🏛️ Built for federal, state & local agencies

AI governance for the public sector, from people who’ve done it.

OMB M-25-21/22 compliance plans, NIST AI RMF crosswalks, an AI use-case inventory, and board-ready reporting — built on the same frameworks used in real federal AI governance work, and written in plain language for the people accountable for it.

Built by public-sector practitioners

Jim Tunnessen — Founder, Gradient Descent LLC

A 2x Federal CIO, CTO, and Chief AI Officer with hands-on experience implementing NIST SP 800-53 and AI governance frameworks across federal agencies. The frameworks baked into this platform are the same ones used in real federal AI governance work — not adapted from generic corporate templates. If your agency needs a hand, the advisory session is a 1:1 with someone who has actually stood these programs up.

The questions your public answers to

Governance tuned for public accountability

Agencies aren’t just managing risk — they’re accountable to the public, to oversight bodies, and to the people they serve. The platform is organized around those obligations.

🤝

Public trust

The dominant question for any agency: can we use AI while preserving public trust? Every default here is tuned for accountability, not just adoption.

🔍

Transparency & records

Disclosure of AI use, decision logging, and an append-only audit log — the documentation a FOIA/records request or an IG review will ask for.

⚖️

Fairness & civil rights

Bias, disparate-impact, and fundamental-rights considerations are first-class in the impact assessment — the lens the public and oversight bodies expect.

📋

Procurement integrity

A vendor AI risk assessment and a named owner per tool, so AI acquired through procurement is documented, reviewed, and accountable.

💰

Stewardship of taxpayer funds

Track what every AI tool costs — monthly and annual, rolled up by program office — so AI spend is defensible line by line, with 60-day renewal alerts.

🛡️

Accountability & oversight

A quarterly leadership report and a governance maturity score give your CIO, CAIO, and oversight bodies one authoritative view of the AI program.

What you can produce

The deliverables your agency actually needs

Every output is a grounded draft for your review — never auto-published, never “compliance advice.” The OMB AI Compliance Plan is available on the Agency plan; the rest span the paid tiers (see the comparison below).

🏛️

OMB M-25-21 / M-25-22 compliance plan

Generate an agency AI compliance plan grounded in the OMB memoranda on federal AI use and acquisition — the plan your agency actually has to produce.

🔗

NIST AI RMF crosswalk

Map your controls line-by-line to NIST AI RMF (and ISO 42001 / the Colorado AI Act), with control-level traceability showing exactly what each requirement satisfies.

👤

Chief AI Officer position description

A ready CAIO position description to stand up the role OMB expects, tailored to your agency's context.

🗂️

AI use-case inventory

The complete inventory OMB expects — every AI use with a named owner, data sensitivity, and risk classification, including the shadow AI staff adopted on their own.

⚠️

Risk register + impact assessments

Score every AI use by likelihood and impact, and run a rights-and-fairness impact assessment that auto-populates your risk register.

📊

Leadership & board reporting

A quarterly report — inventory, risks, incidents, training, cost, and a 0-100 maturity score — that answers oversight questions without you translating the data.

Transparent pricing

Simple, Honest Pricing

Start free. Upgrade when you’re ready to generate and export. Cancel anytime.

Prices below are for the AI Governance module — the first of four GOVERNBOX modules. See modular pricing →

💙 Verified nonprofits save 20% on Starter & Pro annual🚀 Founder pricing — first 10 companies — launch rates, locked
Free
$0/forever
No credit card needed
  • AI Readiness Scorecard
  • Gap report preview
  • NIST AI RMF preview
  • Preview AI Use Policy
  • Dashboard overview
Or try everything
15-Day Free Trial

Credit card required · $0 today · converts to Starter ($3,500/yr — $291.66/mo equivalent) on day 15 unless canceled

  • AI Use Case Inventory
  • Training Module + Project Management
  • Risk Register, Impact Assessments, Incidents
  • AI Agents inventory
  • Quarterly Board Report
  • Regulatory horizon feed ("What's Changing")
  • Organization Profile + dashboard
  • Up to 2 records per module (2 projects, unlimited board tasks)
  • Preview all 10 policy generators (locked until paid)
Starter
$3,500/yr
or $339/mo billed monthly
  • Everything in Free
  • AI Use Policy + AI Acceptable Use Standard
  • NIST AI RMF + ISO 42001 + Colorado AI Act crosswalk
  • Risk Register + Impact Assessments
  • Incident log, Training plan, full Board Report
  • AI Cost Tracking & Roll-Up (per use case + program office)
  • AI Agents inventory (basic registration)
  • AI Project Management — up to 2 concurrent projects
  • Governance Badge + live public Trust Page
  • Employee Attestation Portal — unlimited signers
  • Regulatory horizon feed
  • Word + PDF export
  • 3 seats (up to 5)
Most popular
Pro
$12,000/yr
equates to $1,000 per month
  • Everything in Starter
  • + CCPA data-privacy framework
  • NIST SP 800-53 Rev. 5 / CSF 2.0 crosswalk
  • Risk heat map
  • Full Impact Assessments — auto-populates Risk Register
  • AI Project Management — up to 5 concurrent projects
  • AI Strategic Plan + CAIO Position Statement wizards
  • Privacy Policy (CCPA-grounded)
  • AI Incident Response Plan + Vendor AI Risk Assessment
  • Branded document exports
  • 5 seats (up to 10)
Agency
$25,000/yr
  • Everything in Pro
  • + EU AI Act framework (risk tiering, Art. 5 & Art. 73 reporting)
  • + HIPAA & GDPR data-privacy frameworks
  • White-label exports, branding & badge
  • OMB AI Compliance Plan (M-25-21/22)
  • AI Agents zero-trust checklist + scoring
  • AI Project Management — unlimited projects
  • Priority support
  • Enterprise SSO (SAML / OIDC)
  • Advisory session included
  • 10 seats (up to 20)

Full Plan Comparison

FeatureFreeStarterPro
Most Popular
Agency
Core Platform
AI Readiness Scorecard
AI Use Case Log (inventory + named owner per system)UnlimitedUnlimitedUnlimited
EU AI Act risk tier classification + Art. 5 prohibited-use screen
Dashboard — My Workspace
Notifications center (review countdowns, alerts)
Append-only audit log
Multi-tenant security + row-level isolation
Document Generation
AI Use PolicyPreview
AI Acceptable Use Standard
AI Incident Response Plan
Vendor AI Risk Assessment
AI Strategic Plan (wizard)
CAIO Position Statement (wizard)
AI Committee Charter (wizard)
Privacy Policy (consumer / data-subject rights)CCPA-groundedGDPR + CCPA
OMB AI Compliance Plan (M-25-21 / M-25-22)
Compliance Crosswalk exportNIST + ISO + ColoradoNIST + ISO + ColoradoNIST + ISO + Colorado + EU AI Act
Word (.docx) export
PDF export
Organization logo on document exports
White-label exports (no Gradient Descent branding)
Compliance Frameworks
NIST AI RMFPreview
ISO/IEC 42001
Colorado AI Act (HB 26-1263 / SB 26-189, eff. Jan 1, 2027)
EU AI Act
NIST SP 800-53 Rev. 5 / CSF 2.0
CCPA / CPRA (California consumer privacy)
GDPR (EU data protection)
HIPAA Security & Privacy Rules
OMB M-25-21 / M-25-22 (Federal AI)
Risk & Impact
Risk Register (CRUD + likelihood × impact scoring)
Risk heat map visualization
AI Impact Assessment (7-section questionnaire)
Auto-create risk entries from assessments
AI Project Management Module
AI project list & per-project boardUp to 2Up to 5Unlimited
7-phase AI development lifecycle checklist
45-item NIST/ISO/EU grounded task checklist
Kanban board (drag-drop, task detail, Edit mode)
Cross-links: Use Cases / Projects / Risk Register
Agentic AI Governance Module
AI Agents inventory — basic registration (identity, ownership, data access)
12-item zero-trust controls checklist (NIST SP 800-207)
Zero-trust score + low-score alerts
Agent registration wizard (3-step)
Agent metrics in Board Report governance block
Cross-links: Agents / Use Cases / Risk Register
Training, Incidents & Operations
Training plan + completion tracking
Acceptable-use acknowledgment sign-off
Incident log + severity codes
EU AI Act Art. 73 serious-incident flag
Reporting & Governance
Quarterly Board Report (full — maturity score + quarterly history)
AI Cost Tracking & Roll-Up (per use case + program office, 60-day renewal alerts, Board Report totals)
Board Report — AI Agents governance section
Governance maturity score + stars (dashboard/badge)Preview
Shareable governance badge✓ White-labeled
Live public Trust Page + embeddable live badge✓ White-labeled
Employee Attestation Portal (unlimited signers)
Regulatory horizon feed ("What's Changing")
Gap report with advisory CTAsPreview
Administration
Admin Console (full data inventory & controls)Owner + AdminOwner + AdminOwner + Admin
User roles (Owner / Admin / Editor / Viewer)
User invite & role management
Enterprise SSO (SAML / OIDC)
Data export (full org snapshot)
Retention policy + danger zone (Owner only)
Seats included13 (up to 5)5 (up to 10)10 (up to 20)
White-label client portal
Support & Advisory
Email support
Onboarding walkthrough
Priority support
Advisory session (1:1 with Jim)✓ Included

Common questions

Frequently asked questions

What is GOVERNBOX.ai, and who is it for?
GOVERNBOX.ai ("AI Governance in a Box") is a self-service platform that helps a nonprofit, association, public-sector body, or small-to-midsize business produce a defensible AI governance package — an AI use policy, an acceptable-use standard, a risk register, and compliance crosswalks to frameworks like NIST AI RMF, ISO/IEC 42001, the Colorado AI Act, the EU AI Act, HIPAA, GDPR, and CCPA — without hiring a consultant or buying an enterprise platform built for a dedicated AI risk team.
How is this different from hiring a compliance consultant, or buying an enterprise platform?
Enterprise AI governance platforms typically cost tens to hundreds of thousands of dollars a year and assume a dedicated risk team. Consultants are effective but expensive and slow to engage. GOVERNBOX.ai serves the underserved middle: a guided, affordable, sector-aware product for organizations that need a real, defensible program now — with the option to bring in expert consulting for anything that genuinely needs a human.
How long does it take to get a usable AI governance package?
Most organizations can complete the free Readiness Scorecard, sign up, complete their organization profile, and generate a first grounded, tailored policy document in well under an hour.
Do I need AI or compliance expertise to use this?
No. The product is built for the "accidental AI owner" — someone handed AI governance responsibility without specialist training. Every generated document uses plain language, not jargon, and is written for a board or funder audience, not data scientists.

See our full FAQ →

Stand up a defensible AI governance & management program.

Start free with the Readiness Scorecard, or talk to a former federal CIO/CAIO about your agency’s needs.