Skip to content
Amended. Regulation (EU) 2026/1744 entered into force 27 July 2026. See what moved →
EU AI Act ChecklistIndependent reference
Chapter VI · Articles 57–62

AI regulatory sandboxes

Sandboxes are the Regulation’s answer to “how do we innovate under this?” — and they were deferred to 2 August 2027 by the Digital Omnibus, an amendment almost absent from published coverage that focused on the high-risk date.

Arts. 57–62deferred to 2 Aug 2027 by Reg. (EU) 2026/1744
Date changed. National regulatory sandboxes were originally due by 2 August 2026. Regulation (EU) 2026/1744 moved that to 2 August 2027. If a guide you are reading gives 2026, it predates 27 July 2026. What else moved →

What a sandbox actually is

Article 57 requires member states to ensure their competent authorities establish at least one AI regulatory sandbox at national level. It is a controlled environment for developing, training, testing and validating innovative AI systems before they are placed on the market or put into service, under regulatory supervision and according to an agreed sandbox plan.

Who must provide oneEach member state, at national level. Sandboxes may be established jointly with other member states, and participation in a regional or joint sandbox can satisfy the obligation
Detailed arrangementsArticle 58, eligibility, selection, application, participation and exit
Personal dataArticle 59 permits further processing of personal data lawfully collected for other purposes, in the sandbox, for developing certain AI systems in the public interest, subject to conditions. Note that Article 59 is expressly preserved in the amended Article 2(7) alongside the new Article 4a
Testing outside a sandboxArticle 60 governs testing in real world conditions; Article 61 requires informed consent from participating subjects
SMEsArticle 62: priority access, tailored awareness raising, and conformity assessment fees reduced proportionately to development stage, size and market demand

Where this usually goes next

Three situations account for most people reading this page. Each has a different answer.

A deal is blocked on an AI questionnaire

Legal will not sign until you can evidence how AI is governed. HumanAudit’s AI Trust Package is a fixed $3,500 over five business days: a public trust page, a pre-filled SIG Lite / CAIQ / SSPA Section K questionnaire bank, and your AI inventory and classification.

How this works for AI companies →

You need ISO/IEC 42001 documentation

23 clause-mapped AIMS documents with all 38 Annex A controls pre-populated, editable and yours to keep, from $199. Or score your gaps first: 18 questions, free, no signup to begin.

Free gap assessment →
See the three tiers →

You are not sure what reaches you

Twenty minutes with the founder. No prep, no deck, straight to the person accountable for the work. If none of this applies to you, you get told that on the call.

Book a free 20-minute call →

This reference is published by HumanAudit Inc. Not a law firm, not an accredited certification body, not a registered auditor. We build documentation, your counsel interprets it, and an accredited body of your choosing certifies you. How this is funded →

What participation does and does not buy you

What it gives

  • Supervised development before market placement, with an agreed plan
  • A documented relationship with your competent authority, which is worth more in a new regime than it sounds
  • Relief from administrative fines where you respect the sandbox plan and terms and follow the authority’s guidance in good faith
  • For SMEs: priority access and reduced conformity assessment fees
  • An Article 59 route for further processing of personal data in defined public-interest cases

What it does not give

  • No exemption from the Regulation. A sandbox is supervision, not suspension
  • No relief from liability to third parties for harm caused during participation, under Union or national law
  • No presumption of conformity. That attaches only to harmonised standards cited in the Official Journal. Standards →
  • No effect on the supervisory and corrective powers of the competent authority

Verify the fines provision before you rely on it

Expert analysis. The relief from administrative fines is conditional on respecting the sandbox plan and terms and following the authority’s guidance in good faith. Those are conditions a supervisor assesses, not a status you hold. Read the current wording of Article 57 on EUR-Lex before treating it as protection.

Should you wait for one?

Practical recommendation: no. Sandboxes now open from August 2027 and the Annex III high-risk obligations apply from December 2027, roughly four months apart. A sandbox is not a route to readiness for anyone whose obligations arrive on that timetable.

Where it is genuinely useful: novel systems whose classification is genuinely uncertain, where a documented supervisory dialogue is worth more than a faster launch; and public-interest development where the Article 59 personal data route matters. For everything else, the inventory, the classification and the Article 50 fix are available today and do not need anyone’s permission.

Status labels on this page

Verified fact: The Art. 57 sandbox obligation and joint establishment; Art. 58 detailed arrangements; Art. 59 personal data processing and its preservation in the amended Art. 2(7); Arts. 60 and 61 real-world testing and informed consent; Art. 62 SME priority access and fee reduction; and the deferral to 2 August 2027 by Reg. (EU) 2026/1744.

Expert analysis: The what-it-gives / what-it-does-not table, and the recommendation not to wait for one.

Unsettled: The precise current wording of the administrative fines provision in Article 57. Verify against the consolidated text.

Next step

Nothing here waits on a sandbox

Inventory, classification, the Article 6(4) assessment and the Article 50 fix are all available now and need no supervisory permission. A sandbox opening in August 2027 is not a plan for obligations arriving in December 2027.

Not sure where you sit?

The classifier maps your system against Articles 5, 6, 50 and Annex III. Twelve questions, no email.

Run the classifier →

Frequently asked

What is an EU AI Act regulatory sandbox?

Article 57 requires member states to ensure their competent authorities establish at least one AI regulatory sandbox at national level. A sandbox provides a controlled environment for developing, training, testing and validating innovative AI systems before they are placed on the market or put into service, under regulatory supervision and according to an agreed sandbox plan. Member states may establish sandboxes jointly with other member states, and Article 58 sets out the detailed arrangements.

When will EU AI Act sandboxes be available?

The original date was 2 August 2026. Regulation (EU) 2026/1744 deferred national regulatory sandboxes to 2 August 2027. That deferral is absent from a great deal of published coverage of the Digital Omnibus, which focused on the high-risk deadline.

Do SMEs get priority access to AI regulatory sandboxes?

Article 62 requires member states to provide SMEs including start-ups with priority access to AI regulatory sandboxes to the extent they fulfil the eligibility conditions, and to provide awareness raising and information on the application of the Regulation tailored to their needs. Fees for conformity assessment are to be reduced proportionately to their development stage, size and market demand. Regulation (EU) 2026/1744 was reported to extend further relief to SMEs and small mid-caps.

Does joining a sandbox protect you from fines?

Not from liability generally. Participants remain subject to applicable Union and national liability law for harm caused during participation. The Regulation does provide that where providers respect the sandbox plan and the terms and conditions and follow in good faith the guidance given by the competent authority, no administrative fines shall be imposed for infringements of the Regulation. Verify the current wording against the consolidated text before relying on this.