Scope - What This Guide Covers
You're responsible for securing AI systems that need to comply with the EU AI Act. This guide maps Articles 57-59 sandbox requirements to your security engineering work. It's designed for teams testing high-risk AI systems, especially if you're an SME or startup navigating compliance for the first time.
This isn't about sandbox strategy or policy design. It's a technical reference for understanding what sandboxes protect, what they don't, and how to structure your testing to generate usable compliance evidence.
Key Concepts and Definitions
AI Regulatory Sandbox: A controlled environment where you test AI systems with regulatory supervision before market release. Each EU Member State must establish at least one by 2 August 2026.
National Competent Authority: The regulatory body supervising your sandbox participation. This varies by Member State; some use data protection authorities, others are establishing dedicated AI agencies.
Administrative Fine Protection: If you follow sandbox guidance in good faith, you're protected from EU AI Act fines. You remain liable for damages under applicable liability laws.
Compliance Documentation: Evidence generated during sandbox testing that demonstrates AI Act conformity. This can reduce your downstream validation burden.
Requirements Breakdown
Article 57: Sandbox Establishment
Each Member State establishes at least one sandbox. You can participate in sandboxes from multiple Member States if your deployment spans jurisdictions.
Your Action: Identify which national competent authority governs your primary market. If you're testing cross-border systems, confirm whether joint sandboxes exist between relevant Member States.
Article 58: Operational Requirements
Personal Data Processing: You may process personal data in sandboxes for public interest projects if:
- The data is necessary for testing.
- Security controls prevent external sharing.
- Data is deleted after use.
- You document processing activities.
- You publish a summary (unless law enforcement data is involved).
Your Action: Treat sandbox data processing like a Data Protection Impact Assessment. Document necessity, implement encryption and access controls, and establish clear deletion schedules.
Reporting: National competent authorities submit annual reports to the AI Board. You don't file these directly, but your testing activities inform them.
Article 59: Financial Terms
SMEs and startups access sandboxes free of charge. National authorities may recover "fair and proportionate exceptional costs."
Your Action: Clarify cost expectations during intake. If you're quoted fees beyond basic administrative costs, verify they're exceptional and documented.
Implementation Guidance
Before Entering the Sandbox
Map Your AI System to Risk Tiers: Confirm whether you're developing a high-risk system under Annex III. Sandboxes prioritize these systems.
Prepare Technical Documentation (Annex IV): Start drafting even if incomplete. Sandboxes help refine this, but arriving with a skeleton framework accelerates guidance.
Identify Applicable Standards: If you're building a biometric system, you'll face different requirements than a hiring algorithm. Know which ISO/IEC standards apply, like 42001 for management systems or 23894 for risk management.
Establish Baseline Security Controls: Sandboxes aren't excuses to skip security. Implement Annex A Controls from ISO/IEC 42001 as your starting point.
During Sandbox Participation
Document Everything: Your testing logs, model validation evidence, risk assessments, and authority guidance become your compliance record. Structure this as you'd structure an audit file.
Engage with Testing and Experimentation Facilities (TEFs): Four sector-specific TEFs exist (agri-food, healthcare, manufacturing, smart cities). If your system fits these domains, TEFs provide infrastructure and real-world testing environments. The EU allocated over €220 million for five-year TEF operations.
Utilize European Digital Innovation Hubs (EDIHs): Over 150 EDIHs offer technical expertise and skills development. If your team lacks AI-specific validation experience, EDIHs can fill gaps.
Track Guidance Explicitly: When the national competent authority provides direction, record it verbatim. This is your administrative fine protection. If you deviate, document why.
After Sandbox Exit
Translate Testing to Conformity: Your sandbox documentation should map directly to Technical Documentation (Annex IV) requirements. Don't treat sandbox work as separate from compliance work.
Retain Evidence: Even after market release, keep sandbox records. Post-Market Surveillance and audits will reference this baseline.
Common Pitfalls
Assuming Liability Protection: You're protected from administrative fines, not from damages. If your sandbox testing harms third parties, liability laws still apply. Don't reduce security rigor just because you're in a sandbox.
Ignoring GDPR: Article 58 allows personal data processing for public interest, but you still comply with GDPR. Data minimization, purpose limitation, and security requirements remain mandatory.
Treating Sandboxes as Validation Substitutes: Sandboxes provide guidance and reduce compliance uncertainty. They don't replace model validation or independent assessment. You still need Validation Evidence.
Neglecting Cross-Border Coordination: If you're deploying in multiple Member States, confirm whether your sandbox participation transfers. Some authorities coordinate through the AI Board; others require separate entry.
Overlooking Cost Recovery Clauses: "Fair and proportionate exceptional costs" is vague. Get written cost agreements before committing resources.
Quick Reference Table
| Requirement | Article | Your Responsibility | Protection Granted |
|---|---|---|---|
| Sandbox Participation | 57 | Apply through national competent authority | Access to regulatory guidance |
| Personal Data Processing | 58(4) | Implement security controls, document necessity, delete after use | Processing for public interest testing |
| Administrative Fines | 58(2) | Follow authority guidance in good faith | Protection from EU AI Act fines |
| Liability for Damages | 58(2) | Maintain security and risk controls | None -- liability laws still apply |
| Documentation | 58(5) | Record activities, publish summary (unless law enforcement) | Compliance evidence for Technical Documentation (Annex IV) |
| SME/Startup Access | 59 | Confirm eligibility, clarify exceptional costs | Free access (with limited cost recovery) |
| Reporting | 58(6) | Provide data to national authority for annual AI Board reports | Transparency into sandbox effectiveness |
Deadline Reminder: Member States must establish sandboxes by 2 August 2026. If your target market hasn't announced its approach, engage with the national competent authority now.
EU Support Resources: Connect with EUSAiR (EU Regulatory Sandboxes for AI project), sector-specific TEFs, or your regional EDIH. These aren't optional extras; they're funded infrastructure designed to reduce your compliance burden.



