

Not next year. Today, in tools nobody approved, on work nobody reviewed. Governing AI means knowing what’s in use, deciding what’s allowed, and being able to show both. That’s it.
This page explains what the job actually is, in plain words, before you spend a dollar on it.
Take the free scorecard →Strip away the frameworks and the acronyms and this is the whole job. If you can answer these five in writing, you are governing AI.
Every tool, who owns it, and what data goes into it. Most organizations cannot answer this on the day they're asked.
A written policy and a practical standard, both short enough that staff will actually read them.
A named owner per risk, a sense of how likely and how bad, and a date you'll look again.
Training, then a dated signature per person. Unsigned staff are the gap auditors find first.
Dated records, a report each quarter, and a page you can send to anyone who asks. This is the part a template can't do.
“What's our AI policy?”
Usually followed, one meeting later, by “and how do we know it's working?” The second question is the hard one.
“How are you handling AI?”
Increasingly a line item in grant applications and renewal packets. A live trust page answers it without a scramble.
“Complete this AI questionnaire.”
Security reviews now carry AI sections. The answers come straight out of your inventory and crosswalk.
“Show your assessment.”
State and international AI rules are arriving on a schedule. Where they apply, they ask for records you either have or don't.
AI law stopped being one deadline in one state. GOVERNBOX cites specific statutes from 28 U.S. states, covers 6 of those state AI laws with dedicated frameworks and crosswalks, and reaches U.S. federal law, the EU, the UK, Switzerland and Norway, Canada, the standards bodies and 21 countries in total — as selectable frameworks, not as a blog post. Pick the ones you operate under and every policy, crosswalk and gap report is generated and checked against exactly those.
6 of those laws go further, with their own controls and their own crosswalk report. New states are added as they pass.
National AI law and guidance, plus the EU as a bloc and the international instruments.
Selectable per organization — your documents are generated and checked against the ones you pick.
Expert-written, versioned, and cited by ID in every clause we generate. Nothing is invented.
The library cites specific statutes from 28 states. 6 of those laws, across 5 states, go further and have their own framework, controls and crosswalk report. The rest are reached through the U.S. state law landscape framework, which tracks disclosure, chatbot, biometric, deepfake, health, insurance and employment-AI statutes as they pass — so a new law does not mean a new setting for you.
Includes California's ADMT regulations. The CCPA privacy statute is a separate framework, available on Pro. All 51 jurisdictions shown are reachable through the U.S. state law landscape framework; 28 have their own statutes cited in it, and 5 go further with dedicated controls and a coverage report of their own. This map describes what GOVERNBOX covers — it is not a survey of which states have passed AI legislation, and it is not legal advice.
Colorado ADMT Act (SB 26-189) · Colorado Chatbot Safety (HB 26-1263) · Connecticut SB 5 (PA 26-15) · Texas TRAIGA · California ADMT Regulations · Hawaii AI Acts (247 / 248)
Federal legislation, executive orders and agency regulation, plus a cross-state view of AI disclosure and training-data laws. Per-state statutes are the U.S. State AI Laws jurisdiction above.
PIPEDA and provincial privacy law, the Directive on Automated Decision-Making, and the Canadian Human Rights Act as they apply to AI.
NIST profiles, ISO/IEC standards, IEEE, OECD and the healthcare AI reporting/assurance frameworks (FDA, WHO, CHAI, CONSORT-AI…).
EU regulation beyond the AI Act itself (GPAI code of practice, guidance), plus the UK, Swiss and Norwegian frameworks. The EU AI Act and GDPR remain separate frameworks.
Sixteen further countries' AI laws and guidance plus the international instruments (Council of Europe, OECD, UNESCO, UN).
The EU AI Act, GDPR, HIPAA, CCPA, NIST AI RMF and ISO/IEC 42001 and 42005 are chosen individually alongside these. See coverage by plan for exactly what each plan can select. GOVERNBOX gives you a defensible starting point that you review and approve — it is not legal advice.
That you're already breaking the law
Most of these rules are new, and plenty may not apply to you. We'll tell you which ones do.
That software makes you compliant
It doesn't. It gives you a defensible starting point and the records to back it up. You review and approve everything.
That it's finished in one afternoon
The first package takes about an hour. Running the program is a rhythm, not an event, and that's the point.
The one-page version — designed to forward to a board, an executive team, or a funder.
Any working email — we’ll send the briefing there. Temporary/disposable addresses aren’t accepted. No spam — unsubscribe anytime.
We link the law itself, not an article about the law. Every URL below was checked by a human on July 29, 2026.
Educational briefing, not legal advice. Laws change; check your obligations with counsel. Last verified: July 29, 2026.
Ten minutes, free, and you’ll know exactly which of them you can’t answer yet.
Take the free scorecard →