one automated walkthrough — the AI Readiness Scorecard, AI inventory, risk register, grounded policies with human review, staff training, a board-ready report, and a live trust page.

Let's Talk AI Governance Programs
Film two

After the Applause

A closer look at the AI Governance module in action — inventory the tools, generate a cited policy, review and approve it, and land it in a board-ready report.

Explore the full interactive demo library →

Click through the real product, module by module. No form for the first two.

The trial is the proof, not the pitch

Free for 15 days. Then you choose how far to take it.

The trial hands you every module at once — the whole platform, one login, one shared graph.

Days 1–15 · free

All five modules, open

$0 · no credit card

Not an AI-only teaser. AI Governance, Risk, IT, and Data all unlock on day one.

🤖
AI
⚠️
Risk
💻
IT
🗄️
Data
  • Use case, risk, IT, and data inventories
  • Impact assessments, incidents, AI agents
  • Training + project management
  • Quarterly board report across all four
  • Limited access: 2 records per module
  • No policy or document generator — that unlocks when you subscribe
Day 15 · your call

Pick any plan you want

from $339/mo · $271 nonprofit

Nothing auto-charges and nothing auto-selects. Starter, Pro, Agency — one core module or all four. You choose.

  • Everything you entered during the trial stays with you
  • Your inventories, risks, assessments and incidents come back exactly as you left them
  • Caps lift; all 10 policy and document generators unlock
  • Crosswalks, attestations, trust badge
Whenever you’re ready

Complete — all four core modules

$600/mo · $480 nonprofit
  • AI, Risk, IT, and Data
  • All four for the price of two
  • One quarterly report spanning every domain
  • Nothing re-entered — one shared object graph
🏛️ NONPROFIT PRICING

Nonprofits take 20% off — permanently.

Not an intro rate. The discount applies at signup and at every renewal, on every tier, and on every module configuration you choose.

Nine in ten nonprofits report using AI somewhere in their operations. Fewer than half have a policy for it. You’re the ones being asked the questions with the least budget to answer them — so the price reflects that. The nonprofit rate is public: just choose it at checkout.

$339/month
$271/mo
or $2,800/year billed annually
≈ $233/month
You keep $814/year — or $700 on annual billing.

Fifteen days · about an hour of work

Run the trial. Then decide whether $339 was ever really the question.

No consultant. No sales call. No specialist team. No credit card — and everything you build in those fifteen days stays yours, whichever plan you pick afterward.

Start my 15-day free trial →

Not ready to start? Take the free readiness scorecard — no trial started.

Sources1,561 AI bills across 45 states, as of March 2026 — MultiState AI Legislation Tracker. · 109 state AI laws enacted as of July 1, 2026 — Tech Policy Press, July 6, 2026. · Colorado SB 26-189 (Automated Decision-Making Technology), signed May 14, 2026, operative January 1, 2027; exclusive AG enforcement, penalties up to $20,000 per violation — leg.colorado.gov. · California CCPA ADMT regulations — businesses already using ADMT for a significant decision comply by January 1, 2027 — cppa.ca.gov. · “A covered entity is not shielded from liability for algorithmic discrimination … simply because the tool was developed by a third party” — NJ Division on Civil Rights guidance, January 2025. · 38% of organizations have a formal AI policy — ISACA, 2026. 50% of employees use AI at work — Gallup, 2026. 92% of nonprofits report AI use / 47% have a policy — Fundraising.AI, 2026.
GOVERNBOX.ai is a Gradient Descent LLC product. This page describes a software product and is not legal advice. Cost comparisons are typical market ranges for comparable scope, not quotes. Legal summaries are current as of July 30, 2026.
About the founder
Jim TunnessenFounder & CEO, GOVERNBOX.ai
Former 2× Federal CIO / CAIO / CTO / CPO

Two decades directing large-scale technology portfolios, enterprise risk management and applied machine learning — which is why the control library is authored and versioned the way it is, rather than assembled from templates.

Gradient Descent LLC is an independent company. GOVERNBOX.ai is not affiliated with, endorsed by, or produced on behalf of any government agency.

Coverage by plan

What’s covered on each plan

Each plan keeps everything below it and adds the frameworks listed. Free previews NIST AI RMF only. Every framework here is backed by controls in the library and verified on one of the crosswalk shelves (Frameworks / United States / European Union & Europe / Canada / Global).

Starter
Included on every paid plan:
  • NIST AI RMF
  • ISO/IEC 42001
  • U.S. state AI laws (6 today — added as they pass)
    Colorado ADMT Act (SB 26-189) · Colorado Chatbot Safety (HB 26-1263) · Connecticut SB 5 (PA 26-15) · Texas TRAIGA · California ADMT Regulations · Hawaii AI Acts (247 / 248). The U.S. state law landscape framework additionally cites specific statutes from 28 states.
  • United States — federal law & state landscape
    Federal legislation, executive orders and agency regulation, plus a cross-state view of AI disclosure and training-data laws. Per-state statutes are the U.S. State AI Laws jurisdiction above.
Pro
Everything in Starter, plus:
  • ISO/IEC 42005
  • CCPA
  • Canada
    PIPEDA and provincial privacy law, the Directive on Automated Decision-Making, and the Canadian Human Rights Act as they apply to AI.
  • AI frameworks, standards & healthcare guidelines
    NIST profiles, ISO/IEC standards, IEEE, OECD and the healthcare AI reporting/assurance frameworks (FDA, WHO, CHAI, CONSORT-AI…).
Agency
Everything in Pro, plus:
  • EU AI Act
  • HIPAA
  • GDPR
  • Europe — EU regulation, UK, Switzerland, Norway
    EU regulation beyond the AI Act itself (GPAI code of practice, guidance), plus the UK, Swiss and Norwegian frameworks. The EU AI Act and GDPR remain separate frameworks.
  • Global — Americas, Middle East, Asia-Pacific & international
    Sixteen further countries' AI laws and guidance plus the international instruments (Council of Europe, OECD, UNESCO, UN).

Jurisdictions (U.S. State Laws, U.S. National, Canada, AI Standards, Europe, Global) are each enabled as one unit on the Organization Profile; the standalone frameworks are chosen individually. New state laws are added as they pass. Not legal advice.

Transparent pricing

Simple, Honest Pricing

Start with the free Scorecard, then take the 15-day free trial — no credit card, nothing to cancel. On day 15 your workspace stays exactly as you left it until you pick a plan.

Prices below are for the AI Governance module — the first of four GOVERNBOX modules. See modular pricing →

💙 Nonprofits save 20% on every plan — enter code NONPROFIT20 at checkout

⚡ Not ready to pick a plan?

Test drive GOVERNBOX free for 15 days — no credit card needed.

Start 15-Day Free Trial →

Instant access  ·  15 days free  ·  Zero credit card required

Starter
$3,500/yr
or $339/mo billed monthly
🏛️ Nonprofit: $2,800/yr · code NONPROFIT20
  • The full AI Governance module
  • AI Use Policy + AI Acceptable Use Standard
  • NIST AI RMF + ISO 42001 crosswalks
  • Every U.S. state AI law, added as they pass — Colorado ADMT Act (SB 26-189), Colorado Chatbot Safety (HB 26-1263), Connecticut SB 5 (PA 26-15), Texas TRAIGA, California ADMT Regulations, Hawaii AI Acts (247 / 248)
  • Plus specific statutes from 28 states via the U.S. state law landscape
  • United States — federal law & state landscape (U.S. National)
  • Risk Register + Impact Assessments
  • Incident log, Training plan, full Board Report
  • AI Cost Tracking & Roll-Up (per use case + program office)
  • AI Agents inventory (basic registration)
  • AI Project Management — up to 2 concurrent projects
  • Governance Badge + live public Trust Page
  • Employee Attestation Portal — unlimited signers
  • Regulatory horizon feed
  • Word + PDF export
  • Staff AI-tool reporting portal — anonymous shadow-AI intake, no login
  • Unlimited staff participants — report AI tools, sign policies & complete training, no seat required
  • 10 admin seats
Try Starter free for 15 days →

Instant access  ·  15 days free  ·  Zero credit card required

Most popular
Pro
$12,000/yr
equates to $1,000 per month
🏛️ Nonprofit: $9,600/yr · code NONPROFIT20
  • Everything in Starter
  • + ISO/IEC 42005 · CCPA · Canada · AI frameworks, standards & healthcare guidelines
  • NIST SP 800-53 Rev. 5 / CSF 2.0 crosswalk
  • Risk heat map
  • Full Impact Assessments — auto-populates Risk Register
  • AI Project Management — up to 5 concurrent projects
  • AI Strategic Plan + CAIO Position Statement wizards
  • Privacy Policy (CCPA-grounded)
  • AI Incident Response Plan + Vendor AI Risk Assessment
  • Branded document exports
  • 15 admin seats
Try Pro free for 15 days →

Instant access  ·  15 days free  ·  Zero credit card required

Agency
$25,000/yr
🏛️ Nonprofit: $20,000/yr · code NONPROFIT20
  • Everything in Pro
  • + EU AI Act framework (risk tiering, Art. 5 & Art. 73 reporting)
  • + HIPAA & GDPR data-privacy frameworks
  • + Europe — EU regulation, UK, Switzerland, Norway
  • + Global — Americas, Middle East, Asia-Pacific & international (16 further countries + the international instruments)
  • White-labeled Trust Page & badge
  • OMB AI Compliance Plan (M-25-21/22)
  • AI Agents zero-trust checklist + scoring
  • AI Project Management — unlimited projects
  • Priority support
  • Enterprise SSO (SAML / OIDC)
  • Advisory session included
  • 20 admin seats
Try Agency free for 15 days →

Instant access  ·  15 days free  ·  Zero credit card required