← Back to all articles
Insights

EU AI Act Article 57: Your Plain-English Guide to AI Regulatory Sandboxes

Generated image

If you are building an AI system that touches a regulated domain - healthcare diagnostics, credit scoring, recruitment, biometrics - you have probably wondered how you are supposed to prove compliance before you have a product on the market. That is exactly the problem AI regulatory sandboxes are designed to solve.

Article 57 of the EU AI Act requires every member state to ensure its competent authorities establish at least one AI regulatory sandbox at national level, operational by 2 August 2026. The deadline is now here. This guide explains what sandboxes are, what they give you, and how to get into one.


What Is an AI Regulatory Sandbox?

A sandbox is a controlled environment in which you can develop, train, test, and validate an innovative AI system under direct regulatory supervision - before you place it on the market or put it into service. Participation runs for a limited time under an agreed sandbox plan negotiated between you and the competent authority.

AI regulatory sandboxes create controlled environments where AI systems can be developed and tested with regulatory guidance before market release. They improve legal certainty, support compliance, allow for processing of personal data, and facilitate market access for SMEs and startups.

Think of it as a structured dialogue with your regulator, not a free pass. You agree a plan, you test under supervision, and you come out the other side with documented evidence of what you did and what you learned.

What the law actually says

AI regulatory sandboxes established under Article 57 shall provide for a controlled environment that fosters innovation and facilitates the development, training, testing and validation of innovative AI systems for a limited time before their being placed on the market or put into service pursuant to a specific sandbox plan agreed between the providers or prospective providers and the national competent authority.

The regulator does not just observe - it guides. Competent authorities shall provide providers and prospective providers participating in the AI regulatory sandbox with guidance on regulatory expectations and how to fulfil the requirements and obligations set out in the Regulation. Upon request, the competent authority shall provide a written proof of the activities successfully carried out in the sandbox. The competent authority shall also provide an exit report detailing the activities carried out in the sandbox and the related results and learning outcomes.

That exit report is not just a certificate. Providers may use such documentation to demonstrate their compliance with the Regulation through the conformity assessment process or relevant market surveillance activities. Exit reports and written proof provided by the national competent authority shall be taken positively into account by market surveillance authorities and notified bodies, with a view to accelerating conformity assessment.


Why Sandboxes Exist: Legal Certainty and Regulatory Learning

The EU AI Act has a dual objective. It wants to protect people from harmful AI, but it also wants Europe to be a place where AI innovation can happen. Sandboxes are the mechanism that holds those two goals together.

Sandboxes aim to foster innovation, enhance legal certainty for innovators, and facilitate regulatory learning for competent authorities. That last point matters: regulators learn too. The sandbox is not a one-way inspection - it is a structured experiment that shapes how the rules are interpreted and applied.

The AI regulatory sandboxes aim to improve legal certainty to achieve regulatory compliance, support sharing of best practices through fostering cooperation, innovation and competitiveness, contribute to evidence-based regulatory learning and speed up access to the single market.

There is also a data angle that is easy to miss. Providers may process personal data in sandboxes for projects serving the public interest if the data is necessary, kept secure, not shared externally, and deleted after use. For teams building AI in healthcare, social services, or public administration, this is a significant practical benefit - it opens up real-world data for development that would otherwise be inaccessible.


What Sandboxes Mean for SMEs and Startups

This is where the AI Act is genuinely generous to smaller innovators. The law does not treat sandboxes as a nice-to-have for large incumbents - it explicitly prioritises access for SMEs and startups.

The EU is asking member states to support small and medium-sized businesses (SMEs), including start-ups, in understanding and complying with new AI regulations. This includes giving these businesses priority access to AI regulatory sandboxes, providing training on the new rules, and offering advice through dedicated communication channels.

The key provisions, in plain English:

  • Priority access. Member States must give EU-registered SMEs and startups priority access to their national AI regulatory sandboxes, provided you meet the eligibility conditions. This doesn't exclude other companies from applying - it means you move up the queue when capacity is limited.
  • Free of charge. Access to the AI regulatory sandboxes is free of charge for SMEs, including start-ups, without prejudice to exceptional costs that national competent authorities may recover in a fair and proportionate manner.
  • Market access by design. Article 57(9)(e) requires national AI sandboxes to facilitate and accelerate access to the Union market in particular when the AI system is provided by an SME or startup. This is a design requirement for how sandbox programmes must operate - not just an administrative preference.
  • Fine protection for good-faith participants. The documentation from participating in a sandbox can be used to demonstrate compliance with the AI Act. Further, providers will not face administrative fines for infringements of the Act, as long as they follow the guidance of the national competent authority.

One important caveat: providers remain liable for damages to third parties caused by experimentation with AI systems in a sandbox. The sandbox is not a liability shield - it is a compliance shield.

lightbulb Tip

Cross-border access is allowed. A startup registered in one member state can apply to a sandbox in another. If your home country's sandbox is not yet open, or if another state's sandbox covers your sector better, you are not locked out. Check what is available across the EU before assuming you have to wait for your own national authority.


How the Sandbox Structure Works: Flexibility Built In

The law gives member states considerable flexibility in how they set up their sandboxes, which is both a feature and a complication.

Article 57 allows a sandbox to be established jointly with the competent authorities of other member states, and the obligation can also be met by participating in an existing sandbox in so far as that participation provides an equivalent level of national coverage. Additional AI regulatory sandboxes at regional or local level, or established jointly with the competent authorities of other Member States, may also be established.

The AI Act gives Member States considerable flexibility in designing their regulatory sandboxes. Some Member States are creating centralised approaches with dedicated AI agencies, while others are adopting decentralised models that leverage existing regulatory bodies.

Generally, the sandbox application process involves periodic (cohort-based), continuous (on-tap) or hybrid admission methods. Unlike other sandboxes, such as the European Blockchain Regulatory Sandbox, the AI Act does not explicitly define admission intervals. Instead, it allows national authorities the flexibility to establish their own admission frameworks, adapting to the needs of different AI ecosystems.

In practice, this means the experience of applying to a sandbox in Germany will look different from applying in Spain or the Netherlands. The core legal protections are the same; the process, timeline, and sector focus will vary.


Spain and AESIA: The Worked Example

If you want to understand what a functioning AI regulatory sandbox looks like in practice, Spain is the place to look. It is the EU's front-runner - by a significant margin.

Spain launched Europe's first AI regulatory sandbox under Royal Decree 817/2023, in force since November 2023, operated by AESIA (Agencia Española de Supervisión de la Inteligencia Artificial), which was established by Royal Decree 729/2023.

Spain is among the most advanced EU Member States on AI Act implementation in 2026. AESIA, headquartered in A Coruña, became the competent national authority in 2024 and runs Europe's first operational AI regulatory sandbox.

What AESIA's sandbox has done so far

In this sandbox, high-level training and public consulting services have been provided to twelve high-risk AI systems from Spanish companies selected to be part of the project and operating in six different sectors: essential services, biometrics, employment, critical infrastructure, machinery and healthcare products.

By 2026, Spain's AESIA sandbox had processed more than 20 AI systems end-to-end across multiple cohorts. By mid-2026 more than 20 AI systems had been processed through the programme end-to-end, across sectors including finance, healthcare, education, and employment management.

The sandbox also produced something valuable for the whole EU ecosystem: the 16 guidelines published are the result of the work, learning and experience of this regulatory sandbox and will serve to support other companies that develop, market or deploy AI systems, guiding them in compliance, implementation and actual application of the regulations.

While most member states are still designating authorities and sorting out institutional structures, AESIA has already published 16 detailed compliance guides, selected 12 sandbox projects, and built an operational enforcement apparatus. Even if you do not operate in Spain, AESIA's published guidance is worth reading - it is the most detailed official interpretation of EU AI Act obligations currently available anywhere in the EU.

How applying to AESIA works in practice

Applications are submitted to AESIA directly at aesia.digital.gob.es. Sandbox participation agreements set out the specific testing parameters, the data access and confidentiality rules, and the timeline for the testing period.

For high-risk system development serving the Spanish or EU market, the sandbox offers direct AESIA guidance, early compliance validation, reduced regulatory uncertainty, and input into emerging best practice. The current cohort of twelve projects runs through 2026; future intake calls will be announced by AESIA.

Important: the AESIA model is Spain-specific. Exact figures, cohort timelines, sector focus, and application processes will differ in other member states. Use Spain as a reference point for what a mature sandbox looks like - not as a template for what you will find in your own jurisdiction.

Isometric illustration of a modern regulatory office with a glass-walled testing room. Inside the room, a small startup team works at laptops and whiteboards showing AI system diagrams. Outside the glass, a regulator reviews documents at a desk. Clean, professional atmosphere with soft natural light.

The Uneven Roll-Out: What to Expect Across Member States

Here is the honest picture: progress across the EU has been uneven, and the August 2026 deadline has exposed that gap sharply.

The AI Act obliges Member States to establish, or participate in, at least one AI regulatory sandbox. These are controlled environments in which AI systems' compliance with the AI Act can be tested. EU-level entities coordinate and assist Member States in their obligations. However, researchers have identified design, fragmentation and timing challenges.

In May 2026, the European Parliament and the Council of the EU reached a provisional agreement on the Digital Omnibus, pushing the deadline for member states to establish sandboxes from August 2026 to August 2027 - at a point when only one of the EU's 27 member states had an operational sandbox. That a one-year extension was necessary even before the framework had been meaningfully tested speaks to how many design questions remain unresolved.

The logistical and design challenge presented by Article 57(1)'s ambitious deadline will undoubtedly be exacerbated by the level of discretion given to Member States in operationalising their sandboxes when combined with a knowledge deficit around AI regulatory sandboxes as a new type of regulatory instrument while coordinated EU-level guidance is awaited. There is real potential for quite divergent approaches and priorities being taken by Member States as they make regulatory design choices.

To fully capture the potential benefits, sandbox design and implementation must address significant challenges, including an unclear participation scope, uneven resources, potential bureaucratic obstacles, and transparency concerns.

The EU is working to address this. One of the key initiatives is the EU Regulatory Sandboxes for AI (EUSAiR), a two-year project funded by the European Union's Digital Europe programme working in cooperation with the AI Office. EUSAiR aims to support the implementation of AI regulatory sandboxes by developing common frameworks, enhancing technical and legal capacities, and promoting collaboration among Member States. It aims to provide broad access to sandboxes for AI innovators, especially SMEs and startups, by lowering compliance costs and easing entry barriers to the market.

EU AI Act Sandbox Readiness: Illustrative State of Play (mid-2026)

Should You Apply? A Practical Decision Guide

Not every AI system needs a sandbox. Here is how to think about it.

Sandboxes are most valuable if you are:

  • Developing a high-risk AI system under Annex III (recruitment tools, credit scoring, medical devices, biometric systems, critical infrastructure, etc.)
  • Uncertain about your risk classification and want a documented regulatory view before committing to a conformity assessment pathway
  • Building AI that will process personal data in ways that are hard to justify under GDPR alone, and where the public-interest data processing provisions in Article 59 could help
  • An SME or startup that wants to build a compliance record and reduce enforcement risk before market launch
  • Seeking investor confidence - documented regulator engagement is increasingly a due diligence signal

Sandboxes are probably not for you if you are:

  • Deploying a third-party AI system (you are a deployer, not a provider - the sandbox is aimed at providers)
  • Building a minimal-risk system with no Annex III exposure
  • A large provider with an established conformity assessment programme already underway

How to Prepare: Five Steps Before You Apply

Assuming a sandbox is open in your jurisdiction (or you are planning ahead), here is how to get ready.

1
Classify your system

Before you can write a sandbox plan, you need a clear view of your system's risk tier. Work through the Annex III categories and document your reasoning. If you are uncertain, that uncertainty is itself a reason to apply — regulators can help you resolve it.

2
Map your compliance gaps

Identify which AI Act obligations you cannot yet demonstrate compliance with: technical documentation, risk management system, data governance, human oversight measures, logging. These gaps are what the sandbox is designed to help you close.

3
Draft a sandbox plan

Most sandbox applications require a plan describing your system, its intended use, the testing you want to carry out, the data you will use, the risks you have identified, and the compliance outcomes you are aiming for. The more specific this is, the stronger your application.

4
Identify your national authority and check the timeline

Find out whether your member state's sandbox is operational, when the next cohort opens, and what the eligibility criteria are. If your state's sandbox is not yet live, check whether you can apply to another member state's sandbox. Monitor AESIA's published guidance regardless — it is the most detailed official interpretation available.

5
Engage early and document everything

Regulators in sandbox programmes are generally more accessible than in normal enforcement contexts. Use pre-application meetings where they are offered. Document every interaction. The exit report and written proof you receive at the end are compliance assets — treat the whole process as evidence-building.

lightbulb Tip

Free tools on AI Act Navigator:

  • Risk-Tier Classifier — answer a short questionnaire and get a provisional tier assessment for your AI system, with a plain-English rationale you can share with stakeholders.
  • Obligations Checker — once you know your risk tier, this maps every relevant obligation to practical compliance steps for providers and deployers.
  • The AI Act Brief — our free newsletter tracks sandbox openings, authority designations, and implementation updates across all 27 member states.

The Bottom Line

AI regulatory sandboxes are one of the most practically useful provisions in the EU AI Act for innovators - and one of the most underused, partly because so few were operational until recently. That is changing.

The Digital Omnibus provisional agreement reached in May 2026 extended the sandbox establishment deadline from August 2026 to August 2027, reflecting the reality that only one member state had a fully operational sandbox at the original deadline. That extension gives more states time to get their sandboxes running - and gives you time to prepare a strong application.

Spain's AESIA has shown what is possible: a functioning sandbox that has processed real high-risk systems, produced public guidance, and given participating companies a documented compliance record. Other member states are building toward the same model, at varying speeds.

If you are building a high-risk AI system and you qualify as an SME or startup, the law has specifically reserved a place for you at the front of the queue. The sandbox is free, the regulator is there to help you, and the exit documentation can accelerate your conformity assessment. The question is not really whether to apply - it is whether you are ready when the door opens.

This post is for informational purposes only and does not constitute legal advice. Consult qualified legal counsel for advice specific to your organisation's situation.