EU AI Act · August 2, 2026 · 78 days remaining

AI governance built
to actually work.

For mid-market companies adopting AI faster than they can govern it. From no framework to fully operational — built by operators, not lawyers.

Book a Discovery Call See the Platform →
6/6
SQF audits rated Excellent
$18K
Starting price, fixed scope
90
Days to full framework
0
Billable-hour surprises
78
Days until enforcement

The EU AI Act is not coming.
It is here.

Full enforcement begins August 2, 2026. High-risk AI systems without documented governance face penalties up to €35 million or 7% of global turnover. Most mid-market companies are not ready. We can change that in 90 days.

[The Problem]

Your team is using AI.
Your governance hasn't caught up.

Most mid-market companies adopted AI tools bottom-up, without coordination. The result is a real risk surface no one has mapped — and regulators are now asking hard questions about it.

01 ·

Tool sprawl no one tracks

The average mid-market company has 30+ AI tools in use. Most leaders can name fewer than ten. The rest are someone's free-tier login — running on your data, outside your control.

02 ·

Policies that aren't real policies

A draft in a folder. A page in the handbook nobody updated. A prohibition employees route around because it isn't workable. That's not governance — that's liability with a cover sheet.

03 ·

Compliance creeping from every side

EU AI Act, state laws, sector rules, customer questionnaires, investor diligence. Each one wants a coherent answer. Most companies don't have one yet.

[How It Works]

From assessment
to fully operational.

Four stages, clear timelines, fixed prices. You know exactly where you are and what comes next.

01
2–12 weeks · $3.5K–$18.5K
AI Readiness Audit
Full tool inventory, permission audit, governance gap analysis, and a 90-day roadmap. Board-ready presentation included.
02
3 months · $18K–$35K fixed
Governance Build
Six custom-built deliverables: policy, vendor risk process, compliance mapping, incident response playbook, and training materials.
03
Included in Build
Internal Owner Handoff
We train someone on your team to own the framework. You leave with capability, not dependency.
04
Optional · $3K–$8K / month
Fractional AIGO
Keep your framework current. Quarterly reviews, regulatory digest, vendor risk updates, on-call access. Cancel anytime.
[Products]

Three ways
to get compliant and stay there.

Fixed-scope engagements and platform tools that work together — from first audit through continuous compliance.

AU — Assessment
2–12 weeks · Flat fee

AI Readiness Audit

Full tool inventory, permission audit, governance gap analysis, and a 90-day roadmap. Board-ready presentation included. Start here if you're not sure what you're working with.

$3.5K–$18.5K flat fee
GB — Core Service
3 months · Fixed scope

AI Governance Build

Zero to fully operational AI risk framework. Six custom-built deliverables: policy, vendor risk process, compliance mapping, incident response playbook, training, and internal owner handoff.

$18K–$35K fixed scope
FO — Retainer
Monthly · Cancel anytime

Fractional AI Governance Officer

Keep your framework alive. Quarterly reviews, vendor risk updates, regulatory digest, on-call access. Ongoing accountability without a full-time hire.

$3K–$8K / month
Also available
6/6
Consecutive SQF Excellent ratings
Paige Packaging, Inc.
6yr
Framework durability — outlasted personnel changes, expansions, customer audits
0
Zero to SQF certified, built from the ground up in a single engagement
100%
Client retention on the retainer — every client who started is still on it

Operators,
not lawyers.

We built governance frameworks for regulated industries before AI governance was a category. Six consecutive SQF Excellent audits. 40 years on the operations floor. That's the difference between a policy and a framework that actually holds up.

Talk to the CORA team
01 ·

Fixed scope, fixed price

You know the full investment before we start. No billable-hour surprises, no scope creep. If the engagement needs to grow, we discuss it openly before it does.

02 ·

Custom-built, not templated

Every deliverable is shaped around your tools, your industry, and your regulatory exposure — not downloaded from a law firm's site and lightly edited.

03 ·

Plain language people actually read

If your team can't explain the policy in their own words, it isn't a policy. Everything we write is made to be understood — not filed away.

04 ·

Internal capability transfer

We train an internal owner so the framework lives on after we're done. You don't have to keep us forever. That's by design.

05 ·

We'll tell you the truth

If we're not the right fit, we say so on the discovery call — and point you to who is. We've turned down work that wasn't right for the client.

Go deeper
on AI governance.

[FAQ]

Common questions,
plain answers.

Lawyers write policies. We build frameworks your team can actually operate. Everything is plain language, custom-built for your tools and industry, with an internal owner handoff so you don't need us forever.
You know the full investment before we start. No hourly billing, no scope creep, no surprise invoices. If the project expands beyond what was agreed, we discuss it openly before proceeding.
No. The EU AI Act applies to any company that sells products or services into the EU, or whose AI systems affect EU residents. Many US mid-market companies have EU customers and don't realize they're in scope.
Three months for the full engagement. The AI Readiness Audit that precedes it takes 2–12 weeks depending on your organization's complexity. Most clients go from zero to fully operational in under 6 months total.
Six deliverables: AI Governance Assessment Report, AI Use Policy, Vendor Risk Process, Compliance Mapping Document, Incident Response Playbook, and Training Materials — all in formats your team can maintain without us.
We build into what you already use — Notion, Microsoft 365, Google Workspace, and standard HR and procurement systems. We don't require new software purchases to get your framework operational.
Yes. Our deliverables are mapped to EU AI Act, NIST AI RMF, ISO 42001, SOC 2 AI Addendum, SQF/FSSC 22000, and FDA 21 CFR Part 11. They are built to satisfy auditors, not just check boxes internally.
Start with the AI Readiness Audit. It gives you a complete picture of your risk surface and a 90-day roadmap. Many clients use it to build internal alignment before committing to the full build.

Start with a
30-minute call.

We'll talk through where you are, what your risk picture looks like, and whether we're a fit. If we're not, we'll tell you and point you to who is.

Cora
Cora
ClearpathAI · AI Governance

How can I help you today? I can answer questions, connect you with a partner, or get a meeting on the calendar.

Book a Meeting
What AI governance challenge are you trying to solve?
Cora · just now
Privacy Policy