ISHIGHRISK AI
Analysis

What does an AI regulatory sandbox under the AI Act give you?

National AI regulatory sandboxes must be operational by 2 August 2027. Who can apply, what an exit report and Article 57(12) give you, and what they do not.

Published Regulation (EU) 2024/1689, as amended by the Digital Omnibus
In short

Article 57(1), as amended by Regulation (EU) 2026/1744, requires each Member State to have at least one national AI regulatory sandbox operational by 2 August 2027, a year later than the original 2 August 2026, and Article 57(3a) now lets the AI Office run a Union-level sandbox for systems under its Article 75(1) competence. A sandbox gives a provider or prospective provider supervised development and testing under an agreed sandbox plan, written proof and an exit report that market surveillance authorities and notified bodies must take positively into account (Article 57(7)), and protection from administrative fines under this Regulation while the plan and guidance are followed in good faith (Article 57(12)). It does not remove civil liability for damage to third parties and it does not replace conformity assessment, while SMEs, including start-ups, get free access under Article 58(2)(d) and priority access under Article 62(1)(a). The Article 58 implementing act that sets eligibility, selection and exit rules was still a draft as at 5 October 2026.

The AI regulatory sandbox under the AI Act, in one paragraph

The first thing to know about an AI regulatory sandbox under the AI Act is that the deadline for setting them up moved. Article 57(1), as amended by the Digital Omnibus, Regulation (EU) 2026/1744, requires each Member State to ensure that its competent authorities establish at least one AI regulatory sandbox at national level, "which shall be operational by 2 August 2027". The 2024 text said 2 August 2026. The Digital Omnibus page sets that change alongside the other institutional deadlines that moved.

Article 3(55) defines the sandbox as "a controlled framework set up by a competent authority which offers providers or prospective providers of AI systems the possibility to develop, train, validate and test, where appropriate in real-world conditions, an innovative AI system, pursuant to a sandbox plan for a limited time under regulatory supervision". Three words in that definition do most of the work: providers (the entry ticket), plan (the contract you agree with the authority) and limited (it ends, and you leave with documents rather than a licence).

A sandbox is not an exemption from the Regulation. Article 57(11) states that sandboxes "shall not affect the supervisory or corrective powers of the competent authorities supervising the sandboxes", and nothing in Articles 57 to 59 disapplies the Article 5 prohibitions. The page on prohibited AI practices covers what no sandbox plan can authorise.

Where sandboxes will exist, and when

Article 57 provides for four kinds of sandbox.

Level Who runs it Legal basis
National, mandatory National competent authorities, alone, jointly with other Member States, or by participating in an existing sandbox with equivalent national coverage Article 57(1)
Regional, local or cross-border, optional Competent authorities at those levels or jointly with other Member States Article 57(2)
Union institutions, bodies, offices and agencies, optional European Data Protection Supervisor Article 57(3)
Union level, optional AI Office, for AI systems covered by Article 75(1) Article 57(3a), inserted by Regulation (EU) 2026/1744

The Union-level sandbox is new and narrow. Article 75(1) covers AI systems built on a general-purpose AI model by the same provider or undertaking, with listed exceptions, and AI systems that constitute or are integrated into a designated very large online platform or search engine. That sandbox must give priority access to "SMEs, including start-ups, and SMCs". The word is "may": the text creates a power, not a duty.

2 Aug 2027 At least one national AI regulatory sandbox must be operational in each Member State, under Article 57(1) as amended by Regulation (EU) 2026/1744.

National law is filling in the detail ahead of that date. Four examples, each taken from the statute itself:

Member State Instrument What it provides
Germany KI-MIG, § 13 The Bundesnetzagentur must set up and run at least one KI-Reallabor under Articles 57 and 58, without prejudice to sandboxes run by other authorities. § 13(3) extends priority access to research institutions, universities and their spin-offs with a seat or branch in the EU.
Italy Law 132/2025, Article 20(1)(c) AgID and ACN, each within its competence, ensure the establishment and joint management of "spazi di sperimentazione" for AI systems compliant with national and Union law, consulting the Ministry of Defence on dual-use systems and the Ministry of Justice on judicial systems. The existing testing regime for AI systems used by financial institutions, under Article 36(2-bis) to (2-novies) of Decree-Law 34/2019, is preserved.
Poland Act of 3 July 2026 on AI systems, Articles 91 to 101 KRiBSI, the Commission for the Development and Security of AI, runs the sandbox through a competition. Article 91(7) sets a duration of no less than 6 and no more than 12 months; Article 93(1) makes participation free for micro, small and medium enterprises.
Spain Royal Decree 817/2023 A pilot testing environment set up in November 2023 against the then-proposed Regulation, limited to 36 months or until the Regulation applies in Spain. A forerunner, not an Article 57 sandbox.

The national authorities guide tracks the competent authority in each Member State, and the KI-MIG page covers the German Act in full.

Who can apply

The Regulation answers this in Article 58(2), which lists what the Commission's implementing acts must ensure.

  • Providers and prospective providers. Sandboxes must be "open to any applying provider or prospective provider of an AI system who fulfils eligibility and selection criteria, which shall be transparent and fair" (Article 58(2)(a)). Authorities must tell applicants their decision within three months.
  • Deployers, only in partnership. Article 58(2)(b) lets providers and prospective providers "submit applications in partnerships with deployers and other relevant third parties". A deployer acting alone has no route in, which is one more reason to settle whether you are the provider before applying. The provider versus deployer guide works through that test.
  • SMEs and start-ups first. Article 62(1)(a) requires Member States to give SMEs, including start-ups, "having a registered office or a branch in the Union" priority access, to the extent they meet the eligibility conditions and selection criteria. Priority does not exclude other SMEs who also meet them.
  • Any risk level. Nothing in Articles 57 or 58 limits sandboxes to high-risk systems. The definition speaks of "an innovative AI system".

What a sandbox gives you, and what it does not

The benefits and their limits sit side by side in Article 57.

You get Source The limit
Guidance on regulatory expectations and how to meet the Regulation's requirements Article 57(7), first subparagraph Guidance on expectations, not a ruling that your system complies
Written proof of activities successfully carried out, on request Article 57(7), second subparagraph Evidence for conformity assessment, not a substitute for it
An exit report on activities, results and learning outcomes Article 57(7) Shared with the Commission and the Board only with your agreement, and published only if you and the authority both agree (Article 57(8))
No administrative fines for infringements of the Regulation Article 57(12) Only while you observe the plan and terms and follow the authority's guidance in good faith
Free access for SMEs, including start-ups Article 58(2)(d) Exceptional costs may still be recovered in a fair and proportionate manner
Mutual recognition of participation across the Union Article 58(2)(g) Covers sandboxes established by a Member State or the EDPS

The evidential value of the exit report is stated in strong but bounded terms. Article 57(7) says the exit reports and written proof "shall be taken positively into account by market surveillance authorities and notified bodies, with a view to accelerating conformity assessment procedures to a reasonable extent". The Article 43 procedure still has to be run; the conformity assessment page covers which route applies.

The fines protection is narrower than it is often described. Article 57(12) opens with liability, not immunity: participants "shall remain liable under applicable Union and national liability law for any damage inflicted on third parties as a result of the experimentation taking place in the sandbox". The bar on administrative fines that follows covers infringements of this Regulation, and extends to other Union and national law only where the authorities responsible for that law "were actively involved in the supervision" and gave guidance. If the data protection authority was not actively involved in supervising your system and gave no guidance, Article 57(12) gives no cover against fines under data protection law.

Two things a sandbox cannot do. It cannot take civil liability off the table (Article 57(12)), and it cannot keep a project running once a significant risk cannot be mitigated: Article 57(11) gives the authority power to suspend the testing or the participation, temporarily or permanently, and requires it to inform the AI Office.

One further benefit is narrow: Article 59 allows personal data lawfully collected for other purposes to be processed in the sandbox for AI systems safeguarding a "substantial public interest" in listed areas such as public health, the environment and public administration, and only where all ten conditions in Article 59(1) are met, including that non-personal data cannot do the job.

Testing in real-world conditions outside a sandbox

A sandbox is not the only lawful way to test with real people. Article 60 lets providers and prospective providers of high-risk systems listed in Annex III, or covered by the Annex I Section A legislation, test in real-world conditions outside a sandbox at any time before placing on the market or putting into service, "without prejudice to the prohibitions under Article 5". The high-risk systems guide sets out which systems fall in those categories, and the classifier gives a first answer for yours.

The conditions in Article 60(4) are cumulative. The most consequential, beyond establishment in the Union or a legal representative there (Article 60(4)(d)), are:

  1. A real-world testing plan submitted to, and approved by, the market surveillance authority where the testing happens. Silence for 30 days counts as approval, unless national law does not provide for tacit approval (Article 60(4)(a) and (b)).
  2. Registration of the testing with a Union-wide unique single identification number, with modified routes for law enforcement, migration and border systems and for Annex III point 2 critical infrastructure (Article 60(4)(c)).
  3. A limit of six months, extendable once by six months on prior notification with reasons (Article 60(4)(f)).
  4. Freely given, dated and documented informed consent under Article 61, with the narrow law enforcement exception in Article 60(4)(i).
  5. Outputs that "can be effectively reversed and disregarded" (Article 60(4)(k)).

Serious incidents found during testing must be reported under Article 73 (Article 60(7)), which the serious incident reporting page covers, and Article 60(9) leaves the provider "liable under applicable Union and national liability law for any damage caused in the course of their testing in real world conditions". Article 60 contains no fines protection equivalent to Article 57(12).

The Omnibus added Article 60a for AI-enabled products under the Annex I Section B legislation. It is opt-in: a Member State "may allow" such testing, through a notified framework with a mandatory agreed testing plan (Article 60a(1) to (5)). For those products, Article 2(2) applies Articles 57, 58 and 59 "only in so far as the requirements for high-risk AI systems under this Regulation have been integrated in that Union harmonisation legislation".

Sandbox, research exclusion or real-world testing: which route applies

Three provisions overlap here, and teams often reach for the wrong one.

  • Article 2(6) takes outside the Regulation AI systems or models, including their output, "specifically developed and put into service for the sole purpose of scientific research and development". The word "sole" is the test: on the text, a system with a commercial purpose alongside research does not qualify.
  • Article 2(8) excludes "any research, testing or development activity regarding AI systems or AI models prior to their being placed on the market or put into service", and ends: "Testing in real world conditions shall not be covered by that exclusion."
  • Articles 57 to 61 then govern what Article 2(8) leaves in: real-world testing, either supervised inside a sandbox under Article 57(5) and 58(4), or outside one under Articles 60 and 61.

Read together, they give an order of questions.

  1. Is the system built and put into service solely for scientific research? If so, Article 2(6) takes it out of the Regulation, and a sandbox adds nothing.
  2. Is the work pre-market development or lab testing with no real-world testing? Article 2(8) excludes it. A sandbox is optional and mainly buys guidance and documented evidence.
  3. Will you test a high-risk system with real people or in real conditions before placing it on the market? Article 2(8) no longer applies. Choose between Article 60 testing, with its approval, registration and consent conditions, or a sandbox, where Article 57(5) requires the real-world testing plan to be incorporated in the sandbox plan.
  4. Is the system already on the market? Article 2(8) no longer helps, because it covers only activity before placing on the market or putting into service. The Commission's draft implementing act would admit such a system only if it "will be subject to substantial modification".

The implementing act is still a draft

Article 58(1) requires the Commission to adopt implementing acts on eligibility and selection, application and exit procedures, participants' terms and conditions and, since the Omnibus, governance.

The Commission published a draft for feedback on 2 December 2025, with the consultation running to 13 January 2026. The European Data Protection Supervisor records that the Commission consulted it on the draft on 16 February 2026, and adopted formal comments on 6 March 2026. As at 5 October 2026 no adopted implementing regulation on sandboxes appears on the Commission's AI Act pages.

The draft carries the disclaimer that it "has not been adopted or endorsed by the European Commission", so treat what follows as the direction of travel, not the rule:

  • Eligibility would require a provider or prospective provider, or an authorised representative for one without a registered office or branch in the Union, and a system not yet placed on the market or put into service unless it will be substantially modified (draft Article 3(2)).
  • Larger companies could be charged a proportionate fee, and applicants without an EU office or branch would pay a fee and need an authorised representative (draft Article 2(3) and (4)).
  • The exit report would be due no later than two months after participation ends, and neither it nor the written proof would have the status or legal effect of a declaration of conformity under Article 47 (draft Article 6).

In the meantime the national statutes supply their own procedure: Germany's § 13(4) KI-MIG leaves the operating details to a ministry ordinance, and Poland's Article 91(5) leaves the competition rules to KRiBSI.

What to check before you apply

  1. Confirm you are the provider or prospective provider. If you are a deployer, find the provider willing to apply with you under Article 58(2)(b).
  2. Check whether you need a sandbox at all. Run the system through the Article 2(6) and 2(8) questions above, and through the classifier, before committing months to a sandbox plan.
  3. Find the competent authority and its call. Member States have until 2 August 2027, and a national statute may select participants through a competition with a published deadline for offers, as Poland's Article 94 does. The national authorities guide is the starting point.
  4. Check your SME status. Priority under Article 62(1)(a) and free access under Article 58(2)(d) both turn on being an SME, including a start-up, and the priority also on a registered office or branch in the Union.
  5. List every other regulator your system touches. Article 57(12) fines protection under other law depends on that authority having been actively involved, and Article 57(10) requires data protection authorities to be associated where personal data are processed.
  6. Plan for the exit report. Agree in the sandbox plan which requirements will be examined, because the exit report can only evidence what was actually tested.

Check your own system

The free classifier walks the same tests in order and tells you which of them your system actually trips, with the article each answer rests on.

Run the triage →

Frequently asked questions

When do AI regulatory sandboxes have to be ready under the AI Act?

By 2 August 2027. Article 57(1), as amended by Regulation (EU) 2026/1744, requires Member States to ensure their competent authorities establish at least one AI regulatory sandbox at national level "which shall be operational by 2 August 2027". The original 2024 text set 2 August 2026. A Member State may meet the duty jointly with others, or by participating in an existing sandbox that gives equivalent national coverage.

Who can apply to an AI regulatory sandbox?

Providers and prospective providers of AI systems. Article 58(2)(a) requires sandboxes to be open to "any applying provider or prospective provider of an AI system" who meets transparent and fair eligibility and selection criteria, and Article 58(2)(b) lets them apply in partnership with deployers and other third parties. A deployer has no standalone route in. SMEs and start-ups with a registered office or branch in the Union get priority access under Article 62(1)(a), provided they meet the criteria.

Does taking part in a sandbox protect you from AI Act fines?

Only from administrative fines, and only on conditions. Article 57(12) says that where prospective providers "observe the specific plan and the terms and conditions for their participation and follow in good faith the guidance given by the national competent authority, no administrative fines shall be imposed by the authorities for infringements of this Regulation". The same paragraph keeps providers liable under Union and national liability law for damage caused to third parties by the experimentation, and Article 57(11) lets the authority suspend the testing or the participation where no effective mitigation of a significant risk is possible.

Is a sandbox exit report the same as a conformity assessment?

No. Under Article 57(7) providers may use the written proof and the exit report to demonstrate compliance through the conformity assessment process or market surveillance, and market surveillance authorities and notified bodies must take them "positively into account" with a view to accelerating conformity assessment "to a reasonable extent". The assessment under Article 43 still has to be done. The Commission's draft implementing act states that neither document has the status or legal effect of an Article 47 declaration of conformity.

Is sandbox access free for start-ups?

For SMEs, including start-ups, yes, subject to exceptional costs. Article 58(2)(d) requires the implementing acts to ensure access is "free of charge for SMEs, including start-ups, without prejudice to exceptional costs that national competent authorities may recover in a fair and proportionate manner". The Regulation does not set fees for larger companies; national law and the implementing act do that. Poland's Act of 3 July 2026, for example, makes participation free for micro, small and medium enterprises and caps fees for others.

Do I need a sandbox to test a high-risk AI system with real users?

No. Article 60 allows providers and prospective providers of Annex III and Annex I Section A high-risk systems to test in real-world conditions outside a sandbox, but only on the conditions in Article 60(4): a real-world testing plan approved by the market surveillance authority (tacitly after 30 days where national law allows), registration, informed consent under Article 61, a six-month limit extendable once, and effective oversight. Testing in real-world conditions is not covered by the Article 2(8) research exclusion.

This article is analysis, not legal advice. It reflects Regulation (EU) 2024/1689 as amended by the Digital Omnibus, Regulation (EU) 2026/1744, published in the Official Journal on 24 July 2026 and in force since 27 July 2026, as that text stood at the last site review on 5 October 2026. Final classification for ambiguous cases needs qualified counsel.