Colorado’s ADMT Act, the EU AI Act, GDPR, and CCPA each have their own triggers, deadlines, and requirements — and four other states, U.S. federal law, Canada, the rest of Europe and sixteen further countries have theirs. Nonprofits and small businesses rarely have the time to track them all — one governance program can cover every framework that actually applies to you.
🏔️ SB 26-189 & HB 26-1263
Two separate laws share that date. The ADMT Act (SB 26-189) covers automated decisions that affect hiring, lending, housing, or similar consequential outcomes — pre-use notice, human review, an explanation of adverse decisions, and three years of records. The Chatbot Safety Act (HB 26-1263) covers consumer-facing conversational AI and minors. There is no small-business carve-out — what matters is what your organization does with AI, not its size.
Until 12:00 AM Mountain Time, January 1, 2027 — when Colorado’s ADMT Act (SB 26-189) and HB 26-1263 take effect. California’s CCPA ADMT rules carry the same date.
🇪🇺 Regulation (EU) 2024/1689
Applies to any organization whose AI system’s output is used in the EU — not just EU-based companies. It classifies AI systems by risk (unacceptable, high, limited, minimal) and phases its obligations in over several years. The transparency duties for AI-generated content are taking effect now, while the timelines for high-risk systems have been extended — so the move that pays off is getting your program ready before those duties reach you.
Organizations must disclose when people are interacting with AI, and mark or label AI-generated and manipulated content — chatbots, synthetic media, and deepfakes.
The Act applies in stages over the next several years, scaling what's required to how much risk an AI system carries — from minimal to high.
The compliance timelines for high-risk AI systems have been extended, giving organizations more time to build and document their programs before those duties apply.
The EU AI Act applies to any organization whose AI output is used in the EU — not just EU-based companies. GOVERNBOX helps you get ready before its duties reach you.
Already in effect — not a future deadline
Applies to any organization processing personal data of people in the EU, regardless of where the organization itself is located. Lawful basis for processing, data subject rights, breach notification, and records of processing all apply continuously — enforcement has only intensified since 2018, with AI-driven automated decision-making drawing particular attention.
California’s consumer privacy law, expanded by the CPRA. Applies based on revenue or data-volume thresholds, or simply doing business involving California residents’ personal information. A new AI-driven program, CRM, or donor tool can push an organization over a threshold without anyone noticing until it’s time to check.
One program, every framework
No consultant, no enterprise platform — a guided program built for the accidental AI owner at a nonprofit, association, or small business, that maps to whichever of these frameworks actually apply to you.
AI use policy and acceptable-use standard tailored to your sector and selected frameworks — every clause traces to a cited control, not a generic template.
Dedicated compliance crosswalks for NIST AI RMF, ISO/IEC 42001 and 42005, every U.S. state AI law (Colorado's ADMT and Chatbot Safety Acts, Connecticut, Texas, California ADMT, Hawaii), the EU AI Act, GDPR and CCPA — plus jurisdiction reports for U.S. National (Starter), Canada and the AI-standards pack (Pro), and Europe and Global (Agency), shelved as Frameworks / United States / EU / Canada / Global. Each requirement is mapped to the specific policy clause (or gap) that addresses it.
A quarterly Board Report built around the five questions every board asks, plus a shareable governance badge that proves your program to funders and partners.
Track every AI system by likelihood × impact, with an incident log ready before any framework's reporting clock starts.
Common questions
Have a different question? See our full FAQ →
One AI governance program, mapped to every framework that applies to your organization.
Want the running list? See what’s changing across AI, privacy, and cybersecurity rules →
This page is general information, not legal advice. Consult your own counsel to confirm how these frameworks apply to your organization.
Transparent pricing
Start with the free Scorecard, then take the 15-day free trial — no credit card, nothing to cancel. On day 15 your workspace stays exactly as you left it until you pick a plan.
Prices below are for the AI Governance module — the first of four GOVERNBOX modules. See modular pricing →
NONPROFIT20 at checkout⚡ Not ready to pick a plan?
Test drive GOVERNBOX free for 15 days — no credit card needed.
Start 15-Day Free Trial →✓ Instant access · 15 days free · Zero credit card required
✓ Instant access · 15 days free · Zero credit card required
✓ Instant access · 15 days free · Zero credit card required
✓ Instant access · 15 days free · Zero credit card required
Agency includes one advisory session with the founder. Working sessions, half-day module training and a guided program launch can also be bought on their own, on any plan — see GOVERNBOX.ai Advisory Services →