The AI regulatory sandbox under the AI Act, in one paragraph
The first thing to know about an AI regulatory sandbox under the AI Act is that the deadline for setting them up moved. Article 57(1), as amended by the Digital Omnibus, Regulation (EU) 2026/1744, requires each Member State to ensure that its competent authorities establish at least one AI regulatory sandbox at national level, "which shall be operational by 2 August 2027". The 2024 text said 2 August 2026. The Digital Omnibus page sets that change alongside the other institutional deadlines that moved.
Article 3(55) defines the sandbox as "a controlled framework set up by a competent authority which offers providers or prospective providers of AI systems the possibility to develop, train, validate and test, where appropriate in real-world conditions, an innovative AI system, pursuant to a sandbox plan for a limited time under regulatory supervision". Three words in that definition do most of the work: providers (the entry ticket), plan (the contract you agree with the authority) and limited (it ends, and you leave with documents rather than a licence).
A sandbox is not an exemption from the Regulation. Article 57(11) states that sandboxes "shall not affect the supervisory or corrective powers of the competent authorities supervising the sandboxes", and nothing in Articles 57 to 59 disapplies the Article 5 prohibitions. The page on prohibited AI practices covers what no sandbox plan can authorise.
Where sandboxes will exist, and when
Article 57 provides for four kinds of sandbox.
| Level | Who runs it | Legal basis |
|---|---|---|
| National, mandatory | National competent authorities, alone, jointly with other Member States, or by participating in an existing sandbox with equivalent national coverage | Article 57(1) |
| Regional, local or cross-border, optional | Competent authorities at those levels or jointly with other Member States | Article 57(2) |
| Union institutions, bodies, offices and agencies, optional | European Data Protection Supervisor | Article 57(3) |
| Union level, optional | AI Office, for AI systems covered by Article 75(1) | Article 57(3a), inserted by Regulation (EU) 2026/1744 |
The Union-level sandbox is new and narrow. Article 75(1) covers AI systems built on a general-purpose AI model by the same provider or undertaking, with listed exceptions, and AI systems that constitute or are integrated into a designated very large online platform or search engine. That sandbox must give priority access to "SMEs, including start-ups, and SMCs". The word is "may": the text creates a power, not a duty.
National law is filling in the detail ahead of that date. Four examples, each taken from the statute itself:
| Member State | Instrument | What it provides |
|---|---|---|
| Germany | KI-MIG, § 13 | The Bundesnetzagentur must set up and run at least one KI-Reallabor under Articles 57 and 58, without prejudice to sandboxes run by other authorities. § 13(3) extends priority access to research institutions, universities and their spin-offs with a seat or branch in the EU. |
| Italy | Law 132/2025, Article 20(1)(c) | AgID and ACN, each within its competence, ensure the establishment and joint management of "spazi di sperimentazione" for AI systems compliant with national and Union law, consulting the Ministry of Defence on dual-use systems and the Ministry of Justice on judicial systems. The existing testing regime for AI systems used by financial institutions, under Article 36(2-bis) to (2-novies) of Decree-Law 34/2019, is preserved. |
| Poland | Act of 3 July 2026 on AI systems, Articles 91 to 101 | KRiBSI, the Commission for the Development and Security of AI, runs the sandbox through a competition. Article 91(7) sets a duration of no less than 6 and no more than 12 months; Article 93(1) makes participation free for micro, small and medium enterprises. |
| Spain | Royal Decree 817/2023 | A pilot testing environment set up in November 2023 against the then-proposed Regulation, limited to 36 months or until the Regulation applies in Spain. A forerunner, not an Article 57 sandbox. |
The national authorities guide tracks the competent authority in each Member State, and the KI-MIG page covers the German Act in full.
Who can apply
The Regulation answers this in Article 58(2), which lists what the Commission's implementing acts must ensure.
- Providers and prospective providers. Sandboxes must be "open to any applying provider or prospective provider of an AI system who fulfils eligibility and selection criteria, which shall be transparent and fair" (Article 58(2)(a)). Authorities must tell applicants their decision within three months.
- Deployers, only in partnership. Article 58(2)(b) lets providers and prospective providers "submit applications in partnerships with deployers and other relevant third parties". A deployer acting alone has no route in, which is one more reason to settle whether you are the provider before applying. The provider versus deployer guide works through that test.
- SMEs and start-ups first. Article 62(1)(a) requires Member States to give SMEs, including start-ups, "having a registered office or a branch in the Union" priority access, to the extent they meet the eligibility conditions and selection criteria. Priority does not exclude other SMEs who also meet them.
- Any risk level. Nothing in Articles 57 or 58 limits sandboxes to high-risk systems. The definition speaks of "an innovative AI system".
What a sandbox gives you, and what it does not
The benefits and their limits sit side by side in Article 57.
| You get | Source | The limit |
|---|---|---|
| Guidance on regulatory expectations and how to meet the Regulation's requirements | Article 57(7), first subparagraph | Guidance on expectations, not a ruling that your system complies |
| Written proof of activities successfully carried out, on request | Article 57(7), second subparagraph | Evidence for conformity assessment, not a substitute for it |
| An exit report on activities, results and learning outcomes | Article 57(7) | Shared with the Commission and the Board only with your agreement, and published only if you and the authority both agree (Article 57(8)) |
| No administrative fines for infringements of the Regulation | Article 57(12) | Only while you observe the plan and terms and follow the authority's guidance in good faith |
| Free access for SMEs, including start-ups | Article 58(2)(d) | Exceptional costs may still be recovered in a fair and proportionate manner |
| Mutual recognition of participation across the Union | Article 58(2)(g) | Covers sandboxes established by a Member State or the EDPS |
The evidential value of the exit report is stated in strong but bounded terms. Article 57(7) says the exit reports and written proof "shall be taken positively into account by market surveillance authorities and notified bodies, with a view to accelerating conformity assessment procedures to a reasonable extent". The Article 43 procedure still has to be run; the conformity assessment page covers which route applies.
The fines protection is narrower than it is often described. Article 57(12) opens with liability, not immunity: participants "shall remain liable under applicable Union and national liability law for any damage inflicted on third parties as a result of the experimentation taking place in the sandbox". The bar on administrative fines that follows covers infringements of this Regulation, and extends to other Union and national law only where the authorities responsible for that law "were actively involved in the supervision" and gave guidance. If the data protection authority was not actively involved in supervising your system and gave no guidance, Article 57(12) gives no cover against fines under data protection law.
Two things a sandbox cannot do. It cannot take civil liability off the table (Article 57(12)), and it cannot keep a project running once a significant risk cannot be mitigated: Article 57(11) gives the authority power to suspend the testing or the participation, temporarily or permanently, and requires it to inform the AI Office.
One further benefit is narrow: Article 59 allows personal data lawfully collected for other purposes to be processed in the sandbox for AI systems safeguarding a "substantial public interest" in listed areas such as public health, the environment and public administration, and only where all ten conditions in Article 59(1) are met, including that non-personal data cannot do the job.
Testing in real-world conditions outside a sandbox
A sandbox is not the only lawful way to test with real people. Article 60 lets providers and prospective providers of high-risk systems listed in Annex III, or covered by the Annex I Section A legislation, test in real-world conditions outside a sandbox at any time before placing on the market or putting into service, "without prejudice to the prohibitions under Article 5". The high-risk systems guide sets out which systems fall in those categories, and the classifier gives a first answer for yours.
The conditions in Article 60(4) are cumulative. The most consequential, beyond establishment in the Union or a legal representative there (Article 60(4)(d)), are:
- A real-world testing plan submitted to, and approved by, the market surveillance authority where the testing happens. Silence for 30 days counts as approval, unless national law does not provide for tacit approval (Article 60(4)(a) and (b)).
- Registration of the testing with a Union-wide unique single identification number, with modified routes for law enforcement, migration and border systems and for Annex III point 2 critical infrastructure (Article 60(4)(c)).
- A limit of six months, extendable once by six months on prior notification with reasons (Article 60(4)(f)).
- Freely given, dated and documented informed consent under Article 61, with the narrow law enforcement exception in Article 60(4)(i).
- Outputs that "can be effectively reversed and disregarded" (Article 60(4)(k)).
Serious incidents found during testing must be reported under Article 73 (Article 60(7)), which the serious incident reporting page covers, and Article 60(9) leaves the provider "liable under applicable Union and national liability law for any damage caused in the course of their testing in real world conditions". Article 60 contains no fines protection equivalent to Article 57(12).
The Omnibus added Article 60a for AI-enabled products under the Annex I Section B legislation. It is opt-in: a Member State "may allow" such testing, through a notified framework with a mandatory agreed testing plan (Article 60a(1) to (5)). For those products, Article 2(2) applies Articles 57, 58 and 59 "only in so far as the requirements for high-risk AI systems under this Regulation have been integrated in that Union harmonisation legislation".
Sandbox, research exclusion or real-world testing: which route applies
Three provisions overlap here, and teams often reach for the wrong one.
- Article 2(6) takes outside the Regulation AI systems or models, including their output, "specifically developed and put into service for the sole purpose of scientific research and development". The word "sole" is the test: on the text, a system with a commercial purpose alongside research does not qualify.
- Article 2(8) excludes "any research, testing or development activity regarding AI systems or AI models prior to their being placed on the market or put into service", and ends: "Testing in real world conditions shall not be covered by that exclusion."
- Articles 57 to 61 then govern what Article 2(8) leaves in: real-world testing, either supervised inside a sandbox under Article 57(5) and 58(4), or outside one under Articles 60 and 61.
Read together, they give an order of questions.
- Is the system built and put into service solely for scientific research? If so, Article 2(6) takes it out of the Regulation, and a sandbox adds nothing.
- Is the work pre-market development or lab testing with no real-world testing? Article 2(8) excludes it. A sandbox is optional and mainly buys guidance and documented evidence.
- Will you test a high-risk system with real people or in real conditions before placing it on the market? Article 2(8) no longer applies. Choose between Article 60 testing, with its approval, registration and consent conditions, or a sandbox, where Article 57(5) requires the real-world testing plan to be incorporated in the sandbox plan.
- Is the system already on the market? Article 2(8) no longer helps, because it covers only activity before placing on the market or putting into service. The Commission's draft implementing act would admit such a system only if it "will be subject to substantial modification".
The implementing act is still a draft
Article 58(1) requires the Commission to adopt implementing acts on eligibility and selection, application and exit procedures, participants' terms and conditions and, since the Omnibus, governance.
The Commission published a draft for feedback on 2 December 2025, with the consultation running to 13 January 2026. The European Data Protection Supervisor records that the Commission consulted it on the draft on 16 February 2026, and adopted formal comments on 6 March 2026. As at 5 October 2026 no adopted implementing regulation on sandboxes appears on the Commission's AI Act pages.
The draft carries the disclaimer that it "has not been adopted or endorsed by the European Commission", so treat what follows as the direction of travel, not the rule:
- Eligibility would require a provider or prospective provider, or an authorised representative for one without a registered office or branch in the Union, and a system not yet placed on the market or put into service unless it will be substantially modified (draft Article 3(2)).
- Larger companies could be charged a proportionate fee, and applicants without an EU office or branch would pay a fee and need an authorised representative (draft Article 2(3) and (4)).
- The exit report would be due no later than two months after participation ends, and neither it nor the written proof would have the status or legal effect of a declaration of conformity under Article 47 (draft Article 6).
In the meantime the national statutes supply their own procedure: Germany's § 13(4) KI-MIG leaves the operating details to a ministry ordinance, and Poland's Article 91(5) leaves the competition rules to KRiBSI.
What to check before you apply
- Confirm you are the provider or prospective provider. If you are a deployer, find the provider willing to apply with you under Article 58(2)(b).
- Check whether you need a sandbox at all. Run the system through the Article 2(6) and 2(8) questions above, and through the classifier, before committing months to a sandbox plan.
- Find the competent authority and its call. Member States have until 2 August 2027, and a national statute may select participants through a competition with a published deadline for offers, as Poland's Article 94 does. The national authorities guide is the starting point.
- Check your SME status. Priority under Article 62(1)(a) and free access under Article 58(2)(d) both turn on being an SME, including a start-up, and the priority also on a registered office or branch in the Union.
- List every other regulator your system touches. Article 57(12) fines protection under other law depends on that authority having been actively involved, and Article 57(10) requires data protection authorities to be associated where personal data are processed.
- Plan for the exit report. Agree in the sandbox plan which requirements will be examined, because the exit report can only evidence what was actually tested.