Reglog

← Guides & analysis

EU AI Act regulatory sandboxes: what a startup can actually get, and when

· 13 min read

If you are building AI in Europe, somebody has probably told you to "get into a sandbox". The AI regulatory sandbox is the part of the EU AI Act written most directly for companies starting out with AI: a supervised space where a national authority helps you work out how the rules apply to your system before you ship it.

It is also one of the most misreported parts of the Act. The headline deadline moved, the Union-level version is new, and several of the benefits people quote are conditional in ways the summaries leave out. Here is what the text actually says, checked against the consolidated regulation on 28 September 2026.

This is an information service to help you plan, not legal advice. To see which obligations apply to your own AI use, run the obligation checker.

The short answer

Question Answer Where
Must every EU country run one? Yes — at least one national sandbox, alone or jointly with other Member States Article 57(1)
By when? 2 August 2027 (was 2 August 2026 before the Digital Omnibus) Article 57(1), as amended
Is there an EU-level sandbox? The AI Office may set one up, for systems it supervises directly Article 57(3a) — new
Who gets priority? SMEs and start-ups with a registered office or branch in the EU (national); SMEs, start-ups and small mid-caps (Union-level) Articles 62(1)(a), 57(3a)
Is it free? The implementing acts must ensure free access for SMEs and start-ups, subject to "exceptional costs" Article 58(2)(d)
Fines while inside? No administrative fines under the AI Act if you follow the plan and guidance in good faith Article 57(12)
Civil liability while inside? Unchanged — you remain liable for damage to third parties Article 57(12)
Can you test high-risk AI on real users without a sandbox? Yes for Annex III and Annex I Section A systems, under an approved real-world testing plan (Article 60); for Annex I Section B products, the AI Act route exists only where your Member State adopts a testing framework (Article 60a). Either way, sector testing rules and any legally required ethical review still apply Articles 60, 60a

What a sandbox is, legally

Article 3(55) defines an AI regulatory sandbox as "a controlled framework set up by a competent authority which offers providers or prospective providers of AI systems the possibility to develop, train, validate and test, where appropriate in real-world conditions, an innovative AI system, pursuant to a sandbox plan for a limited time under regulatory supervision."

Three words in that definition do most of the work:

  • Providers. Sandboxes are for companies that build AI (or plan to), not for companies that only use someone else's tool. Deployers can join, but as partners in a provider's application (Article 58(2)(b)). For what a deployer owes instead, see EU AI Act deployer obligations.
  • Plan. Everything runs on a written sandbox plan agreed with the authority (Article 57(5)). Most of the legal benefits below depend on sticking to it.
  • Limited time. Participation is time-boxed, "appropriate to the complexity and scale of the project", and extendable by the authority (Article 58(2)(h)).

Sandboxes are not limited to high-risk AI. Any "innovative AI system" falls within the definition, so a startup unsure whether its product is high-risk at all is a natural candidate — though access still depends on each sandbox's eligibility and selection criteria (Article 58(2)(a)). One exception: for high-risk AI in products under Annex I Section B (vehicles, aviation, rail, marine equipment, machinery), the sandbox articles (57 to 59) apply only in so far as the AI Act's high-risk requirements have been integrated into that sector's legislation (Article 2(2), as amended).

The deadline moved to 2027 — and not every official page has caught up

The original Article 57(1) required each national sandbox to be "operational by 2 August 2026." The Digital Omnibus — Regulation (EU) 2026/1744, in force since 27 July 2026 — replaced the first subparagraph of that paragraph. It now reads "operational by 2 August 2027."

That matters in two practical ways:

  1. "My country missed the deadline" is not true yet. If your Member State has no sandbox today, it is not in breach of Article 57(1) — it has until August 2027.
  2. Check the date on anything you read. On 29 September 2026 the Commission's own AI Act Service Desk page for Article 57 still displays the 2026 date, under a notice that the provision has been amended and the page not yet updated. A lot of commercial guidance repeats the old date too.

The sandbox chapter itself (Chapter VI) is not one of the parts the Omnibus deferred: it applies from the Act's general application date, 2 August 2026 (Article 113). So the rules on how sandboxes must work already apply; what runs to 2027 is the deadline for every country to have one open.

What you actually get from a sandbox

Benefit What the text says The condition
Guidance Authorities must give "guidance on regulatory expectations and how to fulfil the requirements" (Article 57(7)) —
Written proof and an exit report On request, written proof of activities completed; always, an exit report (Article 57(7)) —
Faster conformity assessment Exit reports and proof "shall be taken positively into account by market surveillance authorities and notified bodies, with a view to accelerating conformity assessment procedures to a reasonable extent" (Article 57(7)) "To a reasonable extent" — not a presumption of conformity
No AI Act administrative fines "[N]o administrative fines shall be imposed by the authorities for infringements of this Regulation" (Article 57(12)) You observe the plan and terms and "follow in good faith" the authority's guidance
No fines under other supervised law Same protection for other Union or national law, where that law's authorities were actively involved and gave guidance (Article 57(12)) Those authorities must actually be involved
A decision within three months Implementing acts must ensure applicants are told the outcome within three months (Article 58(2)(a)) Depends on the implementing acts (see below)
EU-wide effect Participation in one Member State's sandbox is to be "mutually and uniformly recognised and carries the same legal effects across the Union" (Article 58(2)(g)) Depends on the implementing acts
Reuse of personal data — narrow Article 59 adds a legal basis for processing personal data collected for other purposes in the sandbox, but only for AI developed in the substantial public interest in listed areas: public safety and health, environment, energy sustainability, transport and infrastructure resilience, public administration — and only if further cumulative safeguards are met (Article 59(1)). Other legal bases under data-protection law are unaffected (Article 59(3)) Most commercial products do not qualify

What a sandbox does not give you

  • No liability shield. Article 57(12) is explicit: participants "shall remain liable under applicable Union and national liability law for any damage inflicted on third parties."
  • No guaranteed continuation. Authorities keep their supervisory and corrective powers and can suspend testing, or your participation, if a significant risk cannot be mitigated (Article 57(11)).
  • No certificate. An exit report helps a conformity assessment; it does not replace one. For which conformity assessment route applies to a high-risk system, and whether it involves a notified body, see do you need a notified body?
  • No confidentiality waiver by default. The Commission and the AI Board may see your exit report only with your agreement; it is published only if both you and the authority explicitly agree (Article 57(8)).

The new Union-level sandbox

The Omnibus added Article 57(3a): the AI Office "may establish an AI regulatory sandbox at Union level for AI systems covered by Article 75(1)." If it does, that sandbox "shall provide priority access to SMEs, including start-ups, and SMCs."

Read the scope carefully. Article 75(1) is the list of AI systems the AI Office supervises directly — broadly, AI systems built on a general-purpose AI model where the model and the system come from the same provider or group, and AI systems that are or sit inside a very large online platform or search engine, with carve-outs for the first group (for example, AI in products under Annex I and critical infrastructure under Annex III point 2). If you build an application on top of a third party's model, you are normally not in Article 75(1), and your route is a national sandbox.

Two further points:

  • The word is "may". The Union-level sandbox is a power, not a duty, and it carries no deadline.
  • It is "without prejudice" to national sandboxes — it does not replace them.

The priority-access clause is also where the Omnibus's new small mid-cap (SMC) tier shows up: SMCs get priority at Union level, but Article 62(1)(a)'s national priority is still written for SMEs and start-ups only. For the size thresholds, see is there an SME exemption in the EU AI Act?

The rulebook is still a draft

Article 58(1) requires the Commission to adopt implementing acts setting the detailed arrangements: eligibility and selection criteria, the application and exit procedures, the terms for participants and — added by the Omnibus — sandbox governance, including data-protection supervision and national/Union coordination.

As of 28 September 2026 those implementing acts have not been adopted. The Commission published a draft for feedback on 2 December 2025 (feedback closed 13 January 2026), and EUR-Lex lists it only as a draft implementing regulation with no number. No adopted version has appeared in the Official Journal.

This is why two rows in the benefits table above say "depends on the implementing acts" (and why the "Is it free?" answer in the short answer is framed the same way). The three-month decision time, free access for SMEs and EU-wide recognition are principles the Act tells the implementing acts to ensure — they bind the Commission's drafting, and national sandboxes already operating set their own terms in the meantime. Until the implementing acts land, read the call for applications of the specific sandbox you are considering.

Testing with real users outside a sandbox

A sandbox is not the only way to test with real people. Article 60 lets providers of certain high-risk AI systems test in real-world conditions outside a sandbox, "at any time before the placing on the market or the putting into service" (Article 60(2)). The Omnibus widened its scope: it now covers systems listed in Annex III and systems covered by the Annex I Section A product legislation (toys, lifts, radio equipment, medical devices and similar — not machinery, which the Omnibus moved to Section B).

Article 60 does not replace a sector's own rules. It is without prejudice to Union or national law on real-world testing of high-risk AI systems related to products covered by Annex I, and to any ethical review required by Union or national law (Article 60(1), third subparagraph, and Article 60(3)). If you build, say, an AI-enabled medical device, any real-world-testing rules in your sector's legislation and any ethical review required by law still apply alongside the Article 60 plan. Article 60 is not the whole approval route.

The key conditions in Article 60(4):

Condition Article 60(4)
Draw up a real-world testing plan and submit it to the market surveillance authority where you test (a)
Get approval — silence for 30 days counts as approval, but where national law does not provide for tacit approval, you still need an authorisation (b)
Register the test in the EU database (special rules for law enforcement, migration, border control and critical infrastructure) (c)
Be established in the EU, or appoint a legal representative who is (d)
Test no longer than necessary, and at most six months, extendable once by six months with prior notification (f)
Obtain informed consent from test subjects under Article 61 (limited law-enforcement exception) (i)
Make sure the system's outputs "can be effectively reversed and disregarded" (k)

Article 60(1) also requires the Commission to specify the elements of the testing plan by implementing act. We found no adopted implementing act on that point in EUR-Lex as of 28 September 2026.

For AI in products under Annex I Section B (vehicles, aviation, marine equipment, rail and — since the Omnibus moved it there — machinery), the Omnibus added a separate route, Article 60a: Member States may adopt national real-world-testing frameworks and must notify the Commission before using them. It is optional for each country, and testing under it must also comply with the product's own sector legislation (Article 60a(6)). For which products sit in which section, see is your AI a "safety component"?

Should you apply?

A sandbox is most useful when three things are true:

  1. You are a provider — you build or substantially shape the AI system.
  2. Your classification is genuinely uncertain — for example, whether the Article 6(3) derogation covers your Annex III use — or you know you are high-risk and want an authority's reading of Articles 8 to 15 before the high-risk obligations apply on 2 December 2027 (Annex III) or 2 August 2028 (Annex I). See has the high-risk deadline been delayed?
  3. You can live with a written plan and supervision — the protections depend on following it.

It is usually not worth it if you only deploy third-party AI, or if your product is plainly minimal-risk and your only duties are transparency and AI literacy. In that case the obligations that matter are the Article 50 transparency rules and staff AI literacy, and no sandbox changes them.

What to do now

  1. Settle your role and risk tier first. Run the obligation checker — sandbox participation only makes sense once you know what you are being tested against.
  2. Find out who your national competent authority is, because it is the body that runs or coordinates the sandbox. See who enforces the EU AI Act?
  3. If your country has no sandbox yet, do not assume it is late. The legal deadline is 2 August 2027.
  4. If you are building a high-risk system under Annex III or Annex I Section A and need real users before then, look at Article 60 real-world testing: a plan, registration, consent, a six-month cap, and 30-day tacit approval where national law provides for it (otherwise an explicit authorisation) — plus any sector testing rules and legally required ethical review. For Annex I Section B products, check whether your Member State has adopted an Article 60a framework.
  5. Watch two Commission deliverables: the Article 58 sandbox implementing acts and the Article 60 testing-plan implementing act. Both change the practical terms.

We track those deliverables and changes to the sandbox rules. Join the waitlist and we will tell you when something that affects your company moves.

The official text is Regulation (EU) 2024/1689; the amending act is Regulation (EU) 2026/1744 (the Digital Omnibus on AI). This article is an information service to help you orient — it is not legal advice, and you should confirm how the rules apply to your own system against the official sources and, where needed, with a qualified adviser.

Frequently asked questions

When do EU countries have to have an AI regulatory sandbox?

By 2 August 2027. Article 57(1) of the AI Act originally said 2 August 2026, but the Digital Omnibus, Regulation (EU) 2026/1744, moved the date to 2 August 2027. Many guides — and, as of 29 September 2026, the Commission's own AI Act Service Desk page for Article 57 — still show the old 2026 date.

Does joining an AI regulatory sandbox protect you from fines?

Partly. Under Article 57(12), if you observe the sandbox plan and the terms of participation and follow the authority's guidance in good faith, no administrative fines may be imposed for infringements of the AI Act. You stay liable under Union and national liability law for any damage to third parties, and the authority can still suspend testing if a significant risk cannot be mitigated (Article 57(11)).

Is an AI regulatory sandbox free for startups?

The Act requires the Commission's implementing acts to ensure that access is free of charge for SMEs, including start-ups, 'without prejudice to exceptional costs that national competent authorities may recover in a fair and proportionate manner' (Article 58(2)(d)). Those implementing acts had not been adopted as of 28 September 2026 — the Commission published a draft for feedback in December 2025 — so check the terms of the specific national sandbox you apply to.

Can I test a high-risk AI system with real users without a sandbox?

It depends on which kind of high-risk system. Under Article 60, providers of Annex III high-risk systems — and, since the Digital Omnibus, of systems under Annex I Section A legislation — can test in real-world conditions outside a sandbox if they submit a real-world testing plan to the market surveillance authority, register the test, obtain informed consent and meet the other Article 60(4) conditions. Article 60 does not replace sector-specific rules on testing Annex I products or any ethical review required by law (Article 60(1) and 60(3)). The authority's silence for 30 days counts as approval, but where national law does not provide for tacit approval the test still needs an explicit authorisation, and testing is capped at six months, extendable once by six more. For products under Annex I Section B (vehicles, aviation, rail, marine equipment, machinery), Article 60 does not apply: the AI Act's real-world-testing route for them, Article 60a, exists only where your Member State adopts a testing framework and notifies it to the Commission, and the testing must also comply with that product's own sector legislation.

See which obligations apply to your company → or join the waitlist

This is an information service, not legal advice.