LinkedInInstagramXTikTok

AI regulatory sandboxes: testing high-risk AI under supervision before 2027

Why sandboxes matter to growing companies

The EU AI Act imposes its heaviest obligations on high-risk AI systems, and it imposes them on companies of every size. A twelve-person startup building a recruitment tool faces the same conformity assessment as a multinational. That asymmetry was recognised while the Act was being drafted, and the response was the regulatory sandbox: a supervised environment where a company can develop, train, test and validate an innovative AI system before it goes to market, with a regulator alongside rather than opposite it.

Sandboxes were originally due to be operational across the Union by 2 August 2026. The Digital Omnibus on AI, Regulation (EU) 2026/1744, moved that deadline to 2 August 2027 – largely because only a small number of Member States had anything running. For businesses, the extra year is planning time. The companies that understand the mechanism now will be first through the door when the schemes open.

What an AI regulatory sandbox actually is

Article 57 requires each Member State to ensure that its competent authorities establish at least one AI regulatory sandbox at national level, operational by 2 August 2027. The obligation can be met regionally, jointly with other Member States, or by participating in an existing sandbox – so a small Member State need not build one alone.

A sandbox provides a controlled environment fostering innovation for a limited time before an AI system is placed on the market or put into service. It runs on a specific sandbox plan agreed between the participant and the competent authority, and the authority provides guidance, supervision and support to identify risks – particularly to fundamental rights, health and safety – and to agree mitigation measures. The authority retains the ability to suspend or terminate participation.

The key point is that a sandbox is not a testing lab. It is a supervised regulatory relationship. The output is not just a working system but a documented, regulator-observed compliance history.

What you get out of it

An exit report you can use

Under Article 57(7), the competent authority provides, on request, written proof of the activities successfully carried out in the sandbox and an exit report detailing the activities and their results. Providers may use that documentation to demonstrate compliance through the conformity assessment process or in market surveillance activities.

The Act goes further: the exit report and written proof must be taken positively into account by market surveillance authorities and notified bodies with a view to accelerating conformity assessment procedures to a reasonable extent. That is meaningful, but it should be read precisely. It is a duty of positive consideration, not a presumption of conformity. Sandbox participation does not certify your system; it makes the certification path shorter and better evidenced.

Protection from fines, not from liability

Article 57(12) is the provision most often misdescribed. Participants remain liable under applicable Union and national liability law for any damage inflicted on third parties as a result of the experimentation. Civil liability is fully preserved.

What the sandbox does provide is protection from administrative fines. Where the participant observes the specific sandbox plan and follows the terms, conditions and guidance of the national competent authority in good faith, no administrative fines are imposed for infringements of the AI Act. Where other authorities responsible for other Union or national law were actively involved in supervising the system and provided compliance guidance, no administrative fines are imposed under that law either.

So the shield is real, conditional and narrow: good faith, plan compliance, administrative fines only.

Priority access and reduced cost for smaller companies

Article 62 requires Member States to provide priority access to sandboxes for SMEs and start-ups established in the Union – extended by the Digital Omnibus to small mid-caps. It also requires awareness-raising and training tailored to smaller organisations, dedicated channels for advice and queries, and facilitation of SME participation in standardisation work. Article 62(2) requires that fees for third-party conformity assessment under Article 43 be reduced proportionately for SMEs and start-ups, taking account of their development stage, size, market and product complexity.

Article 63 allows microenterprises to comply with certain elements of the Article 17 quality management system in a simplified manner. The Digital Omnibus signalled that this possibility should be extended to all SMEs, including start-ups. No derogation is available from the substantive Chapter III requirements – risk management, data governance, technical documentation, logging, transparency, human oversight, accuracy and robustness all still apply.

Personal data inside a sandbox

Article 59 addresses a question that comes up immediately in practice: can you reuse personal data that was lawfully collected for another purpose to train a model inside a sandbox? The answer is a narrow yes, and only for public interest projects.

The system must be developed to safeguard a substantial public interest by a public authority or another person acting on its behalf, in listed areas including public safety and public health, environmental protection and climate, energy sustainability, transport and critical infrastructure safety and resilience, and the efficiency and quality of public administration and public services.

A long list of cumulative conditions then applies: the personal data must be necessary and the objective not achievable with anonymised, synthetic or other non-personal data; processing must occur in a functionally separate, isolated and protected environment under the participant’s control with access limited to authorised persons; the data must not be shared outside the sandbox except in line with the GDPR; no measures or decisions affecting the data subjects may result; the data must be deleted once participation ends; logs must be kept; a complete description of the process and rationale must be retained with the technical documentation; and a short summary of the project must be published on the authority’s website.

Commercial product development on repurposed customer data does not fit through this door.

Testing outside a sandbox

Article 60 provides a separate route: real-world testing of high-risk AI systems outside a sandbox. It runs on a real-world testing plan submitted to the market surveillance authority of the Member State where testing takes place, with registration in the EU database under a unique identification number. Approval can be tacit – if the authority does not respond within 30 days, the plan is taken as approved, unless national law provides otherwise.

Testing may last no longer than necessary and in any event not more than six months, extendable once by a further six months where the provider notifies the authority in advance with justification, giving a twelve-month maximum. Predictions, recommendations and decisions produced during testing must be effectively reversible and capable of being disregarded, and vulnerable groups must be protected.

Article 61 requires freely given informed consent from test subjects, obtained before participation and after proper information about the nature and objectives of the testing, its duration, the right to refuse and to withdraw at any time without detriment and without justification, and how to request reversal of decisions. Consent must be dated, documented, and a copy provided to the subject.

Where things stand in Sweden and across the EU

Spain moved first. Its sandbox, established by royal decree and operated by the Spanish AI supervisory agency, is the only fully operational AI Act sandbox and has been running a cohort of high-risk systems.

In Sweden, the government designated five national competent authorities by decision of 12 June 2026 (Fi2026/01365): Post- och telestyrelsen (PTS), Integritetsskyddsmyndigheten (IMY), Finansinspektionen, Läkemedelsverket and Swedac. PTS is the single point of contact under Article 70(2), leads a national coordination function, and holds the assignment to establish the Swedish AI regulatory sandbox. IMY supervises prohibited practices together with parts of the high-risk and transparency regimes, and the other three authorities carry sector-specific roles. Note that this is an interim assignment running to 31 December 2026. Sweden has not yet enacted its supplementary legislation, and the proposals in SOU 2025:101 — including a formally designated coordinating market surveillance authority — remain proposals. PTS has published information on the sandbox and has been consulting stakeholders on its design against the 2 August 2027 deadline. It is not yet operational.

Separately, IMY has been running the groundwork for years, including a multi-agency sandbox pilot launched in 2024 with Bolagsverket, Skatteverket and Arbetsförmedlingen, which reported in February 2026. Sweden therefore comes to this with practical experience rather than a blank page.

Elsewhere the picture is uneven. Denmark and Luxembourg have data protection-led schemes being extended toward AI Act compliance, several Member States have declared plans, and a significant number have communicated nothing. The Commission implementing act that will set detailed sandbox arrangements under Article 58 – including free access for SMEs and start-ups and a three-month decision deadline on applications – went out for feedback in December 2025 and had not been adopted at the time of writing.

Praktiskt exempel

A Swedish startup is building an AI tool that assesses eligibility for a municipal support scheme. Because it evaluates access to essential public services, it falls within Annex III. The founders have twelve months of runway and no compliance function.

Their options are to attempt a conformity assessment unaided, to abandon the public sector market, or to plan for the PTS sandbox from 2027. The third option gives them supervised development, an exit report that market surveillance authorities and notified bodies must take positively into account, priority access as a start-up, reduced conformity assessment fees, and protection from administrative fines while they act in good faith on the agreed plan.

The work that makes this viable happens now: documenting the intended purpose, building data governance, and preparing an application that is ready when the scheme opens rather than started when it does.

Vanliga misstag som företag gör

The first is believing a sandbox suspends the law. It does not. Every substantive requirement continues to apply, and third-party liability is expressly preserved.

The second is treating the exit report as a certificate. It carries weight in conformity assessment, but it is not a presumption of conformity and it does not replace the assessment.

The third is waiting for the scheme to open before preparing. Sandbox places are limited, applications are competitive, and the strongest applicants arrive with a defined intended purpose, an articulated risk profile and evidence of existing governance.

The fourth is assuming a sandbox solves the data problem. Article 59 is confined to substantial public interest projects with a demanding list of conditions.

Rekommenderade åtgärder

Classify your AI systems against Annex III now, because sandbox eligibility and priority depend on knowing what you are building and how it is classified. Register interest with the relevant national authority – in Sweden, PTS – and follow its consultations, since early engagement tends to shape both the scheme and access to it.

Confirm your SME, start-up or small mid-cap status, as it drives priority access and fee reductions. Build the documentation a sandbox application will require: intended purpose, risk profile, data governance approach and human oversight design. Where a sandbox is not the right route, consider Article 60 real-world testing, but plan for the six-month limit, the registration duty and the Article 61 consent requirements.

Vanliga frågor

Does taking part in a sandbox protect us from all penalties?

No. It protects against administrative fines under the AI Act where you observe the sandbox plan and follow the authority’s guidance in good faith, and against fines under other law where the responsible authorities were actively involved in supervision. You remain fully liable to third parties for damage caused during the experimentation.

When will the Swedish sandbox be available?

Post- och telestyrelsen was designated in June 2026 as the authority responsible for establishing it, working to the 2 August 2027 deadline set by the Digital Omnibus. It is not operational yet, and PTS has been consulting on its design. The detailed EU-level rules under Article 58 were still pending adoption at the time of writing.

Is a sandbox only for high-risk systems?

Sandboxes are aimed at innovative AI systems generally, and the Act does not restrict them to high-risk systems. In practice the value is highest for high-risk systems, because that is where the conformity assessment burden and the fine exposure sit. The Digital Omnibus also enabled the AI Office to establish a sandbox at Union level, with priority access for SMEs, start-ups and small mid-caps.

Slutsats

An AI regulatory sandbox is the closest thing the AI Act offers to a partnership with your regulator: supervised development, a documented compliance history that speeds conformity assessment, priority access and reduced fees for smaller companies, and protection from administrative fines for good-faith participants. It is not a suspension of the rules and it is not a certificate. With Member States required to have schemes running by 2 August 2027 and Sweden’s being built by PTS, the useful work is preparation. Lawgent helps startups and growing companies classify their AI systems, prepare sandbox applications, and build the governance and documentation that turns supervised testing into a genuine route to market.

Lämna ett svar

Din e-postadress kommer inte publiceras. Obligatoriska fält är märkta *


0Varukorg0,00 

Inga produkter i varukorgen.

Gå tillbaka till butiken