EU AI Act

AI regulatory sandboxes under the EU AI Act: what Article 57 provides

Each Member State must have at least one AI regulatory sandbox operational by 2 August 2027, a date the Digital Omnibus moved back from 2 August 2026. A sandbox is supervised, time-limited testing under an agreed plan, with a good-faith protection from administrative fines and an exit report you can use in conformity assessment. Availability today varies by country.

sources

Who this applies to

Providers, especially SMEs and start-ups
Sandboxes target innovative AI systems before market placement. SMEs, start-ups and small mid-caps get priority access to the AI Office's Union-level sandbox.
Member States and competent authorities
Each Member State must ensure at least one national sandbox, alone, jointly or by joining an existing one with equivalent coverage.
Deployers and public bodies
Participation is mainly a provider matter, but public-interest AI projects may use Article 59 on further processing of personal data in a sandbox.

What a sandbox is, and what the Act says

This page rests on Article 57 as shown on the Commission AI Act Service Desk, including the Digital Omnibus amendments.

A sandbox is a controlled environment for developing, training, testing and validating innovative AI systems for a limited time before market placement, under an agreed sandbox plan. Supervised real-world testing can be part of it. The stated objectives are legal certainty, sharing best practices, innovation, evidence-based regulatory learning and faster market access, especially for SMEs, start-ups and small mid-caps.

  • Duty and date. Each Member State must make sure its competent authorities set up at least one national sandbox, operational by 2 August 2027. It can be joint with other Member States, or the State can join an existing sandbox that gives equivalent national coverage.
  • Supervision. Authorities give guidance, supervision and support and look at risks to fundamental rights, health and safety and at whether mitigation works. Data protection authorities and other relevant authorities must be involved where personal data or their remit is concerned.
  • No loophole. Sandboxes do not limit authorities' supervisory or corrective powers. An authority can suspend testing or participation if no effective mitigation is possible.

What participants get

  • Fine protection. Participants stay liable for damage to third parties. If they follow the sandbox plan, the participation terms and the authority's guidance in good faith, no administrative fines are imposed for infringements of the AI Act. The same protection extends to other laws where the relevant authorities were actively involved and gave guidance.
  • Exit report. On request, the authority provides written proof of the activities carried out and an exit report on activities, results and learning outcomes. Providers can use these in conformity assessment or market surveillance, and market surveillance authorities and notified bodies must take them positively into account.
  • Priority for smaller firms. The AI Office may set up a Union-level sandbox, new under the Omnibus, with priority access for SMEs, including start-ups, and small mid-caps.

What is verified about availability, and what is not

PointStatus as of 2026-10-06Source type
EU-wide legal deadline2 August 2027 for each Member StatePrimary (Art. 57 and Regulation 2026/1744)
Union-level AI Office sandboxProvided for by the Omnibus; check the AI Office for opening detailsPrimary (Art. 57(3a))
SpainReported as the only Member State with an operational sandbox as of August 2025; promoted by SEDIA and supported by AESIA, opened April 2025Secondary (commentary citing an EPRS document)
Other Member StatesNot verified. Check your national authorityNot verified

We do not list other national sandboxes because we could not verify them against primary sources on the date above. See commentary on the implementation gap for the Spanish example, and the Commission's governance page for the AI Office's public list when it is published.

How to prepare an application

  1. Describe the AI system, its intended purpose and the risk questions you want the regulator to examine.
  2. Document your planned risk controls: data governance, human oversight, logging and testing.
  3. Define what you will measure during the sandbox, with thresholds fixed in advance.
  4. Identify personal-data flows and involve your data protection officer early.
  5. Agree how the exit report will feed your conformity assessment.

A sandbox is also a place to test the evidence you will later hand to a notified body or market surveillance authority.

How the platform supports it

Each row maps a requirement to a platform control, the evidence artifact it produces, and the Trust & Governance Fabric facets involved. Swfte provides the controls and the evidence. You remain responsible for the decisions.

RequirementPlatform controlEvidence artifactFabric facets
A sandbox plan with defined risk controls and measuresTrust Profile defines owner, risk level, approved models, permitted systems and restricted actions up front.Trust Profile as an annex to the sandbox plan.Identity, Risk, Policy
Supervised testing with traceable behaviourFull action trace from data to model to agent to decision to outcome.Exportable test-run traces for the regulator.Traceability, Auditability
Human oversight during experimentsApproval rules and escalation; autonomy level set per experiment.Approval and escalation records.Human oversight, Access
Data minimisation for personal data used in testingClassification, masking and boundaries on what an agent can read.Data-access records and policy decisions.Data controls, Privacy

Compliance-by-design. Swfte provides the technical controls, governance mechanisms and evidence to support deployment within applicable requirements. The exact posture depends on your use case, jurisdiction, deployment and configuration. This is not legal advice.

Hosting today: customer data is stored in AWS eu-west-1 (Ireland), as stated on the trust page. EU region, in-country, dedicated and on-prem options are the platform position: what it is designed to let you do, scoped with you through a dedicated deployment engagement, not self-serve.

What this does not cover

  • Swfte does not run or operate a regulatory sandbox, and does not grant sandbox access. Sandboxes are run by authorities.
  • It does not guarantee admission, fine protection or any outcome. Protection depends on your good-faith adherence to the plan and the authority's guidance.
  • It does not tell you which Member State sandbox exists or is open today. We verified only the points in the table above.

Frequently asked questions

Are AI regulatory sandboxes mandatory for companies?

No. Member States must provide at least one sandbox by 2 August 2027, but participation is optional for providers.

Did the Digital Omnibus change the sandbox deadline?

Yes. The Member State deadline moved from 2 August 2026 to 2 August 2027. The Omnibus also added an AI Office sandbox at Union level with priority access for SMEs, start-ups and small mid-caps.

Does a sandbox protect me from fines?

If you follow the sandbox plan, the participation terms and the authority's guidance in good faith, no administrative fines are imposed for infringements of the AI Act. You remain liable for damage to third parties, and authorities keep their supervisory powers.

Which country has an operational sandbox?

Spain was reported as the only Member State with an operational sandbox as of August 2025, according to secondary commentary. We have not verified other Member States on the date above, so check your national authority.

Can a sandbox exit report be used later?

Yes. On request, the authority provides an exit report that you can use in conformity assessment or market surveillance, and authorities and notified bodies must take it positively into account.

Sources

Last verified 2026-10-06. Primary sources are EUR-Lex and European Commission pages. Items marked as secondary are commentary or trackers; check the primary text before relying on them.

Across the platform

The controls on this page are part of the Trust & Governance Fabric that runs through every layer of the Sovereign Intelligence Platform.

Build EU-first AI with the evidence already running

Start with one entry point. Add governance, in-region options and evidence as your requirements grow.

Ready to build with Swfte?

One platform for the agents, models and workflows your team ships. Free to start, no card required.