The situation. AI now writes your answers, scores your customers, and acts in your name. Every deployment is a decision made at machine speed, under your accountability.
The complication. Regulators, boards, and customers no longer accept intentions. The European Union Artificial Intelligence Act (Regulation (EU) 2024/1689) provides administrative fines of up to 35 million euros or 7 percent of worldwide annual turnover for prohibited practices, and an ungoverned system does not fail quietly. It fails in front of everyone.
The resolution. This is the operational layer of AI governance: working instruments, response frameworks, and recurring programs that let you govern what you deploy and prove it to the people who ask.
Router 1 of 2 : capacity and sector
Governance obligations are the same for everyone. Capacity to meet them is not. Pick the door that matches your organization: the depth, the sequence, and the price band adjust to you, not the other way around.
Micro and Small : 3 to 50 people : private sector
No dedicated governance role, no slack. You need the one-afternoon versions that hold up when a client or investor asks the hard question.
Your path: the Starter-level kits and the Governance Vault at the Micro and Small band. Right-sized, not watered down.
Enter the small-team door →Mid : 51 to 250 people : private sector
Your first dedicated risk or compliance hire is drowning. You need a repeatable operating system, not another policy PDF.
Your path: the seven pillar kits, the Done-With-You Sprints, and the Vault at the Mid band.
Enter the mid-size door →Large : 251 to 5,000 people : private sector
Multiple units, multiple AI systems, one reputation. Coordination is now the risk. You need cross-unit standards and evidence that travels upward.
Your path: the Flagship Packs, the Vault at the Large band, and the Pre-Scale Governance Audit.
Enter the large-organization door →Enterprise : 5,000+ people : private sector
Board scrutiny, regulators in multiple jurisdictions, federated teams. Governance here is an operating model, not a binder.
Your path: the Enterprise Governance Transformation Program and the Founder's Governance Partnership.
Enter the enterprise door →Any size : agencies, ministries, municipalities
Statutory duty, citizen trust, procurement rules, and transparency mandates. Your governance must survive an audit and a headline.
Your path: public-sector editions with procurement-ready language, the Audit-Ready Evidence Vault, and citizen-impact playbooks.
Enter the public-sector door →Router 2 of 2 : your seat
A board member and an engineer do not buy governance for the same reason. Each seat below opens with the job you are on the hook for, and routes you to the instrument built for it.
Your job: ask the questions that protect the organization, and prove oversight happened.
If AI fails publicly, the minutes will show what you asked. Or what you did not.
Start here: the Board and Executive Governance Pack, then the Intelligence Subscription.
Your job: scale AI without scaling unpriced risk.
Growth built on ungoverned AI is borrowed growth. The cost arrives later, with interest, in public.
Start here: the Govern-Before-You-Scale path and the Pre-Scale Governance Audit.
Your job: build the operating system, then prove it works every quarter.
You own the whole chain: inventory, controls, response, evidence. You need it as a system, not scattered documents.
Start here: the Governance Vault (all-access), then the Certified Practitioner Program.
Your job: survive the regulator's letter with documents, not explanations.
The European Union Artificial Intelligence Act and ISO/IEC 42001 do not ask how you feel about governance. They ask for evidence.
Start here: the EU AI Act Compliance Pack, the ISO/IEC 42001 Certification Toolkit, the Audit-Ready Evidence Vault.
Your job: ship the AI feature without shipping the incident.
Guardrails belong in the architecture, not in a slide. Especially for agentic systems that act on their own.
Start here: the AI Risk Management Kit, the Frontier and AGI Governance Kit, the Interactive Governance Tools.
Your job: govern the AI you buy, because most of your AI is bought, not built.
The vendor's model becomes your incident the day you sign. The contract is your first control.
Start here: the Third-Party AI Risk line and the procurement clause library.
The Flagship Packs exist for the moments when an intention is not enough: the regulator asks for documents, the certifier asks for evidence, the board asks for answers, and a live system asks for a response. Each pack begins where the free layer stops. Each pack costs a fraction of a single readiness engagement, and less than the first two days of senior consulting time.
The job: when an AI system fails in production, run a response your board and regulator will respect. The AI Governance Emergency Response Framework (AI-ERF)™ Implementation Pack is the working toolkit behind the framework: the fillable incident log system, the severity grading worksheet, the printable role cards, the drill and tabletop kit, and the board reporting templates.
Where the free layer stops: the free framework tells you what a response looks like. The pack is the response, ready to run.
The cost of waiting: the first hour of an AI incident decides the outcome, and an unprepared first hour destroys evidence, delays containment, and turns a contained event into a public one. Every case in our library where the response was improvised cost more than the response that was rehearsed.
From the case library: a hospital network with a rehearsed stop authority contained a failing triage model in nine minutes. An agency where everyone was the commander took two days.
The job: classify every AI system under the European Union Artificial Intelligence Act (Regulation (EU) 2024/1689), document the conformity work for high-risk systems, and meet the transparency obligations, with templates instead of guesswork. The pack covers the risk-tier classifier, the high-risk obligations checklist, the transparency notices, and the technical documentation dossier.
Where the free layer stops: the free Regulation-at-a-Glance Card tells you which tier you are in. The pack produces the evidence that tier demands.
The cost of waiting: the regulation provides administrative fines of up to 35 million euros or 7 percent of worldwide annual turnover for prohibited practices, and up to 15 million euros or 3 percent for other violations. The obligations phase in on published dates. Waiting does not pause the calendar.
From the case library: a small public agency completed its full classification in one afternoon with the tier logic in hand. The alternative quote from an external firm was measured in weeks.
The job: stand up a certifiable AI management system under ISO/IEC 42001, the first certifiable AI management system standard, published in December 2023, without drafting every policy from a blank page. The toolkit carries the policy pack, the control implementation guide, the internal audit kit, and the management review templates.
Where the free layer stops: the free Readiness Checklist scores where you stand. The toolkit closes the gaps the score exposes.
The cost of waiting: certification cycles run in quarters, and enterprise customers increasingly ask for the certificate in procurement. Every quarter without a working management system is a quarter your competitors can answer a tender question you cannot.
From the case library: a mid-size private firm cut its readiness work from months to weeks by starting from the toolkit instead of a blank page.
The Global Regulation-to-Action Atlas, Full Edition. Your job: answer any regulator on the map with evidence, not explanations. The Atlas delivers the obligation-by-obligation mapping of the European Union Artificial Intelligence Act, ISO/IEC 42001 clause by clause, the NIST AI Risk Management Framework, and the verified regimes of Latin America and Brazil, Africa, Asia-Pacific, and the Middle East, each row naming the instrument you deploy and the AI GOVERNANCE CHAIN™ evidence you file.
The cost of waiting: the regulatory map changes every quarter, and a document written for last quarter answers a regulator with last quarter's law. Every entry is verified with its legal status and date, and the quarterly Regulatory Update Service keeps the map alive.
4,400 USD, single-organization license. Request this Atlas
The United States Pack. Your job: operate across the American state patchwork with evidence, not guesswork. Six execution-grade instruments in one pack: the Algorithmic Impact Assessment Builder (Colorado SB 24-205), the Prohibited-Practices Register (Texas TRAIGA), the Biometric Consent Tracker (Illinois BIPA), the Annual Bias Audit Playbook (New York City Local Law 144), the AI Content Labeling Kit (California SB 942), and the AI Governance Crosswalk Matrix that maps them all onto one control library.
The cost of waiting: Colorado takes effect June 30, 2026, Texas has been in force since January 1, 2026, and the United States Senate voted 99 to 1 to preserve the state patchwork. Each statute carries its own penalties, and each is verified with its status and date.
4,900 USD, single-organization license. Instruments also sold individually (1,400 to 1,900 USD). Request the United States Pack
The job: give directors and executives the oversight instruments their duty requires: the board reporting templates, the executive briefing deck structure, the Chief Artificial Intelligence Officer operating model, and the questions a board should ask before approving any AI initiative.
Where the free layer stops: the free Board-Ready One-Pager starts the conversation. The pack runs the oversight cycle, quarter after quarter.
The cost of waiting: when an AI failure reaches the press, the second question is always what the board knew and when. A board with no oversight record has no good answer to that question.
Built by: a Member of the Harvard Business Review Advisory Council with decades of professional experience advising boards and executives, writing in the language directors actually use.
The job: audit your systems for the failure no other framework names: artificial intelligence that agrees with its users instead of telling them the truth. Built on the AI Sycophancy Risk Register™, the toolkit carries the full test battery, the scoring engine, the mitigation playbook, and the audit report template your leadership can read.
Where the free layer stops: the free register names the eight failure patterns. The toolkit measures them in your systems and documents what it finds.
The cost of waiting: a sycophantic system fails silently: it validates the plan, flatters the analysis, and confirms the error, until reality does not. By the time agreement becomes visible as a loss, the decision it corrupted has already been made.
From the case library: a micro team caught a flattering model before launch with the test battery. The fix cost an afternoon. The undetected version had already validated a flawed pricing decision.
Every pack: instant delivery after payment, a fourteen-day refund policy, and a single-organization license. Larger organization or public sector? Your door on this page sets your band and your path.
Each kit is the complete operating depth of one governance pillar: the working templates, the scoring instruments, and the decision structures, authored by the creator of the AI Governance Emergency Response Framework (AI-ERF)™. Your free instruments told you WHAT and WHY. These kits are the HOW. Each costs less than a single senior consultant day, and each is right-sized from a three-person team to a national ministry.
AI Ethics Operating Kit
The ethics review board charter, the ethical decision template, the ethics risk register, and the board reporting pack. Ethics as an operating system, not a poster.
The cost of waiting: an ethics failure becomes public the moment a customer, a journalist, or a regulator names it, and by then every decision you cannot document reads as a decision you hid.
Proof: a three-person team caught a sycophantic model before launch using this discipline, the cheapest incident is the one that never ships.
AI Risk Management Kit
The full risk register built on the thirty-risk taxonomy, the treatment planner, the risk appetite statement, the monitoring pack, and the board risk report.
The cost of waiting: the European Union Artificial Intelligence Act provides administrative fines up to 35 million euros or 7 percent of worldwide annual turnover for the most serious violations. An unmapped risk is an unpriced one.
Proof: a large private organization installed guardrails before scaling an autonomous workflow, because its register named the risk first.
AI Assurance and Audit Kit
The assurance evidence system, the self-assessment protocol, the independent review template, the audit-evidence pack, and the ISO/IEC 42001 certification-readiness map.
The cost of waiting: ISO/IEC 42001, the first certifiable AI management system standard, published December 2023, is becoming the proof buyers and regulators ask for, and certification takes quarters, not weeks.
Proof: a mid-size insurer discovered its governance was real but unprovable, one audit letter exposed the gap this kit closes.
AI Literacy and Culture Program Kit
The literacy curriculum by role, the four-level capability ladder, the culture change plan, and the training evidence log.
The cost of waiting: the European Union Artificial Intelligence Act requires organizations to ensure a sufficient level of AI literacy in their staff, an obligation that applies since February 2025. Untrained staff are now a compliance finding.
Proof: organizations that trained first turned the obligation into capability, the rest are documenting remediation.
AI and Human Rights Impact Kit
The human rights impact assessment, the rights-based screening protocol, the mitigation planner, and the public-accountability reporting pack.
The cost of waiting: a rights failure is the one category of AI incident that no communications strategy repairs, and public-sector procurement increasingly demands the assessment before the contract.
Proof: a public agency completed its rights screening before deployment and answered its oversight committee in one session.
Frontier and AGI Governance Kit
The six-risk frontier model, the guardrail architecture, the multi-agent oversight patterns, and the deployment readiness assessment, the thinnest-governed, fastest-moving risk class there is.
The cost of waiting: agentic systems compound errors at machine speed, the first hour of an autonomous failure can execute thousands of decisions no human reviewed.
Proof: a large public organization scaled agentic service automation safely because the guardrails were installed first, not retrofitted.
The Flagship Packs
Each flagship pack solves one expensive, named problem end to end. Every pack is built on the same disciplines regulators and boards already recognize: the European Union Artificial Intelligence Act (EU AI Act, Regulation (EU) 2024/1689), ISO/IEC 42001 (the first certifiable AI management system standard, published December 2023), and the NIST AI Risk Management Framework (AI RMF).
Price them against the real alternative: each pack costs a fraction of a single readiness engagement, and less than the first two days of senior consulting time below. These are fixed-price instruments, not open-ended engagements.
Flagship
The AI-ERF™ Implementation Pack. Your job: run a controlled response when an AI system misbehaves, with named roles, a severity decision, and evidence that survives the review. The pack turns the AI Governance Emergency Response Framework (AI-ERF)™ into working instruments: the incident log system, the severity grading worksheet, the role cards, the drill and tabletop kit, and the board reporting templates.
The cost of waiting: an ungoverned incident is contained by improvisation, and improvisation destroys the evidence you will need for the regulator, the board, and the insurer. Proof from the field: a hospital with a practiced first hour stopped in nine minutes; a retailer that fixed too fast lost the evidence and paid for it twice.
4,900 USD, single-organization license. Fits every tier: right-sized guidance from a three-person team to a national ministry.
The EU AI Act Compliance Pack. Your job: place every AI system into the correct risk tier, document the conclusion, and meet the obligations that follow. The pack delivers the risk-tier classifier, the high-risk obligations checklist, the transparency templates, the technical documentation dossier, and the conformity timeline.
The cost of waiting: the EU AI Act provides administrative fines of up to 35 million euros or 7 percent of worldwide annual turnover for prohibited-practice violations, and its obligations phase in on published dates. Proof from the field: a small public agency completed its classification in one afternoon with these instruments.
4,400 USD, single-organization license.
The ISO/IEC 42001 Certification Toolkit. Your job: build a certifiable AI management system without hiring a firm to write documents you could own. The toolkit delivers the policy pack, the control implementation guide, the internal audit kit, the management review template, and the continual improvement loop.
The cost of waiting: certification cycles run in quarters, and every quarter uncertified is a quarter your competitors can claim the proof you cannot. Proof from the field: a mid-size firm cut its readiness phase from months to weeks with a pre-built document base.
4,400 USD, single-organization license.
The Board and Executive Governance Pack. Your job: give directors and shareholders governance they can see, question, and defend. The pack delivers the board reporting templates, the Chief Artificial Intelligence Officer (CAIO) operating model, the executive briefing set, and the quarterly governance agenda.
The cost of waiting: a board that cannot evidence oversight of AI is a board exposed, and directors know it. Authored by a Member of the Harvard Business Review Advisory Council: this is the pack written in the language the boardroom already speaks.
4,400 USD, single-organization license.
The Sycophancy Audit Toolkit. Your job: prove your systems tell the truth under pressure, before a flattering model walks your organization into a decision it cannot defend. Built on the AI Sycophancy Risk Register™, the toolkit delivers the full test battery, the scoring engine, the mitigation playbook, and the audit report template.
The cost of waiting: sycophantic failure is invisible until the day it is public, because the system never disagrees with the person steering it. Proof from the field: a micro team caught a sycophantic model before launch with exactly this battery. This is the category AI GOVERNANCE CHAIN™ named and owns.
4,400 USD, single-organization license.
Every flagship pack is a direct purchase, deliberately priced below the conversation threshold. Anything above 5,000 USD begins with a conversation, not a cart: the Governance Vault enterprise band (from 12,000 USD per year), the Done-With-You Sprints (from 9,500 USD), the Pre-Scale Governance Audit (from 35,000 USD, scoped by conversation), and the Enterprise Governance Transformation Program (from 150,000 USD, scoped engagement). The Founder’s Governance Partnership is by conversation only. Prices rise as the standard matures: a published increase of ten to twenty percent every two quarters.
The guarantee: every pack is delivered immediately after payment, licensed to your organization, and covered by a clear refund policy. If a pack does not fit your tier, we point you to the one that does.
Not sure which pack is yours? Use the doors above: your organization size sets the depth and the price band, your seat sets the first product. Or start with the free diagnostic and let the result route you.
Artificial intelligence regulation moves quarterly and your systems change weekly, so governance bought once is governance that quietly expires. These programs keep your instruments, your evidence, and your people current, and they are the layer that cannot be pirated: the value is access, currency, and the author, not a file.
The Governance Vault, all-access annual licence
The complete library: all seven pillar kits, the flagship packs, every template and scoring instrument, plus every quarterly update for as long as you subscribe. Size-banded to your door, from a three-person team to an enterprise.
The cost of waiting: buying instruments one at a time costs more within two purchases, and leaves every unbought discipline ungoverned in the meantime.
Proof: a mid-size public organization went from zero to certification-ready in two quarters by running the full library as one system.
Banded by your door. Large and Enterprise bands from 12,000 USD per year, final band set by conversation, not a cart.
Choose your bandCertified Practitioner Program
The examined credential in operational AI governance, built on the AI Governance Emergency Response Framework (AI-ERF)™ and the seven pillars: the assessment, the verifiable badge, and listing in the certified-practitioner directory.
The cost of waiting: the market is minting AI governance roles faster than it can verify them, and the first credential holders set the hiring bar everyone after them is measured against.
Renewal is priced at exactly ten percent of the certification ceiling, the convention used by established certification bodies.
Annual renewal 390 USD, or 990 USD for three years: the current-year frameworks, re-attestation, and directory listing.
Get certifiedThe Governance Circle, membership
The membership where practitioners keep their governance alive: the quarterly cadence, the working sessions, the shared field patterns, and direct access to the evolving standard.
The cost of waiting: governance practiced alone drifts, and the practitioner who discovers a failure pattern second pays full price for it.
Tiers are named by outcome, Practitioner, Professional, and Partner, never by price.
The Living Standard, regulatory update service
The quarterly update pack: what changed in the European Union Artificial Intelligence Act and the standards landscape, what it means for you, and exactly which of your instruments to revise.
The cost of waiting: the European Union Artificial Intelligence Act applies in phases on published dates, and a document written for last quarter answers a regulator with last quarter's law.
Also available standalone for single-kit owners.
Stay currentThe Intelligence Subscription, monthly briefing
The monthly executive briefing: incident case patterns, the regulatory radar, and the questions boards and regulators are asking this quarter, written for the leaders who must answer them.
The cost of waiting: the executive who learns of a governance expectation from their own board meeting has already failed the meeting.
Begins with a conversation, priced to your door.
Request the briefingEvery organization deploying artificial intelligence (AI) will govern it one way or another. The only question is which path you take, what it costs, and what you hold in your hands at the end. Here is the comparison, stated plainly.
| Your option | What it costs | Time to value | What you hold at the end |
|---|---|---|---|
| Do nothing | Zero today. The European Union Artificial Intelligence Act (EU AI Act) provides administrative fines of up to 35 million euros or 7 percent of worldwide annual turnover for the most serious violations, and its obligations are already phasing in on published dates. | Immediate exposure, compounding quarterly | An explanation, delivered after the failure, to a board that asked for documents |
| Hire a consulting firm | Engagements commonly scoped in the high five to seven figures | Months of discovery before the first deliverable | A slide deck and a team that leaves. The methodology walks out the door with them. |
| Build it internally | A senior hire plus months of loaded salary, starting from a blank page | Quarters, learned by trial and error on your own systems | A first draft, untested against any external standard |
| Deploy this catalog | 1,400 to 4,900 USD per instrument, 4,900 to 29,000 USD per year for everything | Working documents this week, authored by a named authority | The operational layer of AI governance: instruments you own, evidence you can file, and a standard that stays current |
Every direct-purchase instrument carries a fourteen-day, no-questions refund. If a kit does not give your organization a working governance instrument it can deploy, you get your money back. Subscriptions cancel anytime. The risk of trying sits with the author, not with you.
No countdown timers here. The urgency is the regulatory calendar itself: the EU AI Act obligations phase in on dates already published, International Organization for Standardization / International Electrotechnical Commission (ISO/IEC) 42001 certification takes quarters, and catalog prices rise ten to twenty percent every two quarters as the standard matures. The earliest buyers pay the least and are ready the soonest.
Every instrument is authored by Mathieu K. Gouanou: decades of professional experience as a strategist, business analyst, and AI architect, Member of the Harvard Business Review Advisory Council, author of the AI Governance Emergency Response Framework (AI-ERF)™ and creator of the AI Sycophancy Risk Register™. This is not a template shop. It is a named standard with a named author who stands behind it.
Your organization size sets your band. Your seat sets your first instrument. The routers above place you in exactly one path, whether you are a three-person team or a national ministry.
Find your fit in 30 seconds Start the conversation (engagements above 5,000 USD)
Not ready to buy? The free tier holds more than twenty working instruments. Take them, use them, and come back when the board starts asking questions.