⭐ Star on GitHub

Summary: Controlled environments under AI Act Articles 57–59 where AI systems can be developed and tested with regulatory guidance before market release. Following the supervising authority’s guidance shields you from administrative fines — but not from third-party liability.

Sources: raw/Laws/AI Regulatory Sandbox Approaches_ EU Member State Overview...md; raw/AI-regulations/Small Businesses' Guide to the AI Act...md

Last updated: 2026-07-28


What they are

“Frameworks for testing AI systems in controlled environments that foster innovation and facilitate development, training, testing, and validation before market entry” (source: AI Regulatory Sandbox Approaches…md).

They “improve legal certainty, support compliance, allow for processing of personal data, and facilitate market access for SMEs and startups.”

The two things that make them worth using

  1. Documentation from participating “can be used to demonstrate compliance with the AI Act.”
  2. “Providers will not face administrative fines for infringements of the Act, as long as they follow the guidance of the national competent authority.”

And the limit: “providers remain liable for damages to third parties caused by experimentation with AI systems in a sandbox” (source: AI Regulatory Sandbox Approaches…md).

So the sandbox converts regulatory risk into supervised risk. It does not convert civil liability into anything. For an AI security team, that distinction sets the boundary of what is safe to test inside one.

The evidence base

Drawn from other sectors: “companies that completed successful testing within the UK FCA sandbox received 6.6 times more fintech investment than their peers,” and the FCA sandbox “reduced the average time required for market authorisation by 40%” (source: AI Regulatory Sandbox Approaches…, citing an OECD report on regulatory sandboxes in AI).

Implementation is uneven

“The implementation status of the sandboxes varies significantly across Member States. Some, such as Denmark, have operational sandboxes and concrete plans, while others remain in early planning stages.”

Institutional approaches differ too: “in some Member States, data protection authorities are leading the effort; elsewhere, new centralised AI agencies are being established. Some Member States are opting for decentralised models that coordinate existing regulators” (source: AI Regulatory Sandbox Approaches…md).

That the supervising authority might be a DPA, a new AI agency, or a coordinated group of existing regulators materially changes what a sandbox engagement looks like. Check the specific Member State.

EU-wide supporting infrastructure

  • EUSAiR — the EU Regulatory Sandboxes for AI.
  • Testing and Experimentation Facilities (TEFs).
  • European Digital Innovation Hubs (EDIHs).

(source: AI Regulatory Sandbox Approaches…md)

The SME angle

Sandboxes are the first-listed SME provision in the Act: “SMEs will have priority access to sandboxes free of charge, and the procedures shall be simple and clear,” with exemption from administrative fees and facilitated real-world-conditions testing (source: Small Businesses’ Guide to the AI Act…md).

Of the six SME reliefs, this is the only one that changes legal exposure rather than paperwork burden. See AI Act and SMEs.

Lineage

The concept comes from OECD Principle 2.3, which recommends governments “consider using experimentation to provide a controlled environment in which AI systems can be tested, and scaled-up, as appropriate.”

Caveat on this page

The source describes itself as “a work in progress” that “will be updated when new information is available,” and solicits corrections about national authorities. Member State detail on this page will go stale quickly — verify current status directly before relying on it.