AI governance tool, platform and software that tracks every AI rule that moved
An AI governance tool is the system of record for every AI system you build, buy or inherit: the inventory, the risk classification, the assessment evidence, and the mapping from each system to the rules that apply to it. The reason this became a product category rather than a spreadsheet is that the rules stopped holding still. Every significant AI compliance deadline scheduled for 2026 moved during the last twelve months, and they moved in different directions.
That is the specific problem Complianceofficer is built for. We are not a model evaluation suite and we do not test your models for bias. We watch the regulations, tell you the day one changes, and show you which of your AI systems, policies and controls the change touches. Below is the current state of every US and EU AI rule a compliance team is tracking, read from the bills, the orders and the court docket rather than from a vendor summary.
Last updated September 2026. Every date and bill number in the table below was checked on 1 September 2026. Vendor pricing pages were opened the same day.
Scan which AI rules already apply to you
Pick your industry and size, then choose the regimes you operate under. The scan returns the obligations that apply to an organization like yours, what moved in the last 12 months, and the primary source behind each line. No signup, nothing stored.
§ Live · Compliance scan
No signup. Nothing you pick is stored.
Sample register · fintech, US · what a scan returns
- § 01 Written AML program with a named officer
- § 02 KYC and customer due diligence
- § 03 Sanctions screening lists Changed
- § 04 PCI DSS v4.0 validation
Every 2026 AI deadline moved, and not all of them moved later
This is the case for buying a tool in this category, and it is worth stating precisely rather than gesturing at. If your AI compliance plan was written in 2025, it is now wrong about Colorado, wrong about the EU high-risk date, and wrong about California's watermarking start. It is still right about Texas. A static checklist cannot tell you which of those four it got wrong, which is the entire argument for treating AI rules as a monitored feed rather than a document.
| Rule | Originally effective | Where it stands now | What changed it |
|---|---|---|---|
| Colorado AI Act, SB 24-205 | 1 February 2026 | Never took effect. Replaced by SB 189, effective 1 January 2027, and far narrower | Delayed to 30 June 2026 by SB 25B-004; enforcement blocked 27 April 2026 in xAI v. Colorado, No. 1:26-cv-00933, before Magistrate Judge Cyrus Y. Chung; SB 189 signed 14 May 2026 |
| EU AI Act, Annex III high-risk systems | 2 August 2026 | Deferred to 2 December 2027, with no further conditions attached | Digital Omnibus, in force 27 July 2026 |
| EU AI Act, Annex I high-risk in regulated products | 2 August 2027 | Deferred to 2 August 2028 | Digital Omnibus |
| EU AI Act, Article 50 transparency and Article 4 AI literacy | 2 August 2026 and 2 February 2025 | Unchanged. These did apply on schedule | Expressly left in place by the Digital Omnibus |
| Texas TRAIGA, HB 149 | 1 January 2026 | In force, unchanged | Nothing |
| California AI Transparency Act, SB 942 | 1 January 2026 | Pushed to 2 August 2026, now in force | Amended by AB 853 |
| California AB 2013, training data transparency | 1 January 2026 | In force, unchanged | Nothing |
| California SB 53, Transparency in Frontier AI Act | 1 January 2026 | In force. Applies to frontier developers above a compute threshold and a $500 million revenue floor, with penalties up to $1 million per violation | Nothing |
| Federal preemption push | Not applicable | Live. A DOJ AI Litigation Task Force has been challenging state AI laws in federal court since 10 January 2026 | Executive order "Ensuring a National Policy Framework for Artificial Intelligence", signed 11 December 2025 |
Read that table as a buyer and one thing stands out. The federal government is now actively litigating against state AI laws, and the first state to write a comprehensive one repealed and replaced it under that pressure before it ever applied. Whatever you build has to survive obligations appearing and disappearing on a timescale of weeks. That is a monitoring problem before it is a documentation problem, which is why we treat it as an extension of regulatory change management rather than a separate discipline.
What an AI governance tool has to do, in the order it matters
Demos in this market usually open with model evaluation dashboards, because they look impressive. In real programs the work stacks in a different order, and teams that start at the top of the stack instead of the bottom end up governing three models while forty AI features run unreviewed inside tools someone else bought.
-
1. Discovery and inventory
Find the AI you are already running. Most of it was not built by your data science team, it was switched on by a vendor in a product you already licensed. An inventory that only lists in-house models is missing the majority of the estate and all of the surprises.
-
2. Classification
Sort systems by what they decide and who they affect. Every live US disclosure rule turns on whether a system contributes to a consequential decision about a person and whether a human meaningfully reviews the output. Get that field right and most obligations resolve themselves.
-
3. Assessment and approval
A recorded decision, before go-live, with a named approver. This is the artifact a regulator or a customer asks for, and the one most programs cannot produce for systems that shipped before the policy existed.
-
4. Obligation mapping
Connect each system to the rules and framework controls it has to satisfy. Do this against one framework spine rather than one list per law, or you will rewrite the whole map every time a legislature moves.
-
5. Monitoring the rules
The part that decays fastest and the part almost no AI governance platform started with. Four of the nine rows in the table above changed status inside twelve months. A map built once is wrong within a quarter.
-
6. Model performance and evaluation
Bias testing, drift, red teaming. Genuinely important, genuinely specialist, and genuinely not where a compliance function should start. This is the layer we do not build, and you should expect a dedicated tool for it.
NIST AI RMF, ISO/IEC 42001 and the EU AI Act are not alternatives
They get presented as a choice and they are not one. Two are voluntary frameworks that give you a vocabulary and a control set. One is a law. You pick a framework as the spine of your program and you comply with the law whether you picked a framework or not.
| NIST AI RMF 1.0 | ISO/IEC 42001 | EU AI Act | |
|---|---|---|---|
| What it is | Voluntary risk management framework | Certifiable management system standard | Binding law with penalties |
| Structure | Four functions, Govern, Map, Measure and Manage, with subcategories beneath | Clauses 4 to 10 plus an Annex A control set of AI-specific controls | Risk tiers, from prohibited through high-risk to transparency-only |
| Can you be certified | No. You can claim alignment | Yes, by an accredited body | Conformity assessment, for high-risk systems only |
| Cost to adopt the text | Free from NIST | Purchased from ISO, plus audit fees | Free, it is published law |
| Pick it when | You need an internal program and a shared vocabulary quickly | A customer, tender or partner wants a certificate | You place AI on the EU market or affect people in the EU. Not optional |
The practical route most US teams take: run NIST AI RMF internally because it is free and immediately usable, and certify to ISO/IEC 42001 only when procurement starts asking. The two overlap heavily. The NIST Govern function and clauses 4 through 10 of 42001 cover the same ground in different words, so the second framework costs far less than the first once the first is real. The same logic applies to security frameworks, which is worked through on ISO 27001 compliance software.
The vendor landscape, and where we honestly sit in it
AI governance became a named analyst category on 16 June 2026, when Gartner published its first Magic Quadrant for AI Governance Platforms covering thirteen vendors and naming IBM, ServiceNow and Truyo as Leaders, with OneTrust among the Visionaries. A market that young means the roundups you find are mostly reprinted press releases, and it means the products behind a single search term solve genuinely different problems.
| Type | Examples | Best when your problem is |
|---|---|---|
| Model lifecycle governance | IBM watsonx.governance, Credo AI, Monitaur, Holistic AI | You build models in house and need evaluation, drift and documented lineage |
| Privacy suites with an AI module | OneTrust, Truyo | You already run a privacy program and want AI records in the same system |
| Enterprise workflow platforms | ServiceNow | Approvals and intake already live there and you want one queue |
| Security compliance suites adding AI | Vanta, Drata | You want an ISO 42001 audit path next to your existing SOC 2 work |
| Regulatory change monitoring | Complianceofficer | You cannot keep up with which AI rules moved and what they touch |
We are the last row and we are not pretending to be the first. If you need to prove a credit model is not discriminating, buy a model governance platform. What we do is keep the register of rules underneath all of it correct, so the assessments those platforms hold are mapped to obligations that still exist. Several teams run both, and that is the arrangement we would recommend. The broader category shortlist lives on best compliance software, and the distinction between governing AI and using AI to run compliance is drawn on AI compliance software.
What AI governance software costs, and why quotes are not comparable
On 1 September 2026 we opened the public pricing pages of the main platforms in this category. Credo AI and Holistic AI returned no pricing page at all. Vanta's AI governance product was still waitlist only, with no figure attached. The two vendors that do state something state a metering basis rather than a price, and the two bases are not the same unit, which is the mechanical reason two AI governance quotes cannot be compared side by side.
| Vendor | Dollar figure published | Stated metering basis |
|---|---|---|
| IBM watsonx.governance | Partly. A metered rate on the Essentials SaaS plan | Resource units consumed, not seats |
| OneTrust AI Governance | No | Admin users plus AI inventory, stated on its own pricing page |
| Credo AI | No. No pricing page resolved | Not stated. Enterprise subscription, demo first |
| Holistic AI | No. No pricing page resolved | Not stated |
| Vanta AI governance | No | Not stated. Waitlist, pre-release at the time of checking |
Compare those units for a moment. A consumption meter grows with how hard you use the platform. A count of AI systems in your inventory grows with how honest your discovery was, which means doing the first job well raises the price of the second. That perverse incentive is worth naming out loud in a negotiation, and it is worth asking every vendor to put its counting rule in the contract. The same trap in the privacy market is documented on privacy compliance software pricing for multi-entity groups, and the full breakdown for this category is on AI governance software pricing.
Who is actually buying an AI governance tool right now
The budget for this is rarely in a data science team. In the deals we see it sits with whoever has to answer a written question from outside the company.
- Compliance and legal at regulated firms. The trigger is usually a customer questionnaire or an examiner asking for the AI inventory, and discovering nobody owns one.
- Banks and insurers with existing model risk programs. They already govern models under SR 11-7 and need somewhere to put the AI that SR 11-7 was never written for, such as vendor features in HR and marketing systems. See bank compliance software.
- Companies selling software to enterprises. Procurement started asking about ISO/IEC 42001 in 2026 the way it started asking about SOC 2 a decade ago, and a deal is stalled.
- Healthcare and life sciences. Clinical and diagnostic AI carries device and validation duties on top of everything above. That path runs through 21 CFR Part 11 compliant software.
- Anyone with EU exposure. Article 50 transparency and the Article 4 literacy duty already apply, whatever happened to the high-risk timetable.
Questions buyers ask about AI governance software
What is an AI governance platform?
An AI governance platform is the system of record for every AI system an organization builds, buys or embeds. It holds the inventory, a risk classification for each system, the evidence that each one was assessed before it went live, and the mapping from those systems to the rules and frameworks that apply. The useful ones also watch the rules, because AI law is changing faster than any other area of US compliance.
What is AI governance?
AI governance is the set of policies, roles, assessments and records that let an organization say which AI systems it runs, who approved each one, what risks were considered, and what happens when something goes wrong. It is distinct from using AI to do compliance work. Governance is about controlling your own models and your vendors' AI features, not about automating control testing.
How to implement AI governance
Start with discovery, not policy. Build the inventory of AI systems you actually run, including the AI features your existing SaaS vendors switched on, then classify each by the decisions it influences. Only then write the policy, because a policy drafted against an imaginary estate is unenforceable. Pick one framework as the spine and map obligations to it rather than maintaining a list per law.
Is the Colorado AI Act still in effect?
No, and it never was. SB 24-205 moved from 1 February 2026 to 30 June 2026, a federal magistrate judge blocked enforcement on 27 April 2026 in xAI v. Colorado, and Governor Polis signed SB 189 on 14 May 2026 replacing it with a narrower disclosure regime effective 1 January 2027. The duty of care, the impact assessments and the attorney general reporting were all removed. Notice at the point of interaction and a plain-language explanation after an adverse outcome survive.
Did the EU AI Act high-risk deadline of August 2, 2026 change?
Yes. The Digital Omnibus entered into force on 27 July 2026 and deferred the high-risk obligations for stand-alone Annex III systems to 2 December 2027, and for AI embedded in regulated products under Annex I to 2 August 2028. Neither new date is conditional on further Commission decisions. The Article 50 transparency duties and the Article 4 AI literacy duty were not moved.
Do I need ISO 42001 or NIST AI RMF?
Use NIST AI RMF if you need a risk vocabulary and an internal program, and ISO/IEC 42001 if a customer or a tender wants a certificate. NIST is voluntary and free. ISO/IEC 42001 is a certifiable management system standard with an Annex A control set and audit fees attached. Most US teams run NIST internally and certify to 42001 only when procurement asks, because the second costs far less once the first is real.
How much does AI governance software cost?
Almost nobody publishes a rate. Checked on 1 September 2026, Credo AI and Holistic AI had no working pricing page, and Vanta AI governance was waitlist only. IBM watsonx.governance meters its Essentials SaaS plan by resource unit rather than by seat. OneTrust states that AI Governance is priced on admin users plus AI inventory. Third-party listings put enterprise platforms in the tens of thousands of dollars a year, and implementation is charged separately.
What should be in an AI system inventory?
Each entry needs an owner, a plain description of what the system decides or produces, the population it affects, the data it consumes, whether a human reviews its output before it takes effect, the vendor if it is bought, and the date it was last assessed. The field people skip is the human review question, and it is the one nearly every current US disclosure rule turns on.
What is the best AI governance software?
Gartner published its first Magic Quadrant for AI Governance Platforms on 16 June 2026, covering thirteen vendors and naming IBM, ServiceNow and Truyo as Leaders, with OneTrust among the Visionaries. That is the closest thing to a neutral shortlist in a market this young. The right answer still depends on whether your problem is model risk, vendor AI features, or keeping up with the law.
Does AI governance software work for financial services?
It has to sit alongside model risk management, not replace it. US banks already govern models under SR 11-7, which predates this category by more than a decade and carries examiner expectations no AI tool inherits. In practice a bank maps the AI inventory to its existing model inventory and uses the AI platform for what SR 11-7 was never written for, such as vendor AI features embedded in HR and marketing tools.
Will federal preemption make state AI laws go away?
Not on its own. Preemption normally flows from an act of Congress rather than an executive order, so the December 2025 order works mainly by directing agencies and by funding litigation through the DOJ AI Litigation Task Force. The order also expressly carves out state laws on child safety, AI compute and data center infrastructure, and state government procurement of AI. Plan for a contested landscape, not a clean slate.
§ 99 · Final entry
Get on the early-access list
Leave your work email, confirm the 6-digit code, and we will email you when your spot opens. Nothing is charged before launch.
Related registers
- Continuous Compliance Monitoring
- Compliance Monitoring Software
- Compliance Software Cost
- Enterprise Compliance Software for CCOs and CISOs
- GRC Software and Governance Risk Compliance Software
- GDPR Compliance Software
- Compliance Automation Software
- AML Transaction Monitoring Plus Regulatory Watch
- SOC 2 Compliance Software Beyond Audit Readiness
- Policy Compliance Software and Policy Compliance Tracking
- Policy Attestation Software and Acknowledgement Tracking
- Regulatory Change Management Software, Tools and Platform
- HIPAA Compliance Software with Security Risk Analysis
- ISO 27001 Software for ISMS Compliance and Audit Evidence
- Vendor Risk Management Software for Third Party Risk
- PCI Compliance Software Tied to PCI DSS 4.0.1
- Audit Management Software for Continuous Readiness
- SOX Compliance
- Segregation of Duties Software
- Financial Services Compliance Software for RIAs and BDs
- 21 CFR Part 11 Compliant Software, GxP Compliance Software
- ITGC Controls Software for SOX IT General Controls Audits
- Compliance Reporting Software and Compliance Dashboards
- SOX Compliance Software for SOX 404 Controls
- Best Compliance Software in 2026, Compared
- CMMC Compliance Software for DoD Contractors
- Enterprise Risk Management Software
- Compliance Software Pricing Comparison
- Healthcare Compliance Software for OIG Compliance Programs
- Bank Compliance Software for Financial Institutions, BSA/AML
- AI Compliance Software
- AML Compliance Software with KYC and Sanctions Screening
- Regulatory Compliance Software with Compliance Tracking
- CCPA Compliance Software, Data Privacy Management Software
- Enterprise Risk Assessment Software, Risk Assessment Tools
- Business Continuity Plan Software, BCM and Disaster Recovery
- SOX 404(b) Compliance Software, Requirements and Threshold
- Integrated Risk Management Software, IRM Platform and Tools
- Vanta Alternative for Regulatory Change Monitoring
- Drata Alternative Focused on Regulatory Change
- Secureframe Alternative for Regulatory Change
- Sprinto Alternative for Regulatory Change
- AuditBoard Alternative (Now Optro) for Regulatory Change
- OneTrust Competitors
- Workiva Competitors and Alternatives