Testing the Limits: The EU's Regulatory Sandbox Framework for AI
By Avv. Filippo Bagni, PhD
July 22, 2026
1. Introduction
The EU Artificial Intelligence Act (the “AI Act”) comes into effect on 2 August 2026, including the transparency obligations and the enforcement of the General-Purpose AI Models (GPAI) regime, a deadline which is now only weeks away. The Digital Omnibus postponed other important obligations to late 2027 and 2028.[1]
In this context, alongside the well-publicized obligations for High-Risk AI systems (HRAIS) and GPAI models, one of the Act's most significant—yet least understood—tools is the AI regulatory sandbox. For companies developing or deploying AI in Europe or seeking to enter the EU market, understanding this framework is now essential.
We are still waiting for the secondary legislation under the AI Act, the implementing act [2], which is expected to be released in Q4 2026. It will provide further detail on the implementation of AI sandboxes, including selection criteria, safeguards, and infrastructure for digital and real-world testing.
2. What Is an AI Regulatory Sandbox?
An AI regulatory sandbox is a controlled environment established and supervised by a national competent authority in which innovative AI systems can be developed, trained, tested, and validated over a set period before being placed on the EU market or put into service. Although the concept originates from fintech regulation, it takes on a different form under the AI Act, where the emphasis is on regulatory learning alongside innovation.
According to Article 57 of the AI Act [3], each EU Member State must ensure that at least one AI regulatory sandbox is operational at the national level by August 2, 2027 (a date that has been postponed by the Omnibus). Participation is voluntary for businesses but highly recommended where the technology is innovative.
Importantly, a positive outcome at the end of the experimentation period does not constitute a formal attestation of conformity; however, it generates documented evidence of regulatory engagement that can be highly significant when facing market surveillance or supervisory scrutiny, almost amounting to a “presumption of conformity."
Several features of the regulatory sandbox regime deserve close attention from practitioners and their clients. First, with reference to liability, participating providers remain liable under applicable EU and national tort law for damages suffered by third parties as a result of experimentation in the sandbox. The regulatory sandbox does not create a liability shield. It does, however, protect participants from administrative fines under the AI Act where the participant observed the agreed sandbox plan and acted in good faith on the authority's guidance. Given the AI Act's substantial fine regime, this protection is meaningful. [4]
Second, with respect to personal data, providers may process personal data in sandboxes for projects serving the public interest if the data is necessary, kept secure, not shared externally, and deleted after use. This creates a structured pathway for training and testing AI on real-world data that companies cannot easily replicate outside the sandbox environment under the GDPR. [5]
Third, as to supervision and exit documentation, at the end of the trial period, the competent authority shall provide the company written documentation of the activities successfully carried out in the regulatory sandbox, as well as an “exit report” detailing these activities, their results, and the learning outcomes. Such documentation may be used by providers to demonstrate compliance through the conformity assessment process or relevant market surveillance activities. In some cases, companies have also used positive exit reports as a business card to expand their activity in Europe. [6]
Finally, access for SMEs and start-ups is free of charge: AI regulatory sandboxes improve legal certainty, support compliance, and facilitate market access, particularly for SMEs and start-ups. The AI Act explicitly requires that sandboxes include measures targeting these businesses in order to prevent the compliance infrastructure from becoming the exclusive domain of large incumbents. [7]
3. Where Things Stand: A Fragmented Landscape
As of mid-2026, several EU Member States are actively implementing their sandboxes, 4 have declared their intention to do so, and 16 have not yet communicated their plans. Spain's sandbox pilot, the only one in partnership with the European Commission, opened in 2025, hosting 12 high-risk AI systems. In December 2025, Spain's authority published guidelines to support compliance with the AI Act. [8]
At the EU level, the Commission is working to establish common rules. In 2024, the European Commission launched the “EUSAiR project," a two-year initiative funded by the Digital Europe program to support the implementation of AI regulatory sandboxes across the EU. [9] The project is currently running over 80 sandbox pilots with actual businesses to provide clear and concrete guidance to the EU Commission and the Member States.
In December 2025, the Commission launched a stakeholder consultation on its draft implementing act for the establishment, development, implementation, operation, and supervision of AI regulatory sandboxes, with the aim of adopting a binding implementing regulation. As of this writing, however, no implementing act has been formally adopted, (so that Member States have had to design their national sandboxes without binding Commission guidance.) [10]
Following the Omnibus modifications—which postponed the HRAIS obligations to fixed later dates (Dec. 2, 2027, for stand-alone Annex III systems and Aug. 2, 2028, for AI embedded in regulated products) [11]—and in the absence of Commission implementing acts, the regulatory sandbox provisions of the AI Act will take effect on August 2, 2027.
4. Practical Implications for Companies Investing in Europe.
For US companies, startups or otherwise, wishing to develop their innovative AI systems in the EU – whether HRAIS in healthcare, employment, credit, or border management or systems based on GPAI models—the sandbox framework raises concrete strategic questions. Above all, sandbox participation should be understood as an early-compliance investment. Participating companies will gain direct regulatory engagement, documented compliance evidence, and the ability to identify and address risk before market deployment. Participation also allows companies to demonstrate traceability and explainability in AI-driven decisions and to formalize human oversight and escalation pathways. [12]
Beyond compliance dialogue and free, qualified legal support within a complex regulatory framework, sandbox participation offers further benefits: a positive exit report from the sandbox carries significant reputational value in Europe, particularly for companies from outside the EU, and the process itself provides a practical, first-hand immersion in a regulatory framework that has recently undergone significant change.
The AI regulatory sandbox is not a shortcut. Participation in and exit documentation from the sandbox are not a formal declaration of conformity under the AI Act – they provide evidence of regulatory engagement and should complement, rather than replace, the full compliance stack, which includes technical documentation, risk management, human oversight, and post-market monitoring. Nevertheless, this does not diminish the practical value of the exercise. A positive outcome from the sandbox means that the relevant authority – which is the same authority that will later supervise the company – has actively reviewed and endorsed the company's approach. As it would be difficult (though not legally impossible) for that authority to contradict its own position later on, participation in the sandbox creates a de facto layer of regulatory reassurance that meaningfully reduces enforcement risk, even short of formal compliance. [13]
5. Conclusion
The months leading up to August 2, 2027, when the obligation to establish national-level sandboxes takes effect, will be formative for this framework. Once adopted, the Commission's implementing act will provide the binding framework that has so far been missing. The AI Act's approach, as set out in Article 57, is novel in requiring each Member State to act and allocate sufficient resources to the task. The AI regulatory sandbox is one of the Act's most forward-looking mechanisms and a new governance tool that is here to stay. It changes the rules of law-making by facilitating dialogue between regulators and regulated entities and gives businesses a significant opportunity to influence future regulation without resorting to regulatory capture. [14] The effectiveness with which it is implemented across the 27 Member States and at the EU level will be a key indicator of whether the AI Act succeeds as a practical governance framework rather than a merely aspirational one.
Avv. Filippo Bagni, PhD, is an attorney admitted in Italy and a research fellow at CybeRights, a Center of Excellence in Cybersecurity, Artificial Intelligence, Media Literacy, and New Technologies at the University of Florence, Italy. This publication is based on his recent book, "Sandboxing innovation. Designing regulatory sandboxes for AI and cybersecurity."[15]
Disclaimer: This publication is provided for general informational purposes only and does not constitute legal advice. Reading or relying on this material does not create an attorney-client relationship
—
[1] Hogan Lovells Cadwalader, EU legislators agree to delay for high-risk AI rules (May 7, 2026), https://www.hlc.com/en/publications/eu-legislators-agree-to-delay-for-highrisk-ai-rules.
[2] See https://digital-strategy.ec.europa.eu/en/consultations/commission-seeks-feedback-draft-implementing-act-establish-ai-regulatory-sandboxes-under-ai-act.
[3] RGPD, Article 57 - AI Regulatory Sandboxes (AI Act, Chapter VI – Measures in Support of Innovation), https://rgpd.com/ai-act/chapter-6-measures-in-support-of-innovation/article-57-ai-regulatory-sandboxes/.
[4] Id.
[5] EU Artificial Intelligence Act, AI Regulatory Sandbox Approaches: EU Member State Overview (May 2, 2025), https://artificialintelligenceact.eu/ai-regulatory-sandbox-approaches-eu-member-state-overview/.
[6] RGPD, Article 57 - AI Regulatory Sandboxes (AI Act, Chapter VI – Measures in Support of Innovation), https://rgpd.com/ai-act/chapter-6-measures-in-support-of-innovation/article-57-ai-regulatory-sandboxes/.
[7] EU Artificial Intelligence Act, AI Regulatory Sandbox Approaches: EU Member State Overview (May 2, 2025), https://artificialintelligenceact.eu/ai-regulatory-sandbox-approaches-eu-member-state-overview/.
[8] European Parliamentary Research Service (EPRS) blog, AI Regulatory Sandboxes: State of Play and Implementation Challenges (Apr. 1, 2026), https://epthinktank.eu/2026/04/01/ai-regulatory-sandboxes-state-of-play-and-implementation-challenges/.
[9] EUSAiR Project, Project Overview, https://eusair-project.eu/project-overview/.
[10] European Commission, Commission seeks feedback on draft implementing act to establish AI regulatory sandboxes under the AI Act (Dec. 2, 2025), https://digital-strategy.ec.europa.eu/en/consultations/commission-seeks-feedback-draft-implementing-act-establish-ai-regulatory-sandboxes-under-ai-act.
[11] Hogan Lovells Cadwalader, EU legislators agree to delay for high-risk AI rules (May 7, 2026), https://www.hlc.com/en/publications/eu-legislators-agree-to-delay-for-highrisk-ai-rules.
[12] Silent Eight blog, Regulatory Sandboxes and AI: The EU's Plans for 2026, (Apr. 30, 2026), https://www.silenteight.com/blog/regulatory-sandboxes-and-ai-the-eu%E2%80%99s-plans-for-2026.
[13] MedQAIR, EU Draft Rules on AI Regulatory Sandboxes (Dec. 17, 2025), https://medqair.com/regulatory-news/eu-draft-rules-ai-regulatory-sandboxes/.
[14] Data & Maatschappij (Knowledge Centre Data & Society), AI Sandboxes: Between Promises and Perils (Dec. 19, 2025), https://data-en-maatschappij.ai/en/news/ai-sandboxes-between-promises-and-perils.
[15] F. Bagni, Sandboxing Innovation: Designing Regulatory Sandboxes for AI and Cybersecurity, Wolters Kluwer, https://shop.wki.it/libri/sandboxing-innovation-designing-regulatory-sandboxes-for-ai-and-cybersecurity-s812915/.