EU AI Act Regulatory Sandboxes for Startups Explained

This page explains what an AI regulatory sandbox under Articles 57 to 62 of the EU AI Act actually is, who can get into one, what legal relief you receive in exchange for the paperwork, and how to decide whether a 20 to 500 person company shipping an AI product should spend time on it.

What the Act says

Article 57 obliges every Member State to ensure that at least one AI regulatory sandbox is established at national level and operational. A Member State can satisfy this by setting one up alone, jointly with other Member States, or by participating in an existing sandbox. The sandbox is a controlled environment, run by the national competent authority, in which an innovative AI system can be developed, trained, tested and validated for a limited period before it is placed on the market or put into service, under a sandbox plan agreed in advance between the participant and the authority.

The authority provides guidance, supervision and support, identifies risks to health, safety and fundamental rights during the process, and keeps its supervisory and corrective powers throughout, including the power to suspend testing. On request, the authority issues written proof of the activities carried out successfully and an exit report. Those documents can be taken into account by market surveillance authorities and notified bodies to speed up a later conformity assessment.

The relief that matters commercially is in Article 57(12). Where a participant complies with the agreed sandbox plan and follows the authority's guidance in good faith, no administrative fines are imposed for infringements of the Regulation in respect of the sandboxed activity. Where other authorities supervising other Union law were involved in the sandbox and gave guidance, the same protection extends to that law. Civil liability is untouched. If your system harms someone, you are still liable under national and Union liability rules.

Article 58 directs the Commission to adopt implementing acts setting the detailed arrangements for sandboxes, including eligibility and selection criteria, application and participation procedures, and the terms on which access is free of charge for SMEs and start-ups, apart from exceptional costs that authorities may recover in a fair and proportionate way.

Article 59 is the sleeper provision. It permits further processing of personal data that was lawfully collected for other purposes, solely for developing, training and testing certain AI systems in the sandbox, where the system serves a substantial public interest in an area such as public safety and health, environmental protection, energy sustainability, transport and infrastructure, or the efficiency of public administration. The conditions are strict: a functionally separate, isolated and protected processing environment, no transmission of the data outside that environment, no decisions affecting the data subjects, deletion once participation ends, logs kept for the duration of participation, and a published summary of the processing. If your product is not in one of those public interest domains, this gate does not open for you.

Articles 60 and 61 cover something different that is often confused with sandboxes: testing high-risk systems in real world conditions outside a sandbox. That route requires a real world testing plan submitted to the market surveillance authority, registration in the EU database with a single identification number, a testing period capped at six months and extendable once by a further six months, informed consent from test subjects under Article 61, a right to withdraw without detriment, and reporting of serious incidents.

Article 62 is the start-up clause. National authorities must give SMEs and start-ups with a registered office or branch in the Union priority access to sandboxes where they meet the eligibility conditions, run awareness raising and training on the Regulation, and open dedicated communication channels. Conformity assessment fees charged by notified bodies must be reduced proportionally to company size, development stage and market demand. Article 63 separately allows microenterprises to satisfy certain elements of the quality management system in a simplified manner.

Who this applies to

Sandbox participation under Article 57 is for providers and prospective providers, the party that develops an AI system and places it on the market or puts it into service under its own name or trade mark. If you build and sell the model or system, that is you. A deployer, the party using an AI system under its own authority, cannot apply on its own, but deployers and prospective deployers can take part in real world testing under Article 60 in partnership with the provider. That partnership route is the practical one for a vendor that needs live operational data from a customer environment.

Sandboxes are not restricted to high-risk systems, but in practice the queue is dominated by teams with Annex III exposure in employment, education, credit, insurance pricing, essential services and law enforcement, because those are the teams facing a conformity assessment they have never done before.

What participation actually requires

  • An application to the national competent authority covering the system, its intended purpose, the development stage and the specific regulatory questions you want resolved.
  • A sandbox plan agreed with the authority, setting objectives, test conditions, duration, milestones and the mitigation measures you will apply if a risk to health, safety or fundamental rights appears.
  • Genuine disclosure. You are showing a regulator your training data provenance, your evaluation results and your failure modes. Anything you would rather not explain will be explained.
  • Engineering time from people who are also shipping. Expect months, not weeks, and expect the authority to ask for evidence you do not currently generate.
  • Acceptance that the authority can suspend your testing if significant risk emerges.

The dates that bind

DateWhat happens
2 February 2025Article 5 prohibited practices apply.
2 August 2026Deadline for Member States to have at least one national sandbox operational under Article 57. Enforcement powers, Article 53 GPAI obligations and Article 50 transparency duties are all in force.
2 December 2027Annex III standalone high-risk obligations apply, as extended by the Digital Omnibus provisional agreement of May 2026, still pending formal adoption. 419 days away.
2 August 2028Annex I embedded high-risk obligations apply.

The sandbox deadline has passed, and national rollout is uneven. Spain moved earliest with a pilot that predates the Regulation. Several other Member States have published frameworks without running cohorts at volume. Treat capacity as scarce and do not assume a slot is available in your country this quarter. The Digital Omnibus changes the Annex III date, not the sandbox regime.

Is it worth it

Be honest about what you are buying. You are buying three things: documented regulatory guidance you can show to a notified body, an exit report that speeds up conformity assessment, and protection from administrative fines for the sandboxed activity while you follow the plan. You are not buying an exemption from the Regulation, a faster CE marking by right, or any shield against civil claims.

It is worth pursuing if you have a clear Annex III classification, a novel technical approach where the correct interpretation of Articles 9 to 15 is genuinely contested, and a product roadmap that can absorb a supervised testing period before December 2027. It is usually not worth pursuing if your classification is settled, your obligations are the ordinary ones, or you are still deciding whether you are in scope at all. In that case the time is better spent building the technical documentation you will need regardless.

What to do next

  1. Settle your classification first. Decide whether you are a provider or a deployer for each system, and whether any system falls under Annex III. A sandbox application with an unclear classification will be sent back.
  2. Check your national competent authority's published sandbox status, eligibility criteria and application window. If no cohort is open, register interest and ask for the expected date rather than waiting.
  3. Write the two or three specific regulatory questions you want answered, for example how your human oversight design satisfies Article 14 or what data governance evidence under Article 10 the authority expects for your data sources. Vague applications lose to specific ones.
  4. If you need live operational data, scope Article 60 real world testing in parallel. It is a separate route with its own plan, EU database registration, six month cap extendable once, and informed consent requirements under Article 61.
  5. Invoke Article 62 explicitly when you apply. Priority access for SMEs and start-ups, and reduced conformity assessment fees, are entitlements, not favours, and authorities respond to being asked.

If you are not yet certain which systems in your product put you in scope, or whether you are the provider or the deployer for each of them, our free screener at https://www.getactcomply.com/check walks through the classification questions in about ten minutes and gives you the answer you need before any sandbox conversation is useful. Teams at an earlier stage may find the startup compliance guide a more direct starting point.

Check your EU AI Act risk in 5 minutes

Free risk classifier. No signup required. Enforcement is already live.

Run the free screener