AI Guide

Regulatory Sandbox (EU AI Act): Testing AI systems under supervisory guidance

A regulatory sandbox is a supervised testing environment where companies develop and validate AI systems under real conditions before market placement, with reduced regulatory risk. Article 57 of the EU AI Act requires every member state to operate at least one national sandbox by 2 August 2026, with priority access for SMEs. Learn below how sandboxes work, what protections they offer, and how German Mittelstand companies can use them to de-risk AI projects.

Key Facts
  • Article 57 of the EU AI Act requires every EU member state to operate a national AI regulatory sandbox by 2 August 2026
  • SMEs and startups get priority access and reduced or waived fees under Article 62
  • Testing phases inside a sandbox typically run 6 months, extendable to 12 months for complex cases
  • Only 24% of German companies have actively engaged with the EU AI Act so far, according to Bitkom's 2026 AI study
  • Germany's Bundesnetzagentur operates the national sandbox under the KI-MIG implementation act, alongside state-level pilots in Bavaria, Baden-Wurttemberg, and NRW

Definition: Regulatory Sandbox (EU AI Act)

A regulatory sandbox is a supervised testing environment, run by a national authority under Article 57 of the EU AI Act, where providers develop and validate AI systems under real conditions before market placement.

Core characteristics of regulatory sandboxes

A sandbox sits between an internal AI proof of concept and a full launch: real users, with an authority monitoring risk directly.

  • Direct guidance from the national authority
  • A time-limited plan agreed in advance
  • No fines for good-faith participants within plan
  • Findings feed into the conformity assessment

Regulatory Sandbox vs. AI Proof of Concept

A proof of concept is an internal, unsupervised experiment based on a company’s own risk judgment. A sandbox is a supervised arrangement whose outcome can support a later conformity assessment, used once a validated concept needs real data or targets a high-risk AI system.

Importance of regulatory sandboxes in enterprise AI

For companies building AI in regulated areas such as HR or credit scoring, a sandbox is often the only realistic way to test with real data before full compliance applies; only 24% of German companies have engaged with the EU AI Act so far, per Bitkom’s 2026 study.

Methods and procedures for regulatory sandboxes

Entering a sandbox follows a defined sequence set by the authority.

Application and eligibility assessment

Companies apply with a description of the system, its purpose, and the risks to test, reviewed against published admission criteria.

  • Purpose and target users of the system
  • Risk classification hypothesis and data sources
  • Requested testing period and exit criteria

Supervised testing plan

Once admitted, company and authority agree a written plan covering scope, duration, checkpoints, and reporting; deviations must be reported at once.

Exit and conformity pathway

At the end of testing, the authority issues a summary report on performance and risks; it does not replace a conformity assessment but shortens the notified body’s later evidence work.

Important KPIs for regulatory sandboxes

Companies should track both process and outcome metrics.

Operational metrics

  • Application-to-admission time: 4-8 weeks
  • Testing duration: 6 months, up to 12 for complex cases
  • Reporting checkpoints: monthly or quarterly
  • Deviation incidents: target zero

Strategic metrics

2026 guidance shows SMEs with a clear plan reach market readiness faster than those without a supervised trial.

Quality metrics

A well-run engagement produces a clean audit trail: deviations logged, checkpoints met, no duplicate evidence requests later.

Risk factors and controls for regulatory sandboxes

Sandbox participation reduces certain risks but introduces others.

Scope creep beyond sandbox terms

Protection covers only what the agreed plan describes; use outside that scope removes the safe harbor.

  • Testing with data sources not listed in the plan
  • Expanding the user group beyond the pilot
  • Continuing operation past the approved window

False sense of full compliance

A sandbox report is evidence, not a certificate; high-risk systems still need a complete conformity assessment before wider deployment.

Limited sandbox capacity and long waitlists

National sandboxes have finite intake, and demand is expected to exceed supply through 2027, risking months of delay for late applicants.

Practical example

A 90-employee HR software provider in Leipzig built an AI screening tool ranking job applicants, a use case the EU AI Act classifies as high-risk. The company applied to Germany’s national sandbox, run by the Bundesnetzagentur, and over a six-month window with two partner employers, the authority flagged one data source for removal. The report became core evidence for the conformity assessment.

  • Supervised testing with real applicant data
  • Early detection of a bias risk before launch
  • A documented evidence trail reused in the assessment
  • No fines despite one deviation, corrected in good faith

Current developments and effects

Sandbox availability across the EU is still ramping up toward the August 2026 deadline.

National sandbox rollout across the EU

Every member state must have an operational sandbox by 2 August 2026, though capacity varies.

  • Germany’s KI-MIG law assigns operation to the Bundesnetzagentur
  • Bavaria, Baden-Wurttemberg, and NRW run parallel pilots
  • Smaller member states rely on shared regional arrangements

Cross-border testing frameworks

The Commission is coordinating national sandboxes so a plan validated in one state carries weight in another.

Convergence with the Digital Omnibus timeline

The Digital Omnibus postponed some Annex III obligations to December 2027, but sandbox access is available now, giving companies extra lead time.

Conclusion

Regulatory sandboxes let companies test AI against real scrutiny before facing the consequences of getting it wrong. For Mittelstand companies near a high-risk use case, a sandbox slot is often the fastest route to a defensible compliance position. As capacity fills through 2026 and 2027, early applicants reach market with more certainty than those who wait. A sandbox builds the evidence compliance requires.

Frequently Asked Questions

What is a regulatory sandbox under the EU AI Act?

A supervised testing environment run by a national authority under Article 57, letting companies develop and validate AI systems under real conditions with direct regulatory guidance before market launch.

Is a regulatory sandbox worth it for a company with under 100 employees?

Yes, SMEs get priority. Article 62 guarantees preferred access and reduced or waived fees, making sandboxes a cost-effective way to de-risk systems that would otherwise need costly legal review.

How does a regulatory sandbox affect GDPR and conformity assessment obligations?

It runs alongside both, replacing neither, though its documentation typically becomes strong evidence in a later conformity assessment.

What does it cost to join a national AI sandbox?

Costs vary by member state, but Article 62 requires reduced or waived fees for SMEs, so budget mainly for internal preparation time.

How long does a sandbox testing period typically take?

Plans typically run six months, extendable to twelve for complex systems, plus 4-8 weeks for application and admission.

Is there funding available for Mittelstand companies using a regulatory sandbox?

Some regional digitalization funding programs cover consulting and preparation costs, though the sandbox slot itself has no price.

Building better software Contact us together