Skip to main content
Do Regulatory Sandboxes Actually Help You Ship?EU AI Act & GPAI
6 min readFor AI Governance Leaders

Do Regulatory Sandboxes Actually Help You Ship?

You're in a sprint planning meeting when someone asks, "Can we test this high-risk AI system on actual users before we've locked down every compliance checkbox?" The EU AI Act says yes, through regulatory sandboxes. But the follow-up question is always: "Does that actually help, or just add another layer of process?"

These questions aren't theoretical. They're coming up in team channels, compliance reviews, and roadmap planning sessions as companies try to innovate under the EU AI Act without getting stuck in regulatory limbo. Here's what you need to know.

Understanding the Context

The EU AI Act introduced regulatory sandboxes when it came into force in August 2024. The idea is to let companies develop, train, validate, and test innovative AI systems on real people for a limited period under regulatory supervision. In December 2025, the Commission launched a stakeholder consultation on draft implementing rules. Then in May 2026, the Digital Omnibus provisional agreement pushed the establishment deadline from August 2026 to August 2027.

The framework exists, but the operational details are still being hammered out. That's why governance teams are asking practical questions now, before committing resources to a sandbox application.

What's the Benefit if I'm Still Liable for Damages?

Sandboxes protect you from administrative fines if you follow national authority guidance in good faith. This is significant, as potential penalties under Article 101 can reach 3 percent of global annual turnover for certain violations.

However, you remain fully liable for third-party damages. If your system harms someone during sandbox testing, you're responsible. The sandbox doesn't create a liability shield; it creates a compliance dialogue.

The practical value? You get documentation that's usable to demonstrate compliance after market release. If a regulator questions your risk assessment or validation approach post-launch, you can point to the sandbox supervision record. It's not a get-out-of-jail-free card, but it's evidence that you didn't just wing it.

Can a 20-Person Startup Afford to Participate?

Access is supposed to be free, removing the direct cost barrier. But "free" doesn't mean "cheap" when you factor in the compliance overhead.

You'll need to prepare documentation, respond to supervisor requests, and potentially adjust your development process to align with sandbox requirements. For a small team, that's real engineering and legal time. The draft implementing law sets out common rules, but national authorities will run the actual sandboxes, and their resource requirements will vary.

One study found that sandbox participants raised significantly more capital than comparable non-participants, suggesting investors see sandbox participation as a positive signal. But correlation isn't causation, and that study predates the AI Act's specific framework.

If you're already building a high-risk system under Annex III, the sandbox might streamline your path to compliance. If not, don't join just to signal credibility.

What if the Supervisor Tells Us to Change Our Approach Mid-Development?

The sandbox lets you develop, train, validate, and test for a limited period under supervision. "Supervision" means ongoing dialogue, not a one-time approval. If your risk mitigation approach doesn't satisfy the authority, you'll need to adjust.

Would you rather discover that your bias testing framework is inadequate during a sandbox review, or during a post-market audit when you've already deployed to 100,000 users? The sandbox front-loads regulatory risk, which is uncomfortable but often cheaper than retrofitting compliance.

Document everything. If the supervisor's guidance conflicts with your original plan, you want a clear record of what changed and why. That documentation protects you if questions arise later about your design choices.

Do We Get Any Special Treatment from the AI Office?

Not directly. The AI Office's enforcement powers under Articles 91-93 apply to General-Purpose AI Model providers, not to sandbox participants. The Office can demand technical documentation, commission independent evaluations, and require specific mitigation measures, but those powers target foundation model providers, not companies testing application-layer systems in sandboxes.

Your relationship is with the national authority running the sandbox, not the AI Office. That authority reports annually to the AI Office, which helps the Commission understand how sandboxes are working in practice. But you're not getting a compliance exemption from Brussels; you're getting supervised testing at the national level.

Can Sandbox Participation Satisfy Technical Documentation Requirements Under Annex IV?

Yes, but with caveats. The AI Act explicitly states that sandbox documentation is usable to demonstrate compliance. That includes elements of your Technical Documentation under Annex IV: risk management, data governance, validation evidence.

But "usable" doesn't mean "sufficient." Annex IV requires specific elements: a general description of the AI system, detailed information about data governance, technical specifications, validation and testing procedures, and cybersecurity measures. Your sandbox work should generate much of this, but you'll still need to organize it into the required structure.

Think of the sandbox as a compliance workshop, not a compliance shortcut. You're building the evidence base you'll need for Technical Documentation, but you're not exempt from producing the actual documentation in the required format.

What if We're Building an Open-Source Model? Do We Still Need a Sandbox?

Open-source systems aren't exempt from Article 50's transparency obligations, and they're not automatically exempt from sandbox requirements if they're high-risk. Whether you need a sandbox depends on your use case and risk tier, not your licensing model.

If you're providing an open-source AI system that falls under Annex III, like a model used for employment screening or credit scoring, you're subject to the same high-risk requirements as proprietary systems. The sandbox could help you validate compliance before release, especially if you're uncertain about how to satisfy the Technical Documentation or risk management requirements for a system you're not directly deploying.

The FAQ on General-Purpose AI Models clarifies various obligations for open-source models, but those are specific to GPAI systems. For application-layer systems, your open-source status doesn't change the compliance calculus.

Is This Worth It, or Should We Just Hire a Consultant and Ship?

If you're confident in your compliance framework and have legal counsel who understands the AI Act, you might not need a sandbox. But most teams aren't there yet.

The sandbox makes sense if you're building a novel high-risk system without clear precedent, want regulatory validation before significant capital investment, or are uncertain how to interpret specific requirements for your use case.

It doesn't make sense if you're building a straightforward system with established compliance patterns, can't afford the development timeline extension, or aren't actually in a high-risk category.

The establishment deadline is August 2027. That gives you time to watch how early sandboxes operate before committing. If your development timeline allows, wait to see how the first cohort fares. If you need to ship sooner, focus on building robust Technical Documentation and risk management processes outside the sandbox framework.

Where to Go for More

The European Commission's targeted consultation on high-risk AI classification guidelines runs until 23 June 2026. If you're unsure whether your system qualifies as high-risk, that's your chance to see worked examples and provide input on the clarity of the guidance.

The AI Office's FAQ on General-Purpose AI Models covers GPAI-specific questions, including compute thresholds and systemic risk classification. If you're building on top of a foundation model, start there.

For sandbox-specific questions, track the implementing law development. The December 2025 draft sets out common rules, but national authorities will publish their own application requirements. Your first stop should be your national competent authority's guidance, not the Commission's high-level framework.

You Might Also Like