CXO Ready finds every AI system in your business, including the ones nobody told you about. It scores each against the EU AI Act, GDPR and ISO 42001, then hands you a prioritised plan with the evidence to back it up.

Every AI system, owner, and risk in one register
Blended governance score across EU AI Act and GDPR
Action plan, evidence, and audit-ready exports
Trusted in production
VIVID Homes governs its AI estate on CXO Ready.
One of the UK’s larger housing associations, with over 1,000 staff and an award-winning AI programme, uses CXO Ready to keep every AI system inventoried, scored and evidenced.
Built around the frameworks your regulators use
What it is
CXO Ready is the record of which AI your organisation runs, how risky each system is, and what you have done about it. Three things, kept current, that together answer almost every question anyone will ask about your AI.
Every AI system in the business in one register. Vendor tools, models your teams built, and the ones nobody declared, each with an owner, a purpose and a lifecycle stage.
Each system classified and scored against the EU AI Act, GDPR and ISO 42001, so you can say which are high-risk and why, rather than guessing.
The assessments, decisions, owners and dates behind that position, recorded as you go and exportable when a regulator, customer or auditor asks.
It is not a policy library and not a consultancy. It is the working record underneath both, the thing that has to exist before any of it can be evidenced.
Where the law stands today
Every date below has already passed. Enforcement began on 2 August 2026, and the first question a regulator, customer or insurer asks is the same one: which AI systems do you run, and who is accountable for each of them?
Published in the Official Journal, starting the phased timetable.
Banned practices became unlawful, and staff working with AI must be given adequate AI literacy.
Transparency, documentation and copyright duties for GPAI model providers, plus the governance and penalty framework.
The AI Office and national authorities began enforcing. Further obligations continue to phase in after this date.
In force nowLater obligations phase in beyond 2026, and the timetable has been amended since the Act was published. The European Commission's AI Act pages are the authority on current dates. This summary is for orientation, not legal advice.
How it works
Add every AI system, owner, vendor, and use case. Find shadow AI through team surveys.
Blended governance score against EU AI Act, GDPR, and ISO 42001, with per-system breakdowns.
Prioritised action plan, owner assigned, evidence captured, exportable for the boardroom.
What you get
One register for every model, vendor, and use case. Shadow AI surfaced through team surveys before it surfaces in an incident.

One score, built from the evidence each system actually carries: legal basis, DPIA, human oversight, bias and drift controls, kill-switch and security posture. Click any number to see exactly which controls moved it.

Prioritised tasks and a Gantt the team actually delivers against. Tasks auto-generated from scoring gaps, exportable for the board pack.

CXO Ready translates complex EU AI Act and GDPR requirements into one indicative score, giving your board a clear view of where your AI estate stands.
It tracks every system so you can see what has been documented and what has not, and evidence the work you have done. It structures the assessment; it does not certify the outcome, and it is not a substitute for legal advice.
Built for the executive table
See it yourself
Eight questions, an indicative score, and a snapshot of where you stand against the EU AI Act. Indicative only, not legal advice.
See how well your organisation is set up to manage AI risk, governance, and readiness.
Answer 8 quick questions to get your AI Governance score and see where your biggest gaps might be. Takes about 60 seconds.
Pricing
Start free on a single system. Move up when your estate does.
£0/month
Evaluate a single system, free forever.
1 AI system
£150/month
The usual starting point for a real AI estate.
Up to 20 AI systems
£500/month
For a group-wide estate across business units.
Up to 200 AI systems
7-day free trial on paid plans. No card required to start.
CXO Ready is an aid, not an assurance. It helps you structure your thinking, record what you have done and see where the gaps are. It does not make you compliant, and nothing it produces is legal advice or a regulatory opinion. Scores are indicative. Responsibility for compliance stays with your organisation, and decisions with legal consequences should be taken with a qualified adviser.
Common questions
AI governance software keeps a register of every AI system an organisation runs, records who owns each one and what it does, and measures each against the obligations that apply to it. CXO Ready scores every system against the EU AI Act, UK GDPR and ISO 42001, then turns the gaps into an owned action plan with evidence attached.
A spreadsheet records what someone typed. CXO Ready scores each system from the evidence it actually carries — legal basis, DPIA, human oversight, bias and drift controls, kill-switch, security posture — so the score reflects what has been documented rather than what was self-declared. It also tracks change over time, assigns owners, and exports audit-ready evidence per requirement.
No, and no tool can. CXO Ready shows you where you stand, what is missing and who needs to fix it, with the evidence to demonstrate it. Compliance remains your organisation’s responsibility, and our scores are indicative rather than a legal opinion. What we give you is the register, the measurement and the proof — the things you would otherwise assemble by hand before an audit.
General GRC platforms were not built for AI-specific obligations: risk classification under the EU AI Act, model drift, human oversight, shadow AI, or per-system DPIA status. CXO Ready covers that layer specifically, and exports evidence you can feed into the GRC process you already run.
Shadow AI is any AI tool staff use that has not been sanctioned or recorded — typically a subscription bought on a card, or a free assistant handling real customer data. CXO Ready surfaces it with short surveys sent across the business, so tools appear in your register before they appear in an incident.
Setup takes about five minutes and the free trial runs for seven days with no card required. Most organisations have their first systems inventoried and scored on day one; a full estate depends on how many teams you need to survey.
Plans run from free for a single AI system up to £500 a month for 200 systems, with Starter at £50, Professional at £150 and Business at £300. Every paid plan includes unlimited users, so cost scales with the size of your AI estate rather than headcount.
The people accountable when someone asks whether your AI is under control: CIOs and CTOs who need estate visibility, risk officers who need AI risk quantified, general counsel who need compliance evidence, and CFOs tracking return on AI investment. It is built for business use in regulated and enterprise organisations across the UK and EU.
The Act entered into force on 1 August 2024 and applies in stages. Prohibited practices and AI literacy duties applied from 2 February 2025, general-purpose AI model obligations from 2 August 2025, and on 2 August 2026 the Act became generally applicable, with enforcement by the AI Office and national authorities. Later obligations continue to phase in, and the timetable has been amended since publication, so check the European Commission's pages for current dates.
Fines are tiered. The heaviest apply to prohibited practices, then to breaches of obligations for high-risk systems and general-purpose AI models, with lower amounts for supplying incorrect or misleading information to authorities. The exact figures are set in the Act itself; the practical point is that penalties are turnover-linked, so they scale with the size of the business rather than the size of the AI system.
In practice, yes. Almost every obligation starts from knowing which AI systems you operate and who is accountable for each: risk classification, human oversight, transparency, incident reporting, and the record-keeping behind them. An organisation that cannot list its AI systems cannot evidence anything else, which is why an inventory is the first thing CXO Ready builds.
More detail on the full FAQ.