CXO Ready
    EU AI Act enforceable since 2 August 2026

    Prove your AI governance.
    Before a regulator asks.

    CXO Ready finds every AI system in your business, including the ones nobody told you about. It scores each against the EU AI Act, GDPR and ISO 42001, then hands you a prioritised plan with the evidence to back it up.

    7-day free trialNo credit card5-minute setup
    cxoready.com / Dashboard
    CXO Ready executive governance dashboard showing blended score, AI systems, and KPIs
    See

    Every AI system, owner, and risk in one register

    Control

    Blended governance score across EU AI Act and GDPR

    Prove

    Action plan, evidence, and audit-ready exports

    Trusted in production

    VIVID Homes governs its AI estate on CXO Ready.

    One of the UK’s larger housing associations, with over 1,000 staff and an award-winning AI programme, uses CXO Ready to keep every AI system inventoried, scored and evidenced.

    Built around the frameworks your regulators use

    EU AI Act
    GDPR
    ISO 42001

    What it is

    AI governance software, in one sentence.

    CXO Ready is the record of which AI your organisation runs, how risky each system is, and what you have done about it. Three things, kept current, that together answer almost every question anyone will ask about your AI.

    An inventory

    Every AI system in the business in one register. Vendor tools, models your teams built, and the ones nobody declared, each with an owner, a purpose and a lifecycle stage.

    A risk position

    Each system classified and scored against the EU AI Act, GDPR and ISO 42001, so you can say which are high-risk and why, rather than guessing.

    The evidence

    The assessments, decisions, owners and dates behind that position, recorded as you go and exportable when a regulator, customer or auditor asks.

    It is not a policy library and not a consultancy. It is the working record underneath both, the thing that has to exist before any of it can be evidenced.

    Where the law stands today

    The EU AI Act is no longer coming.
    It is here.

    Every date below has already passed. Enforcement began on 2 August 2026, and the first question a regulator, customer or insurer asks is the same one: which AI systems do you run, and who is accountable for each of them?

    1. The Act entered into force

      Published in the Official Journal, starting the phased timetable.

    2. Prohibitions and AI literacy applied

      Banned practices became unlawful, and staff working with AI must be given adequate AI literacy.

    3. General-purpose AI obligations applied

      Transparency, documentation and copyright duties for GPAI model providers, plus the governance and penalty framework.

    4. The Act applies, and enforcement begins

      The AI Office and national authorities began enforcing. Further obligations continue to phase in after this date.

      In force now

    Later obligations phase in beyond 2026, and the timetable has been amended since the Act was published. The European Commission's AI Act pages are the authority on current dates. This summary is for orientation, not legal advice.

    How it works

    Three steps to AI you can defend.

    01

    Capture your estate

    Add every AI system, owner, vendor, and use case. Find shadow AI through team surveys.

    02

    Assess and score

    Blended governance score against EU AI Act, GDPR, and ISO 42001, with per-system breakdowns.

    03

    Act and prove

    Prioritised action plan, owner assigned, evidence captured, exportable for the boardroom.

    What you get

    Every screen, built for the boardroom.

    AI Systems Inventory

    One register for every model, vendor, and use case. Shadow AI surfaced through team surveys before it surfaces in an incident.

    • Shadow AI discovery via team surveys
    • Owner and sponsor recorded per system
    • Risk classification mapped to EU AI Act
    AI Systems inventory

    Governance Dashboard

    One score, built from the evidence each system actually carries: legal basis, DPIA, human oversight, bias and drift controls, kill-switch and security posture. Click any number to see exactly which controls moved it.

    • Best practice & regulatory controls logged
    • Monthly trend lines for readiness
    • Score interpretation explains every number
    Governance dashboard

    Action Plan & Roadmap

    Prioritised tasks and a Gantt the team actually delivers against. Tasks auto-generated from scoring gaps, exportable for the board pack.

    • Tasks generated automatically from gaps
    • Owners, target dates, monthly analytics
    • Completion metrics to show progress
    Action plan and roadmap

    Regulatory Compliance

    CXO Ready translates complex EU AI Act and GDPR requirements into one indicative score, giving your board a clear view of where your AI estate stands.

    It tracks every system so you can see what has been documented and what has not, and evidence the work you have done. It structures the assessment; it does not certify the outcome, and it is not a substitute for legal advice.

    • Per-system applicability for GDPR and EU AI Act
    • Hard-fail controls capped to prevent false comfort
    • Audit-ready evidence per requirement

    Built for the executive table

    A single source of truth, for every leader accountable for AI.

    For CIO

    Know what AI is running and where the risk sits.

    • Full estate visibility, no spreadsheets
    • Vendor and integration mapping per system
    • Reviews and assurance cycles on a schedule
    For CRO

    Quantified AI risk, mapped to EU AI Act categories.

    • Risk register linked to systems and incidents
    • Escalation paths with 4-tier SLA logic
    • Board-ready risk reporting on demand
    For General Counsel

    Compliance evidence ready before the regulator asks.

    • EU AI Act, GDPR, ISO 42001 alignment
    • Policy library with review cadence
    • Audit logs and evidence per requirement
    For CFO

    ROI horizon and cost-to-deliver per AI system.

    • Multi-year configurable ROI horizon
    • Cost-to-deliver and operational costs tracked
    • Adoption metrics linked to value realised

    See it yourself

    Take the 2-minute AI governance health check.

    Eight questions, an indicative score, and a snapshot of where you stand against the EU AI Act. Indicative only, not legal advice.

    AI Governance Health Check

    See how well your organisation is set up to manage AI risk, governance, and readiness.

    Answer 8 quick questions to get your AI Governance score and see where your biggest gaps might be. Takes about 60 seconds.

    Pricing

    Priced per month. No sales call to find out.

    Start free on a single system. Move up when your estate does.

    Free

    £0/month

    Evaluate a single system, free forever.

    1 AI system

    Most chosen

    Professional

    £150/month

    The usual starting point for a real AI estate.

    Up to 20 AI systems

    Enterprise

    £500/month

    For a group-wide estate across business units.

    Up to 200 AI systems

    Compare all five plans

    7-day free trial on paid plans. No card required to start.

    CXO Ready is an aid, not an assurance. It helps you structure your thinking, record what you have done and see where the gaps are. It does not make you compliant, and nothing it produces is legal advice or a regulatory opinion. Scores are indicative. Responsibility for compliance stays with your organisation, and decisions with legal consequences should be taken with a qualified adviser.

    Common questions

    What people ask before they start.

    What is AI governance software?

    AI governance software keeps a register of every AI system an organisation runs, records who owns each one and what it does, and measures each against the obligations that apply to it. CXO Ready scores every system against the EU AI Act, UK GDPR and ISO 42001, then turns the gaps into an owned action plan with evidence attached.

    How is this different from a spreadsheet?

    A spreadsheet records what someone typed. CXO Ready scores each system from the evidence it actually carries — legal basis, DPIA, human oversight, bias and drift controls, kill-switch, security posture — so the score reflects what has been documented rather than what was self-declared. It also tracks change over time, assigns owners, and exports audit-ready evidence per requirement.

    Does CXO Ready make us compliant with the EU AI Act or GDPR?

    No, and no tool can. CXO Ready shows you where you stand, what is missing and who needs to fix it, with the evidence to demonstrate it. Compliance remains your organisation’s responsibility, and our scores are indicative rather than a legal opinion. What we give you is the register, the measurement and the proof — the things you would otherwise assemble by hand before an audit.

    We already have a GRC tool. Why do we need this?

    General GRC platforms were not built for AI-specific obligations: risk classification under the EU AI Act, model drift, human oversight, shadow AI, or per-system DPIA status. CXO Ready covers that layer specifically, and exports evidence you can feed into the GRC process you already run.

    What is shadow AI, and how do you find it?

    Shadow AI is any AI tool staff use that has not been sanctioned or recorded — typically a subscription bought on a card, or a free assistant handling real customer data. CXO Ready surfaces it with short surveys sent across the business, so tools appear in your register before they appear in an incident.

    How long does it take to get started?

    Setup takes about five minutes and the free trial runs for seven days with no card required. Most organisations have their first systems inventoried and scored on day one; a full estate depends on how many teams you need to survey.

    How much does CXO Ready cost?

    Plans run from free for a single AI system up to £500 a month for 200 systems, with Starter at £50, Professional at £150 and Business at £300. Every paid plan includes unlimited users, so cost scales with the size of your AI estate rather than headcount.

    Who is CXO Ready for?

    The people accountable when someone asks whether your AI is under control: CIOs and CTOs who need estate visibility, risk officers who need AI risk quantified, general counsel who need compliance evidence, and CFOs tracking return on AI investment. It is built for business use in regulated and enterprise organisations across the UK and EU.

    When did the EU AI Act come into force?

    The Act entered into force on 1 August 2024 and applies in stages. Prohibited practices and AI literacy duties applied from 2 February 2025, general-purpose AI model obligations from 2 August 2025, and on 2 August 2026 the Act became generally applicable, with enforcement by the AI Office and national authorities. Later obligations continue to phase in, and the timetable has been amended since publication, so check the European Commission's pages for current dates.

    What are the penalties for breaching the EU AI Act?

    Fines are tiered. The heaviest apply to prohibited practices, then to breaches of obligations for high-risk systems and general-purpose AI models, with lower amounts for supplying incorrect or misleading information to authorities. The exact figures are set in the Act itself; the practical point is that penalties are turnover-linked, so they scale with the size of the business rather than the size of the AI system.

    Do we need an AI inventory?

    In practice, yes. Almost every obligation starts from knowing which AI systems you operate and who is accountable for each: risk classification, human oversight, transparency, incident reporting, and the record-keeping behind them. An organisation that cannot list its AI systems cannot evidence anything else, which is why an inventory is the first thing CXO Ready builds.

    More detail on the full FAQ.

    Plans for every stage

    Bring your AI estate under control this quarter.

    From free to £500 a month. Start with a 7-day free trial, no credit card required.

    Free£0Starter£50Professional£150Business£300Enterprise£500
    7-day free trial No credit card Cancel anytime

    Your Privacy Matters

    We use cookies to provide essential functionality, analyse usage, and improve your experience. Under GDPR, you have the right to choose which cookies you allow. Strictly necessary cookies cannot be disabled. Privacy Policy