The Question
The whole program in one automated walkthrough — the AI Readiness Scorecard, AI inventory, risk register, grounded policies with human review, staff training, a board-ready report, and a live trust page.
That’s the actual choice. A fragmented stack of point tools, spreadsheets, and consultant hours — or one governance system of record you run yourself.
Start free for 15 days with all five modules open. Build a defensible, board-ready package in about an hour — on one platform, one login, one shared object graph.
Start for free — no credit card required
Line by line
Four programs a middle-market organization can never staff separately — run by one accountable person, on one shared object graph.
Stack costs are typical middle-market ranges for comparable scope, not quotes. Your consultant may be cheaper. They will not be a system of record.
Why this line item exists at all
Fifty state legislatures spent 2026 writing AI rules, and the duties land on the organization that deploys the tool — not the vendor who built it. New Jersey’s Attorney General put it plainly: buying a third-party tool does not shield you from liability for what it decides.
Colorado’s SB 26-189 and California’s CCPA rules on automated decisionmaking both begin: notice before use, a plain-language explanation of an adverse decision within 30 days, human review and data correction, and three years of records. Colorado’s Attorney General enforces it — up to $20,000 per violation.
Fifteen days is enough to know whether you’re covered. The gap list you don’t have is the one that gets discovered for you.
Not eventually — on a schedule someone else set. Here is who asks, what they ask, and the five things you need to be able to answer.
“What's our AI policy?”
Usually followed, one meeting later, by “and how do we know it's working?” The second question is the hard one.
“How are you handling AI?”
Increasingly a line item in grant applications and renewal packets. A live trust page answers it without a scramble.
“Complete this AI questionnaire.”
Security reviews now carry AI sections. The answers come straight out of your inventory and crosswalk.
“Show your assessment.”
State and international AI rules are arriving on a schedule. Where they apply, they ask for records you either have or don't.
Every tool, who owns it, and what data goes into it. Most organizations cannot answer this on the day they're asked.
A written policy and a practical standard, both short enough that staff will actually read them.
A named owner per risk, a sense of how likely and how bad, and a date you'll look again.
Training, then a dated signature per person. Unsigned staff are the gap auditors find first.
Dated records, a report each quarter, and a page you can send to anyone who asks. This is the part a template can't do.
Most of these rules are new, and plenty may not apply to you. We'll tell you which ones do.
It doesn't. It gives you a defensible starting point and the records to back it up. You review and approve everything.
The first package takes about an hour. Running the program is a rhythm, not an event, and that's the point.
This is the short version. Read the full 2026 executive briefing — the deadlines, the numbers and every primary source, last verified by a human on July 29, 2026.
AI law stopped being one deadline in one state. GOVERNBOX cites specific statutes from 28 U.S. states, covers 6 of those state AI laws with dedicated frameworks and crosswalks, and reaches U.S. federal law, the EU, the UK, Switzerland and Norway, Canada, the standards bodies and 21 countries in total — as selectable frameworks, not as a blog post. Pick the ones you operate under and every policy, crosswalk and gap report is generated and checked against exactly those.
6 of those laws go further, with their own controls and their own crosswalk report. New states are added as they pass.
National AI law and guidance, plus the EU as a bloc and the international instruments.
Selectable per organization — your documents are generated and checked against the ones you pick.
Expert-written, versioned, and cited by ID in every clause we generate. Nothing is invented.
The library cites specific statutes from 28 states. 6 of those laws, across 5 states, go further and have their own framework, controls and crosswalk report. The rest are reached through the U.S. state law landscape framework, which tracks disclosure, chatbot, biometric, deepfake, health, insurance and employment-AI statutes as they pass — so a new law does not mean a new setting for you.
Includes California's ADMT regulations. The CCPA privacy statute is a separate framework, available on Pro. All 51 jurisdictions shown are reachable through the U.S. state law landscape framework; 28 have their own statutes cited in it, and 5 go further with dedicated controls and a coverage report of their own. This map describes what GOVERNBOX covers — it is not a survey of which states have passed AI legislation, and it is not legal advice.
Colorado ADMT Act (SB 26-189) · Colorado Chatbot Safety (HB 26-1263) · Connecticut SB 5 (PA 26-15) · Texas TRAIGA · California ADMT Regulations · Hawaii AI Acts (247 / 248)
Federal legislation, executive orders and agency regulation, plus a cross-state view of AI disclosure and training-data laws. Per-state statutes are the U.S. State AI Laws jurisdiction above.
PIPEDA and provincial privacy law, the Directive on Automated Decision-Making, and the Canadian Human Rights Act as they apply to AI.
NIST profiles, ISO/IEC standards, IEEE, OECD and the healthcare AI reporting/assurance frameworks (FDA, WHO, CHAI, CONSORT-AI…).
EU regulation beyond the AI Act itself (GPAI code of practice, guidance), plus the UK, Swiss and Norwegian frameworks. The EU AI Act and GDPR remain separate frameworks.
Sixteen further countries' AI laws and guidance plus the international instruments (Council of Europe, OECD, UNESCO, UN).
The EU AI Act, GDPR, HIPAA, CCPA, NIST AI RMF and ISO/IEC 42001 and 42005 are chosen individually alongside these. See coverage by plan for exactly what each plan can select. GOVERNBOX gives you a defensible starting point that you review and approve — it is not legal advice.
Two short films
Both are interactive — click through the real product at your own pace. No form, no card, no call.
The whole program in one automated walkthrough — the AI Readiness Scorecard, AI inventory, risk register, grounded policies with human review, staff training, a board-ready report, and a live trust page.
A closer look at the AI Governance module in action — inventory the tools, generate a cited policy, review and approve it, and land it in a board-ready report.
Click through the real product, module by module. No form for the first two.
The trial is the proof, not the pitch
The trial hands you every module at once — the whole platform, one login, one shared graph.
Not an AI-only teaser. AI Governance, Risk, IT, and Data all unlock on day one.
Nothing auto-charges and nothing auto-selects. Starter, Pro, Agency — one core module or all four. You choose.
Not an intro rate. The discount applies at signup and at every renewal, on every tier, and on every module configuration you choose.
Nine in ten nonprofits report using AI somewhere in their operations. Fewer than half have a policy for it. You’re the ones being asked the questions with the least budget to answer them — so the price reflects that. The nonprofit rate is public: just choose it at checkout.
Fifteen days · about an hour of work
No consultant. No sales call. No specialist team. No credit card — and everything you build in those fifteen days stays yours, whichever plan you pick afterward.
Start my 15-day free trial →Not ready to start? Take the free readiness scorecard — no trial started.
Two decades directing large-scale technology portfolios, enterprise risk management and applied machine learning — which is why the control library is authored and versioned the way it is, rather than assembled from templates.
Gradient Descent LLC is an independent company. GOVERNBOX.ai is not affiliated with, endorsed by, or produced on behalf of any government agency.
Each plan keeps everything below it and adds the frameworks listed. Free previews NIST AI RMF only. Every framework here is backed by controls in the library and verified on one of the crosswalk shelves (Frameworks / United States / European Union & Europe / Canada / Global).
Jurisdictions (U.S. State Laws, U.S. National, Canada, AI Standards, Europe, Global) are each enabled as one unit on the Organization Profile; the standalone frameworks are chosen individually. New state laws are added as they pass. Not legal advice.
Transparent pricing
Start with the free Scorecard, then take the 15-day free trial — no credit card, nothing to cancel. On day 15 your workspace stays exactly as you left it until you pick a plan.
Prices below are for the AI Governance module — the first of four GOVERNBOX modules. See modular pricing →
NONPROFIT20 at checkout⚡ Not ready to pick a plan?
Test drive GOVERNBOX free for 15 days — no credit card needed.
Start 15-Day Free Trial →✓ Instant access · 15 days free · Zero credit card required
✓ Instant access · 15 days free · Zero credit card required
✓ Instant access · 15 days free · Zero credit card required
✓ Instant access · 15 days free · Zero credit card required