Buy the AI system inventory now; defer the conformity-assessment engine until 2027. The EU AI Act's standalone high-risk obligations moved to 2 December 2027, and not one CEN-CENELEC harmonised standard has been cited in the Official Journal. Every "EU AI Act policy pack" you can buy today is a vendor's reading of a rule that is still being written. The inventory is the only artifact that survives every version of what happens next.
The reference workload for everything below: a 4,000-employee, EU-exposed enterprise with roughly 60 AI systems in the register, three of them Annex III high-risk, running on Azure and Databricks, governed by a two-person team who also own privacy.
| Platform | What you are actually buying | Published price | Do not buy if |
|---|---|---|---|
| ServiceNow AI Control Tower | Inventory + workflow on the CMDB you already own | No list price; bundled into all 2026 tiers | You are not already a ServiceNow shop |
| IBM watsonx.governance | Model lifecycle, evaluations, drift monitoring | $42,000/12 mo (5 use cases) + $15,960 per extra use case | Your register will exceed ~10 use cases |
| Credo AI | Policy-first mapping, regulator-facing evidence | Contact sales | You need runtime enforcement, not documentation |
| OneTrust AI Governance | AI registry welded to your existing DPIA program | Contact sales | You do not already run OneTrust for privacy |
| Holistic AI | Bias/robustness testing, 40+ test suites | Contact sales | Nobody on staff can act on a fairness result |
| Vanta | Audit-automation path to ISO 42001 | Contact sales (4 tiers) | You need Annex IV technical documentation |
| Truyo | Inventory + privacy + consent, one vendor | $250,000/12 mo (private offer) | You cannot verify the premium against references |
What Is Actually Due in August 2026 Is Not Governance Software
The obligation that landed on 2 August 2026 is Article 50 transparency, and no governance platform discharges it. The deferral itself is settled law rather than a proposal you can still hope moves: the Council gave final approval on 29 June 2026 and the Digital Omnibus entered into force on 27 July 2026 as Regulation (EU) 2026/1744, three days after publication in the Official Journal. It defers standalone Annex III high-risk systems to 2 December 2027 and embedded Annex I systems to 2 August 2028.
Article 50 was not deferred. It binds five duties: AI-interaction disclosure and synthetic-content marking on providers, and emotion-recognition notice, deepfake disclosure and public-interest text disclosure on deployers — with systems already on the market before 2 August 2026 getting until 2 December 2026 for the marking requirement only. Breach exposure is up to €15 million or 3% of worldwide turnover, whichever is higher.
Read that list again as an engineering ticket. Marking output as machine-readable synthetic content is a change to your inference pipeline. Telling a user they are talking to a bot is a change to your UI. A governance platform records that you did both; it cannot do either. Two other obligations are already live and equally untouched by software: Article 4 AI literacy has applied to every provider and deployer since 2 February 2025, and the Commission's enforcement and fining powers over general-purpose AI providers began on 2 August 2026, a year after the GPAI obligations themselves.
Zero Cited Standards Means Every Policy Pack Is a Guess
No standard currently grants presumption of conformity, which makes the central feature of this product category unverifiable. The first one has now been written: CEN-CENELEC approved EN 18286 on quality management on 12 July 2026 and published it later that month, the first AI Act standard to get that far. But publication is not citation — zero deliverables have been cited in the Official Journal, so none of them shifts the burden of proof yet. The rest are still at enquiry or earlier — the public trackers disagree on exactly how many, which is its own signal — and the amended standardisation request runs to 28 February 2027 against an internal target of Q4 2026. CEN and CENELEC publicly moved to accelerate the programme in late 2025, which is itself the tell.
Do the arithmetic on the runway. If the prioritised standards land in Q4 2026, a December 2027 deadline leaves about twelve months of standards-backed compliance work, not the sixteen months the deferral appears to grant. The delay is smaller than it looks.
The infrastructure below the standards is thinner still. Conformity-assessment bodies are applying, but designation takes six to twelve months per applicant and very few had been fully designated as of early 2026, with only three member states having fully designated their competent authorities. You cannot buy your way past a notified body that does not exist.
So when a vendor demonstrates an "EU AI Act policy pack" that maps controls to Articles 9 through 15, understand precisely what you are seeing: a competent, good-faith interpretation, built before the technical specification was published, which will be revised. That is worth something. It is not worth six figures a year, two years early, on a multi-year contract.
The Seven Platforms, and Who Should Not Buy Each
ServiceNow AI Control Tower is the strongest default for the reference workload, and the reason is commercial rather than technical. On 9 April 2026 ServiceNow collapsed five legacy tiers into Foundation, Advanced and Prime, and AI Control Tower, Now Assist, Moveworks and Workflow Data Fabric are now bundled into every tier rather than sold as add-ons, with legacy SKUs going end-of-sale on 1 July 2026. It was also named a Leader in Gartner's first AI Governance Platforms Magic Quadrant, published June 2026. Do not buy it if you are not already a ServiceNow shop — the value is the CMDB and the workflow engine you already paid for, and buying the platform to get the module inverts the economics entirely.
IBM watsonx.governance is the deepest model-lifecycle product here and the only one whose price you can check without a sales call. It was also a Leader in that same Magic Quadrant. Its strength is evaluations, drift and monitoring — the machinery that makes Article 15 accuracy and robustness claims defensible later. Do not buy it if your register is a sprawl of shadow AI rather than a set of governed models; per-use-case economics turn hostile fast, as the next section shows.
Credo AI is the best pure-play regulatory instrument. Its platform runs an AI registry with auto-discovery, a policy engine with pre-built regulatory packs, runtime trace evaluation and shadow-AI classification, plus dependency graphs across agents, models, tools and data. Forrester named it a Leader in The Forrester Wave: AI Governance Solutions, Q3 2025 with top scores across twelve criteria including policy management and regulatory compliance audit. Gartner placed it as a Visionary. Both readings can be true: it is the most sophisticated documentation and policy layer in the category. Do not buy it expecting enforcement — documenting a control and enforcing it at the execution layer are different products, and this one is emphatically the former.
OneTrust AI Governance exists to be bought by people who already run OneTrust for privacy. It catalogs models, datasets, agents and vendors, tiers risk by use case, and ships EU AI Act, NIST AI RMF and ISO 42001 templates with attestation and sign-off tracking. Its real advantage is that a fundamental rights impact assessment is a first cousin of a DPIA, and your privacy team already runs that muscle. Gartner placed it as a Visionary. Do not buy it as a standalone; against Credo AI on AI-specific depth it loses, and the whole case rests on the adjacency.
Holistic AI is the testing house of the group — discovery, then 40+ specialised tests across bias, safety, security and performance, then enforcement agents. Gartner placed it as a Challenger. Do not buy it unless someone on staff can act on a fairness result. A bias report nobody is accountable for remediating is an expensive way to create discoverable evidence that you knew.
Vanta is the honest mid-market answer, and the one most buyers of this reference workload should shortlist against ServiceNow. It frames the Act as 150+ controls, 16 policies and dozens of artifacts, reuses ISO 42001 and NIST AI RMF evidence across frameworks, and automates collection across its integration estate. Pricing is four tiers — Essentials, Plus, Professional, Enterprise — with no published figures and AI governance and ISO 42001 as separate framework offerings. Do not buy it if your near-term need is Annex IV technical documentation for a high-risk system. Audit automation and conformity evidence are not the same discipline.
Truyo is the loser of this comparison, and the reason is the price-to-verifiability ratio rather than the product. It is a genuine Gartner Leader with inventory, risk, privacy and consent in one platform, and its AWS Marketplace listing publishes a $250,000 twelve-month subscription, private offer only — checked 7 August 2026. Two things sit uneasily beside that number. Gartner's inaugural MQ was, by the analysis above, a vision-and-product evaluation that explicitly did not rate market track record or operations, from a field filtered to vendors with more than ten paid deployments. And the vendor's answer to buyer uncertainty is a certification warranty of up to $1 million, underwritten by a third party, rather than a reference list. A warranty is not evidence that the product works; it is a price on the risk that it does not. If you shortlist Truyo, make customer references at your scale a gating condition.
Only One Vendor Publishes a Price, and Its Unit Punishes You
Six of the seven make you call sales, which is itself the finding: this category has no price discipline because buyers are frightened and deadlines do the selling.
IBM is the exception, and the published unit is the whole story. Its AWS Marketplace listing shows $42,000 for a twelve-month Standard contract covering one instance, model risk governance for 5 AI use cases, 25 concurrent users and 12,000 evaluations, with additional use cases at $15,960 each — checked 7 August 2026.
Run the reference workload through it. Sixty governed use cases means five included and fifty-five at $15,960, or roughly $920,000 a year at list. No enterprise pays list and a negotiated agreement will not look like that. But the shape survives negotiation, and the shape is the point: the billing unit charges you more precisely as your inventory gets more honest. A governance tool whose cost rises with the completeness of your register is taxing the behaviour you are trying to buy. We have made this argument before about LLM observability pricing and it holds harder here, because the register is a legal artifact rather than a debugging convenience.
Ask every vendor on your shortlist one question in writing: what happens to my bill when my inventory doubles? If the answer is "it doubles", you are buying a disincentive to find your own shadow AI.
The Inventory Is the Artifact That Survives Every Scenario
Buy the register first because it is the only deliverable that is required under every framework, unaffected by the standards delay, and impossible to acquire quickly.
Policy packs get revised when the Official Journal citation lands. Conformity workflows are useless until a notified body can receive them. The inventory is different: you need it for Article 50 (to know which systems talk to humans), for the December 2027 high-risk work (to know which systems are Annex III), for ISO 42001, for NIST AI RMF, and for any US state regime that arrives next. It is also the slowest to build, because a register is only as good as its discovery — and discovery is where these programmes actually fail. Enterprises consistently find AI agents and workflows their security teams did not know existed, and an inventory built from a survey of team leads is fiction that every downstream control inherits.
This is also why the platform-native options deserve a look before any of the seven. If your estate is genuinely consolidated, Azure AI Foundry and Databricks Mosaic AI already emit lineage and asset discovery you are paying for, and monitoring specialists like Fiddler AI and Arthur cover the evaluation layer without a governance suite on top. The trap is that estates are never as consolidated as the architecture diagram claims, which is exactly what a discovery scan is for. Run one before you buy anything; the result reorders the shortlist more often than not.
What Still Needs a Human Being
No platform on this list produces the four things that will actually decide your conformity, and vendors are quiet about all four.
Risk classification. Deciding whether your CV-screening tool is Annex III high-risk is a legal judgement about your specific deployment context. Software structures the question and records the answer. A lawyer owns it.
The fundamental rights impact assessment. Article 27 requires six substantive elements — deployment processes, period and frequency of use, affected persons, specific fundamental-rights risks, oversight measures, and the measures taken when those risks materialise, including internal governance and complaint mechanisms. A template renders that; it cannot write it, and the complaint mechanism is an operational commitment involving staffed humans answering complaints.
Human oversight under Article 14. The Act requires oversight that is meaningful. Our own reporting on how reviewers defer to confident-sounding AI explanations is the uncomfortable version of this: a named reviewer who rubber-stamps is a documented control and a real failure at once. No platform detects the difference.
Accountability. Someone must own the decision when a governed system causes harm, and that ownership is still the gap in most AI programmes. A workflow with an approver field is not the same as a person with authority to stop a launch.
Budget for these separately. In practice they consume more of the programme than the licence does, and a platform bought to substitute for them produces the worst outcome available: an immaculate audit trail documenting decisions nobody actually made.
How to Decide Before Your Next Budget Cycle
This week: Close Article 50. Confirm every customer-facing system discloses that it is AI, and that synthetic output carries machine-readable marking. That is the live obligation with a €15 million ceiling, and it is an engineering ticket, not a procurement.
This month: Run a discovery scan and build the register — owner, purpose, data, model, EU exposure, provider-or-deployer. Most vendors here will run one in a trial. Do the scan before you choose, and treat the gap between the scan and your team's list as the real measure of your programme.
Before Q4 close: Pick on inventory quality and billing unit, in that order. If you run ServiceNow, use what is bundled and revisit in a year. If you do not, shortlist Vanta against Credo AI and demand written answers on the cost of doubling your register. Sign nothing longer than twelve months while the harmonised standards remain uncited.
Q1 2027: Reopen the conformity question once the JTC 21 deliverables are cited and notified bodies are actually designated. That is when a policy pack becomes a product rather than a projection, and when the December 2027 work can start against a real specification.
The Bottom Line
This category is selling a deadline that moved. The vendors are mostly good, the analysts genuinely disagree about who leads — Forrester's Leader is Gartner's Visionary — and the products converge on the same three things: a register, a workflow, and a mapping. Two of those three are durable. The mapping is the one being marketed hardest, and it is the one pointed at a standard that has not been cited.
Buyers who spend 2026 building an honest inventory and closing Article 50 will do the December 2027 work in months. Buyers who spend 2026 buying a conformity engine will renew it once before it has anything real to assess.
Buy the register. Rent the opinion.
Continue Reading
- EU AI Act Deadline Shifted 16 Months. Don't Celebrate Yet.
- EU AI Transparency Law Starts Monday: Are You Ready?
- Datadog vs Arize vs LangSmith: Buy on the Billing Unit
- ServiceNow Control Tower Finds Shadow AI Before Auditors
- No One's Responsible When AI Agents Fail. That Ends Now.
- Why 69% of Enterprises Can't Govern Their Own AI Agents
- Pinecone vs Weaviate vs pgvector: Stay on Postgres
