Key Takeaways
- Every EU Member State must have at least one AI regulatory sandbox operational by 2 August 2027, moved back a year by the 2026 Digital Omnibus
- Spain's National AI Sandbox (Royal Decree 817/2023) is already operational
- The EU AI Office can now run a Union-level sandbox, with priority access for SMEs, startups and small mid-caps
- Participation is free for SMEs and startups under Article 58
- Sandboxes provide regulatory guidance before full market compliance requirements
What Is an AI Regulatory Sandbox?
An AI regulatory sandbox is a controlled environment where startups can develop, test, and validate innovative AI systems under regulatory supervision before facing full market compliance requirements. Think of it as a 'safe space' to work out compliance issues with direct regulator guidance.
Under Articles 57 and 58 of the EU AI Act, sandboxes serve four core purposes:
- Development and testing: Train and validate AI systems in controlled conditions
- Regulatory learning: Understand requirements with direct feedback from authorities
- Risk identification: Work with supervisors to identify and mitigate risks
- Market preparation: Build compliance readiness before full obligations apply
The AI Act Compliance Timeline: Where Sandboxes Fit
Understanding when different AI Act provisions apply helps you see how sandboxes can bridge the gap between innovation and compliance. The Act phases in over several years.
Full Implementation Timeline
| Date | Milestone | Sandbox Relevance |
|---|---|---|
| February 2, 2025 | Prohibited AI practices ban takes effect | Sandboxes can help assess if your AI falls into prohibited categories |
| August 2, 2025 | GPAI rules apply | Sandbox testing for GPAI models underway |
| August 2, 2026 | Article 50 transparency obligations apply | A sandbox can help you work out what you have to disclose |
| December 2, 2026 | Machine-readable marking of AI-generated output, for generative systems already on the market | Relevant if your product generates text, images, audio or video |
| August 2, 2027 | Every Member State must have a national sandbox operational | An obligation on Member States, not on you |
| December 2, 2027 | High-risk obligations apply to standalone Annex III systems | The date to work backward from if you are Annex III |
| August 2, 2028 | High-risk obligations apply to AI inside regulated products (Annex I) | A longer runway for embedded systems |
Why the Timeline Matters for Startups
If you're building AI systems now, you have a window:
- Now: Classify your systems and get your Article 50 disclosures right
- 2026-2027: Use a sandbox to test your approach if classification is genuinely unclear
- From December 2027: High-risk obligations apply to Annex III systems, and from August 2028 to AI inside regulated products
The sandboxes are designed to close the gap between "we're building innovative AI" and "we need to comply with comprehensive regulations we're still learning to interpret."
Where Sandboxes Stand Today
The 2026 Digital Omnibus moved the deadline for national sandboxes from 2 August 2026 to 2 August 2027. That is an obligation on Member States, not on you. It also says nothing about whether your national sandbox will have capacity when you need it.
Three routes exist:
- National sandboxes. Some already run, including Spain's under Royal Decree 817/2023. Others are still being set up. Your national competent authority publishes its own calls.
- A Union-level sandbox. The Omnibus lets the EU AI Office run a sandbox at Union level for systems under its supervision, with priority access for SMEs, startups and small mid-caps.
- Joint sandboxes. Member States may meet the obligation together, so one sandbox can cover more than one country.
Open calls and cohort dates change several times a year, so we do not list them here. Under Article 57(15) the AI Office maintains the current list of planned and existing sandboxes, and the European Commission's AI Act Service Desk points to national resources.
What You Get from Sandbox Participation
Sandbox participation provides direct regulatory guidance, risk assessment support, legal certainty documentation, and a compliance roadmap—all free for startups and SMEs.
Regulatory Guidance and Feedback
Instead of interpreting the AI Act alone, you work directly with competent authorities who:
- Review your risk classification
- Provide feedback on your conformity assessment approach
- Identify compliance gaps before they become problems
- Answer specific questions about your use case
Risk Identification and Mitigation
Article 57 specifically requires sandbox supervisors to provide guidance on:
- Identifying risks to fundamental rights
- Health and safety risks
- Environmental risks
- Risk mitigation strategies
For high-risk AI systems, this supervised risk assessment is invaluable.
Sandbox Plan and Exit Report
Every sandbox participant operates under a specific "sandbox plan" documenting objectives, testing conditions, expected outcomes, and timelines (implementation may vary by Member State). When you exit, you receive an exit report documenting your participation, findings, and compliance status—evidence of good faith compliance efforts.
Legal Certainty for Participants
Free Access, and Priority, for Smaller Companies
Article 58(6) is explicit: "Access to the AI regulatory sandboxes shall be free of charge for SMEs, including start-ups." Compare that to the cost of private compliance consulting.
The 2026 Omnibus went further. It wrote SME and small mid-cap definitions into the AI Act and gave both groups priority access to sandboxes, including the new EU-level one run by the AI Office. A small mid-cap is a company that has grown past the SME thresholds but is still not large.
The same package attached three other reliefs that follow you out of the sandbox and into the high-risk regime itself:
- Simplified technical documentation for high-risk systems, in place of the full Annex IV set
- Proportionate quality management obligations, scaled to your size
- Lower administrative fine caps than a large provider faces
Our high-risk guide covers what those obligations involve and when they apply to you.
Eligibility Requirements: Can Your Startup Participate?
Any AI provider—including prospective providers still developing systems—can apply for sandbox participation, with selection based on transparent criteria. There's no minimum company size or revenue requirement.
Who Can Apply
Article 58(2) establishes that sandboxes must be open to:
- AI providers: Companies that develop AI systems for market placement
- Prospective providers: Companies developing AI that intends to place it on market
- SMEs and startups: Explicitly mentioned as target beneficiaries
- Authorized representatives: For non-EU companies with EU market intentions
Selection Criteria
The AI Act requires selection criteria to be "transparent and fair." Common factors include:
- Innovation level: Novel AI applications
- Market readiness: Reasonable path to commercialization
- Risk profile: Systems facing compliance challenges
- Societal benefit: Positive impact potential
- Compliance commitment: Genuine intent
- Resource adequacy: Ability to participate meaningfully
Application Timeline
Article 58(2)(a) requires authorities to inform applicants of their decision within three months. Plan accordingly:
- Applications for testing in 2027: check your national authority's current call
- Cohort windows differ by Member State and change through the year
- Allow 3 months for decision plus time for sandbox plan development
How to Prepare Your Sandbox Application
A strong sandbox application demonstrates your AI system, regulatory challenges, compliance approach, and capacity to participate meaningfully.
Step 1: Document Your AI System
Create clear documentation covering:
- System description (what it does, how it works, training data)
- Intended purpose
- Technical architecture
- Risk category assessment
- Current development stage
Step 2: Identify Your Regulatory Challenges
Be specific about:
- Which AI Act provisions are unclear
- Where you're unsure about risk classification
- Technical requirements you're struggling to interpret
- Conformity assessment questions
Step 3: Propose Your Testing Approach
Outline:
- Controlled testing parameters
- Real-world testing needs
- Metrics you'd measure
- Timeline expectations
- Resources you can commit
Step 4: Prepare Supporting Materials
Have ready:
- Company registration documents
- Technical team credentials
- Existing compliance documentation
- Data protection measures (GDPR compliance)
- Funding/runway information
Step 5: Submit and Follow Up
Submit through the designated portal, track application status, respond promptly to clarification requests, and prepare for discussion meeting if selected.
Sandbox Participation: What to Expect
Sandbox participation follows a structured process: agreed plan, supervised development, regular check-ins, and documented exit.
Phase 1: Sandbox Plan Development (2-4 weeks)
After selection, you work with authorities to develop your specific sandbox plan:
- Define testing objectives and scope
- Agree on conditions
- Establish timeline and milestones
- Document expected outcomes
- Set supervision arrangements
Phase 2: Active Testing (3-6 months typical)
During the testing period:
- Develop and iterate your AI system
- Conduct agreed testing
- Receive regular guidance from supervisors
- Document all activities and findings
- Flag any issues or risks identified
Key mindset: Treat authority reviews as collaboration, not audits.
Phase 3: Exit and Reporting (2-4 weeks)
When testing concludes:
- Compile participation records
- Submit findings to authorities
- Receive exit report with compliance status
- Get recommendations for remaining compliance work
- Transition to standard market compliance
Real-World Testing Conditions
Article 58(5) permits testing outside laboratory settings under sandbox supervision, with:
- Informed consent from subjects
- Safeguards against adverse effects
- Reversibility of AI decisions where feasible
- Compliance with existing law (especially GDPR)
Sandboxes vs. Full Compliance: Strategic Considerations
Sandboxes aren't right for every startup—they're most valuable when facing genuine regulatory uncertainty or building high-risk AI.
When Sandboxes Make Sense
- High-risk AI classification: Direct guidance on conformity assessment
- Uncertain risk classification: Authoritative determination from regulators
- Novel AI applications: No precedent to follow
- Cross-border deployment: Multi-jurisdiction coordination
- Limited compliance budget: Free access, expert guidance
When Standard Compliance May Be Better
- Low-risk AI clearly: Requirements are minimal, straightforward
- Established precedent exists: Others have solved same challenge
- Very early stage: Not ready to engage meaningfully
- Tight launch timeline: Sandbox adds time
- Strong in-house expertise: May not need external guidance
The Middle Path: Monitor and Decide
- Now: Assess your AI against the risk categories and check sandbox availability in your target markets
- Late 2026: Decide whether a sandbox or direct compliance work fits your situation
- 2027: Apply if a classification question is still open
- December 2027: High-risk obligations apply regardless, and August 2028 for AI inside regulated products
Frequently Asked Questions
Are AI regulatory sandboxes free for startups?
Yes. Article 58(6) explicitly states that access shall be free of charge for SMEs, including startups. Exceptional costs may be recovered in some cases, but the baseline is free participation.
Can non-EU startups participate in EU AI sandboxes?
Yes, if you intend to place AI systems on the EU market. You'll need an authorized representative in the EU and may need to designate representatives in specific Member States.
Do I need a finished AI product to apply?
No. Sandboxes accept "prospective providers"—companies still developing AI systems. You need enough development progress to meaningfully test, but production readiness isn't required.
How long does sandbox participation last?
Typically 3-6 months, depending on the program and your testing needs. The sandbox plan you agree with authorities defines the timeline. Extensions may be possible for complex systems.
Does sandbox participation guarantee compliance?
No. Sandboxes provide guidance and a controlled environment for testing, but you still need to achieve actual compliance. The exit report documents your status and remaining work. However, participation demonstrates good faith compliance efforts.
What happens if my AI fails testing in the sandbox?
Sandbox testing is about learning and improving, not pass/fail certification. If issues emerge, you work with supervisors to address them. Serious risks to fundamental rights would halt participation, but normal compliance gaps are part of the process.
Can I sell my AI product while in the sandbox?
Generally no. Sandboxes are for pre-market testing. However, controlled real-world testing with specific users under sandbox supervision is permitted. Full commercial deployment waits until you've completed the sandbox and achieved standard compliance.
Which sandbox should I apply to: national or Union-level?
It depends on where you operate and on your national sandbox rules. If you are based in Spain with a Spanish market focus, Spain's sandbox is the most mature national option. The EU AI Office's Union-level sandbox covers systems under its own supervision and gives priority access to SMEs and startups. Check the AI Office's published list before you plan around either.
Will sandbox participation delay my market launch?
Possibly. Sandbox participation takes time (3-6 months typically). However, for complex high-risk AI, the alternative—attempting compliance independently—may take longer and carry more risk. Calculate the trade-off based on your specific situation.
What documentation do I receive from sandbox participation?
You receive an exit report documenting your participation, testing conducted, findings, compliance status, and recommendations. This serves as evidence of your compliance efforts and can be valuable in any future regulatory discussions.
Conclusion: Sandboxes as Strategic Compliance Tools
AI regulatory sandboxes represent a genuine opportunity for startups building innovative AI systems. They're not exemptions—they're supervised pathways that provide guidance, reduce uncertainty, and document your compliance efforts.
The strategic value is clearest for startups facing:
- High-risk classifications with complex conformity assessment requirements
- Regulatory uncertainty about how provisions apply to their specific systems
- Limited compliance resources that make expert guidance particularly valuable
- Cross-border intentions requiring multi-jurisdiction coordination
With some national sandboxes already operational, a Union-level sandbox now possible, and every Member State required to have a programme by 2 August 2027, the infrastructure is still being built out.
The window between now and December 2027 is when these resources are most useful. Apply early, engage properly, and use sandbox participation to settle your classification before the high-risk obligations apply.
Sources
- EU AI Act, Articles 57 and 58 (Official Journal of the European Union)
- Spanish Royal Decree 817/2023 - National AI Sandbox
- EUSAiR Project (European Union Sandboxes for AI Regulation)
- European Commission AI Act Implementation Timeline
- EU AI Act Service Desk - National Resources
- European Commission Draft Implementing Act on AI Regulatory Sandboxes (2024 Consultation)
Disclaimer: This article provides general information about EU AI Act regulatory sandboxes. It does not constitute legal advice. For advice specific to your situation, consult a qualified legal professional.
If the next question is whether to run an AI contract review or instruct a lawyer, read AI contract review or a lawyer?.
Sandbox readiness map: from eligibility to exit evidence
- Eligibility: confirm the competent sandbox, applicant role, establishment or representative requirements and selection criteria.
- Testing plan: define the system, hypotheses, safeguards, success evidence, participants and responsible owners.
- Data and rights: document the lawful basis, access controls, monitoring and response if significant risks emerge.
- Supporting agreements: align provider, deployer, testing partner, data-access, confidentiality and liability terms with the plan.
- Exit evidence: preserve the sandbox plan, testing record, authority guidance, mitigations and exit report. Participation is not a compliance certificate.
Primary source checked
Check the agreements supporting the test plan. See how Outlex supports contract review before the sandbox application or supervised test begins.
Sandboxes are one route into AI Act readiness. For the full obligation map at seed stage, read our EU AI Act compliance guide for seed-stage startups.



