Skip to content
complianceofficer

AI governance tool, platform and software that tracks every AI rule that moved

An AI governance tool is the system of record for every AI system you build, buy or inherit: the inventory, the risk classification, the assessment evidence, and the mapping from each system to the rules that apply to it. The reason this became a product category rather than a spreadsheet is that the rules stopped holding still. Every significant AI compliance deadline scheduled for 2026 moved during the last twelve months, and they moved in different directions.

That is the specific problem Complianceofficer is built for. We are not a model evaluation suite and we do not test your models for bias. We watch the regulations, tell you the day one changes, and show you which of your AI systems, policies and controls the change touches. Below is the current state of every US and EU AI rule a compliance team is tracking, read from the bills, the orders and the court docket rather than from a vendor summary.

Last updated September 2026. Every date and bill number in the table below was checked on 1 September 2026. Vendor pricing pages were opened the same day.

Scan which AI rules already apply to you

Pick your industry and size, then choose the regimes you operate under. The scan returns the obligations that apply to an organization like yours, what moved in the last 12 months, and the primary source behind each line. No signup, nothing stored.

§ Live · Compliance scan

No signup. Nothing you pick is stored.

Frameworks you answer to

Sample register · fintech, US · what a scan returns

  • § 01 Written AML program with a named officer
  • § 02 KYC and customer due diligence
  • § 03 Sanctions screening lists Changed
  • § 04 PCI DSS v4.0 validation
§ 156 What moved

Every 2026 AI deadline moved, and not all of them moved later

This is the case for buying a tool in this category, and it is worth stating precisely rather than gesturing at. If your AI compliance plan was written in 2025, it is now wrong about Colorado, wrong about the EU high-risk date, and wrong about California's watermarking start. It is still right about Texas. A static checklist cannot tell you which of those four it got wrong, which is the entire argument for treating AI rules as a monitored feed rather than a document.

Status of major US and EU AI compliance deadlines, verified 1 September 2026
Rule Originally effective Where it stands now What changed it
Colorado AI Act, SB 24-205 1 February 2026 Never took effect. Replaced by SB 189, effective 1 January 2027, and far narrower Delayed to 30 June 2026 by SB 25B-004; enforcement blocked 27 April 2026 in xAI v. Colorado, No. 1:26-cv-00933, before Magistrate Judge Cyrus Y. Chung; SB 189 signed 14 May 2026
EU AI Act, Annex III high-risk systems 2 August 2026 Deferred to 2 December 2027, with no further conditions attached Digital Omnibus, in force 27 July 2026
EU AI Act, Annex I high-risk in regulated products 2 August 2027 Deferred to 2 August 2028 Digital Omnibus
EU AI Act, Article 50 transparency and Article 4 AI literacy 2 August 2026 and 2 February 2025 Unchanged. These did apply on schedule Expressly left in place by the Digital Omnibus
Texas TRAIGA, HB 149 1 January 2026 In force, unchanged Nothing
California AI Transparency Act, SB 942 1 January 2026 Pushed to 2 August 2026, now in force Amended by AB 853
California AB 2013, training data transparency 1 January 2026 In force, unchanged Nothing
California SB 53, Transparency in Frontier AI Act 1 January 2026 In force. Applies to frontier developers above a compute threshold and a $500 million revenue floor, with penalties up to $1 million per violation Nothing
Federal preemption push Not applicable Live. A DOJ AI Litigation Task Force has been challenging state AI laws in federal court since 10 January 2026 Executive order "Ensuring a National Policy Framework for Artificial Intelligence", signed 11 December 2025

Read that table as a buyer and one thing stands out. The federal government is now actively litigating against state AI laws, and the first state to write a comprehensive one repealed and replaced it under that pressure before it ever applied. Whatever you build has to survive obligations appearing and disappearing on a timescale of weeks. That is a monitoring problem before it is a documentation problem, which is why we treat it as an extension of regulatory change management rather than a separate discipline.

§ 157 The job

What an AI governance tool has to do, in the order it matters

Demos in this market usually open with model evaluation dashboards, because they look impressive. In real programs the work stacks in a different order, and teams that start at the top of the stack instead of the bottom end up governing three models while forty AI features run unreviewed inside tools someone else bought.

  1. 1. Discovery and inventory

    Find the AI you are already running. Most of it was not built by your data science team, it was switched on by a vendor in a product you already licensed. An inventory that only lists in-house models is missing the majority of the estate and all of the surprises.

  2. 2. Classification

    Sort systems by what they decide and who they affect. Every live US disclosure rule turns on whether a system contributes to a consequential decision about a person and whether a human meaningfully reviews the output. Get that field right and most obligations resolve themselves.

  3. 3. Assessment and approval

    A recorded decision, before go-live, with a named approver. This is the artifact a regulator or a customer asks for, and the one most programs cannot produce for systems that shipped before the policy existed.

  4. 4. Obligation mapping

    Connect each system to the rules and framework controls it has to satisfy. Do this against one framework spine rather than one list per law, or you will rewrite the whole map every time a legislature moves.

  5. 5. Monitoring the rules

    The part that decays fastest and the part almost no AI governance platform started with. Four of the nine rows in the table above changed status inside twelve months. A map built once is wrong within a quarter.

  6. 6. Model performance and evaluation

    Bias testing, drift, red teaming. Genuinely important, genuinely specialist, and genuinely not where a compliance function should start. This is the layer we do not build, and you should expect a dedicated tool for it.

§ 158 Frameworks

NIST AI RMF, ISO/IEC 42001 and the EU AI Act are not alternatives

They get presented as a choice and they are not one. Two are voluntary frameworks that give you a vocabulary and a control set. One is a law. You pick a framework as the spine of your program and you comply with the law whether you picked a framework or not.

Comparison of NIST AI RMF, ISO/IEC 42001 and the EU AI Act
NIST AI RMF 1.0 ISO/IEC 42001 EU AI Act
What it is Voluntary risk management framework Certifiable management system standard Binding law with penalties
Structure Four functions, Govern, Map, Measure and Manage, with subcategories beneath Clauses 4 to 10 plus an Annex A control set of AI-specific controls Risk tiers, from prohibited through high-risk to transparency-only
Can you be certified No. You can claim alignment Yes, by an accredited body Conformity assessment, for high-risk systems only
Cost to adopt the text Free from NIST Purchased from ISO, plus audit fees Free, it is published law
Pick it when You need an internal program and a shared vocabulary quickly A customer, tender or partner wants a certificate You place AI on the EU market or affect people in the EU. Not optional

The practical route most US teams take: run NIST AI RMF internally because it is free and immediately usable, and certify to ISO/IEC 42001 only when procurement starts asking. The two overlap heavily. The NIST Govern function and clauses 4 through 10 of 42001 cover the same ground in different words, so the second framework costs far less than the first once the first is real. The same logic applies to security frameworks, which is worked through on ISO 27001 compliance software.

§ 159 The market

The vendor landscape, and where we honestly sit in it

AI governance became a named analyst category on 16 June 2026, when Gartner published its first Magic Quadrant for AI Governance Platforms covering thirteen vendors and naming IBM, ServiceNow and Truyo as Leaders, with OneTrust among the Visionaries. A market that young means the roundups you find are mostly reprinted press releases, and it means the products behind a single search term solve genuinely different problems.

Types of AI governance platform and the problem each one solves
Type Examples Best when your problem is
Model lifecycle governance IBM watsonx.governance, Credo AI, Monitaur, Holistic AI You build models in house and need evaluation, drift and documented lineage
Privacy suites with an AI module OneTrust, Truyo You already run a privacy program and want AI records in the same system
Enterprise workflow platforms ServiceNow Approvals and intake already live there and you want one queue
Security compliance suites adding AI Vanta, Drata You want an ISO 42001 audit path next to your existing SOC 2 work
Regulatory change monitoring Complianceofficer You cannot keep up with which AI rules moved and what they touch

We are the last row and we are not pretending to be the first. If you need to prove a credit model is not discriminating, buy a model governance platform. What we do is keep the register of rules underneath all of it correct, so the assessments those platforms hold are mapped to obligations that still exist. Several teams run both, and that is the arrangement we would recommend. The broader category shortlist lives on best compliance software, and the distinction between governing AI and using AI to run compliance is drawn on AI compliance software.

§ 160 The number

What AI governance software costs, and why quotes are not comparable

On 1 September 2026 we opened the public pricing pages of the main platforms in this category. Credo AI and Holistic AI returned no pricing page at all. Vanta's AI governance product was still waitlist only, with no figure attached. The two vendors that do state something state a metering basis rather than a price, and the two bases are not the same unit, which is the mechanical reason two AI governance quotes cannot be compared side by side.

AI governance platform pricing disclosure, checked 1 September 2026
Vendor Dollar figure published Stated metering basis
IBM watsonx.governance Partly. A metered rate on the Essentials SaaS plan Resource units consumed, not seats
OneTrust AI Governance No Admin users plus AI inventory, stated on its own pricing page
Credo AI No. No pricing page resolved Not stated. Enterprise subscription, demo first
Holistic AI No. No pricing page resolved Not stated
Vanta AI governance No Not stated. Waitlist, pre-release at the time of checking

Compare those units for a moment. A consumption meter grows with how hard you use the platform. A count of AI systems in your inventory grows with how honest your discovery was, which means doing the first job well raises the price of the second. That perverse incentive is worth naming out loud in a negotiation, and it is worth asking every vendor to put its counting rule in the contract. The same trap in the privacy market is documented on privacy compliance software pricing for multi-entity groups, and the full breakdown for this category is on AI governance software pricing.

§ 161 Who buys it

Who is actually buying an AI governance tool right now

The budget for this is rarely in a data science team. In the deals we see it sits with whoever has to answer a written question from outside the company.

  • Compliance and legal at regulated firms. The trigger is usually a customer questionnaire or an examiner asking for the AI inventory, and discovering nobody owns one.
  • Banks and insurers with existing model risk programs. They already govern models under SR 11-7 and need somewhere to put the AI that SR 11-7 was never written for, such as vendor features in HR and marketing systems. See bank compliance software.
  • Companies selling software to enterprises. Procurement started asking about ISO/IEC 42001 in 2026 the way it started asking about SOC 2 a decade ago, and a deal is stalled.
  • Healthcare and life sciences. Clinical and diagnostic AI carries device and validation duties on top of everything above. That path runs through 21 CFR Part 11 compliant software.
  • Anyone with EU exposure. Article 50 transparency and the Article 4 literacy duty already apply, whatever happened to the high-risk timetable.
§ 162 Questions buyers ask

Questions buyers ask about AI governance software

What is an AI governance platform?

An AI governance platform is the system of record for every AI system an organization builds, buys or embeds. It holds the inventory, a risk classification for each system, the evidence that each one was assessed before it went live, and the mapping from those systems to the rules and frameworks that apply. The useful ones also watch the rules, because AI law is changing faster than any other area of US compliance.

What is AI governance?

AI governance is the set of policies, roles, assessments and records that let an organization say which AI systems it runs, who approved each one, what risks were considered, and what happens when something goes wrong. It is distinct from using AI to do compliance work. Governance is about controlling your own models and your vendors' AI features, not about automating control testing.

How to implement AI governance

Start with discovery, not policy. Build the inventory of AI systems you actually run, including the AI features your existing SaaS vendors switched on, then classify each by the decisions it influences. Only then write the policy, because a policy drafted against an imaginary estate is unenforceable. Pick one framework as the spine and map obligations to it rather than maintaining a list per law.

Is the Colorado AI Act still in effect?

No, and it never was. SB 24-205 moved from 1 February 2026 to 30 June 2026, a federal magistrate judge blocked enforcement on 27 April 2026 in xAI v. Colorado, and Governor Polis signed SB 189 on 14 May 2026 replacing it with a narrower disclosure regime effective 1 January 2027. The duty of care, the impact assessments and the attorney general reporting were all removed. Notice at the point of interaction and a plain-language explanation after an adverse outcome survive.

Did the EU AI Act high-risk deadline of August 2, 2026 change?

Yes. The Digital Omnibus entered into force on 27 July 2026 and deferred the high-risk obligations for stand-alone Annex III systems to 2 December 2027, and for AI embedded in regulated products under Annex I to 2 August 2028. Neither new date is conditional on further Commission decisions. The Article 50 transparency duties and the Article 4 AI literacy duty were not moved.

Do I need ISO 42001 or NIST AI RMF?

Use NIST AI RMF if you need a risk vocabulary and an internal program, and ISO/IEC 42001 if a customer or a tender wants a certificate. NIST is voluntary and free. ISO/IEC 42001 is a certifiable management system standard with an Annex A control set and audit fees attached. Most US teams run NIST internally and certify to 42001 only when procurement asks, because the second costs far less once the first is real.

How much does AI governance software cost?

Almost nobody publishes a rate. Checked on 1 September 2026, Credo AI and Holistic AI had no working pricing page, and Vanta AI governance was waitlist only. IBM watsonx.governance meters its Essentials SaaS plan by resource unit rather than by seat. OneTrust states that AI Governance is priced on admin users plus AI inventory. Third-party listings put enterprise platforms in the tens of thousands of dollars a year, and implementation is charged separately.

What should be in an AI system inventory?

Each entry needs an owner, a plain description of what the system decides or produces, the population it affects, the data it consumes, whether a human reviews its output before it takes effect, the vendor if it is bought, and the date it was last assessed. The field people skip is the human review question, and it is the one nearly every current US disclosure rule turns on.

What is the best AI governance software?

Gartner published its first Magic Quadrant for AI Governance Platforms on 16 June 2026, covering thirteen vendors and naming IBM, ServiceNow and Truyo as Leaders, with OneTrust among the Visionaries. That is the closest thing to a neutral shortlist in a market this young. The right answer still depends on whether your problem is model risk, vendor AI features, or keeping up with the law.

Does AI governance software work for financial services?

It has to sit alongside model risk management, not replace it. US banks already govern models under SR 11-7, which predates this category by more than a decade and carries examiner expectations no AI tool inherits. In practice a bank maps the AI inventory to its existing model inventory and uses the AI platform for what SR 11-7 was never written for, such as vendor AI features embedded in HR and marketing tools.

Will federal preemption make state AI laws go away?

Not on its own. Preemption normally flows from an act of Congress rather than an executive order, so the December 2025 order works mainly by directing agencies and by funding litigation through the DOJ AI Litigation Task Force. The order also expressly carves out state laws on child safety, AI compute and data center infrastructure, and state government procurement of AI. Plan for a contested landscape, not a clean slate.

§ 99 · Final entry

Get on the early-access list

Leave your work email, confirm the 6-digit code, and we will email you when your spot opens. Nothing is charged before launch.

§ 90

Related registers