AI Applications
AI Regulatory Sandboxes Under the EU AI Act: What They Are, Who Can Use Them, and the 2026 Deadline
The EU AI Act requires every member state to have a national AI regulatory sandbox operational by 2 August 2026. This article explains what Articles 57 to 63 cover, what legal protection a sandbox does and does not give you, how real-world testing differs, and what Indian startups, IT services firms and GCCs building AI for European clients should prepare now.
Admin ·
The EU AI Act requires every member state to have a national AI regulatory sandbox operational by 2 August 2026. This article explains what Articles 57 to 63 cover, what legal protection a sandbox does and does not give you, how real-world testing differs, and what Indian startups, IT services firms and GCCs building AI for European clients should prepare now.
What the AI Act actually says about sandboxes
AI regulatory sandboxes sit in Chapter VI of the EU AI Act, spread across Articles 57 to 63. Every EU member state must have at least one national AI regulatory sandbox established and operational by 2 August 2026, either on its own, jointly with other states, or by joining an existing one. A sandbox is a controlled environment set up by a competent authority where you can develop, train, test and validate an AI system for a limited period under regulatory supervision, following an agreed sandbox plan, before you put it on the market.
The point of it is not leniency. It is that the authority sits with you while you build, tells you where your system is likely to breach the Act, and gives you written proof of what you did. At the end you get an exit report describing the activities carried out and the results. That report is meant to be taken into account by market surveillance and notified bodies, so it can speed up your conformity assessment later. It does not replace it.
Small companies get specific treatment. Access has to be free of charge for SMEs and startups, apart from exceptional costs recovered fairly, and Article 62 gives them priority access provided they meet the eligibility conditions.
| Article | What it covers |
|---|---|
| 57 | National AI regulatory sandboxes, the 2 August 2026 deadline, supervision, exit reports |
| 58 | Common rules and detailed arrangements, to be set out by the Commission in an implementing act |
| 59 | Further processing of lawfully collected personal data inside a sandbox, for public interest AI, under strict conditions |
| 60 | Testing high-risk AI systems in real world conditions outside a sandbox, capped at six months and extendable once |
| 61 | Informed consent from subjects taking part in real world testing |
| 62 | Measures for SMEs and startups, including priority sandbox access and dedicated awareness and training |
| 63 | Proportionate derogations for microenterprises on parts of the quality management system |
The protection is real, but narrower than people assume
Here is the bit that gets misquoted. Article 57 says that where participants respect the sandbox plan and the terms of participation, and follow the guidance of the national competent authority in good faith, no administrative fines shall be imposed for infringements of the AI Act itself. That is a meaningful shield during a stage when your system genuinely might not be compliant yet.
Everything else stays live. Liability under other Union and national law is untouched, so GDPR, product liability and sectoral rules apply exactly as before. Data protection authorities keep their supervisory powers and are involved in running the sandbox. If your system causes harm to a third party during the sandbox, you are liable, and if you stop following the plan the authority can suspend or end your participation.
So treat a sandbox as supervised de-risking, not as an exemption. Companies that walk in expecting a free pass usually walk out annoyed.
Sandbox or real-world testing? They are not the same thing
People searching for sandboxes often actually need Article 60. A sandbox is a supervised environment set up by a regulator. Real world testing under Article 60 is you testing a high-risk system in actual conditions outside a sandbox, before placing it on the market, after registering the plan and getting authorisation from the market surveillance authority.
Real world testing has hard limits. Six months, extendable by another six with justification. You need a real world testing plan, a registered single identification number, human oversight by qualified people, informed consent from subjects under Article 61, and the ability to reverse or disregard predictions on request. Subjects can withdraw at any time without giving a reason.
One route gives you regulatory guidance while you build. The other gives you permission to run a system on real people for a fixed window. Choose based on where your risk actually is.
Where this stands right now, and why the dates keep moving
The AI Act entered into force on 1 August 2024. Prohibitions and AI literacy obligations kicked in on 2 February 2025, general purpose AI model obligations on 2 August 2025, and the bulk of the high-risk regime on 2 August 2026, the same date as the sandbox deadline. That alignment is deliberate. The sandboxes are supposed to exist before the hardest obligations bite.
Spain moved earliest, setting up its AI supervision agency and a national sandbox pilot ahead of most of Europe. Several other states have run pilots or consultations. Progress is uneven, and some countries will scrape the deadline.
Then there is the Digital Omnibus package the Commission proposed in November 2025, which floats delaying parts of the high-risk timeline and simplifying some obligations. It is a proposal, not law, and it has to go through Parliament and Council. Plan for the dates in the Act as written, and watch the omnibus rather than betting on it.
What this means if you are building AI from India
If you sell an AI product into the EU, or you build AI systems that a European client puts their name on, the AI Act reaches you. A recruitment scoring tool, a credit risk model, a medical triage feature, an exam proctoring system: all sit in Annex III high-risk territory regardless of where the code was written.
Sandbox access is a different question. These are national schemes run by national authorities, and in practice applications assume an entity established in that member state or a partner who is. If you have an EU subsidiary or a European deployer, look at the scheme in that country. If you do not, the useful move is to treat the sandbox requirements as a compliance blueprint even from outside: risk management file, data governance evidence, technical documentation, logging, human oversight design, post-market monitoring plan. Buyers in Europe are already asking for these in procurement questionnaires, well before any regulator does.
India has no equivalent statute. The India AI Governance Guidelines released by MeitY in November 2025 lean on a techno-legal approach and explicitly favour sandboxing and graded oversight rather than a hard AI law, and sector regulators such as the RBI have run sandboxes since 2019 in fintech. So the direction of travel is similar. The obligations are not.
For most Indian teams the practical gap is not legal knowledge, it is engineering discipline. Somebody has to own model documentation, evaluation evidence and monitoring inside the product team, and that person usually does not exist yet. If you want to build that capability in your team rather than hire a consultant every quarter, our AI Masterclasses and certifications run as mentor-led implementation sessions where your own use case is the working example. Students and early-career professionals eyeing AI governance and responsible AI roles, which are hiring faster than most people realise, are better served by the hands-on project route in the AI Creator Fellowship.
If you are unsure whether your product falls into the high-risk category at all, tell us what it does and who uses it, and our team will help you work out what applies before you spend money on compliance you may not need.
- Map every AI feature you ship to an AI Act risk tier, and write down why
- Check whether your European client is the provider or the deployer, because the obligations differ
- Start the technical documentation and logging now, because retrofitting them is brutal
- Track the national sandbox in the member state where your EU entity or main client sits
- Watch the Article 58 implementing act, which will set the common sandbox rules
FAQs
1. Is joining an AI regulatory sandbox mandatory under the EU AI Act?
No. Participation is voluntary for companies. The obligation falls on member states, each of which must have at least one national AI regulatory sandbox operational by 2 August 2026.
2. Does a sandbox exit report mean my AI system is compliant?
No. The exit report describes what was done and what the results were, and market surveillance authorities and notified bodies must take it into account, which can speed up conformity assessment. You still have to complete the actual conformity assessment and CE marking before placing a high-risk system on the market.
3. Can a company outside the EU join an EU AI regulatory sandbox?
Sandboxes are national schemes with national eligibility rules, and in practice they expect an entity established in that member state or the EU. A non-EU company usually participates through an EU subsidiary, an importer or a European deployer partner, so check the specific national scheme before applying.
4. What is the difference between the EU AI Act sandbox and the RBI regulatory sandbox in India?
The RBI sandbox is a sector-specific fintech scheme operating since 2019 under Indian financial regulation. The AI Act sandbox is a cross-sector environment tied to a binding AI law, with a defined fine shield under Article 57 and an exit report that feeds into conformity assessment. India currently has no statutory AI-specific sandbox, though the November 2025 India AI Governance Guidelines recommend sandboxing as an approach.
5. How long can you test a high-risk AI system in real world conditions?
Article 60 caps real world testing outside a sandbox at six months, extendable once by a further six months with justification notified to the market surveillance authority. Informed consent from test subjects is required, and they can withdraw at any time without giving a reason.
6. Will the 2 August 2026 sandbox deadline be delayed?
The deadline in the Act as adopted is 2 August 2026. The Commission's Digital Omnibus proposal of November 2025 suggests changes to parts of the high-risk timeline, but it is a proposal still going through Parliament and Council, so plan against the dates currently in law.