Introduction
The European Union’s Artificial Intelligence Act (AI Act) introduces a framework for regulatory sandboxes to support the development of AI technologies while protecting health, safety, and fundamental rights. This blog post delves into the concept of regulatory sandboxes, their objectives, powers and the issues surrounding their implementation in the EU’s AI Act.
What is a Regulatory Sandbox?
A regulatory sandbox is a tool providing a structured context for experimentation, enabling the testing of innovative AI technologies, products, or services in a real-world environment for a limited time and under regulatory supervision. It allows innovators to test the innovations in a controlled environment, and provides regulators a better understanding of new technologies. Regulatory sandboxes were initially developed to promote innovation within the financial services industry, but are also starting to emerge in other areas such as commerce, health care, mobility, data protection, and AI regulation. The goal of it in all these areas are to enable innovation and ensure safety through legal certainty, law enforcement, and flexibility.
Several jurisdictions have regulatory sandboxes, particularly in the financial innovation sector. The UK’s Financial Conduct Authority (FCA) was created the first formal regulatory sandbox in 2016. Since then, the FCA sandbox has supported over 700 firms and increased their average speed to market by 40% compared to the regulator’s standard authorization time.
Another successful example is Singapore’s regulatory sandbox. The Monetary Authority of Singapore (MAS) published its guidelines for the financial regulatory sandbox in 2016. Sandbox entities in Singapore are freed from the administrative and financial burdens of ordinary compliance processes and are entitled to a broader testing ground.
What Powers Do Regulatory Sandboxes Have?
Regulatory sandboxes can be equipped with various legal powers, usually they are: providing legal guidance, to issue no- enforcement letters, and/or grant exemptions from legal rules.
First, regulators can provide legal guidance to innovators to help them determine whether their AI products or services comply with current legal requirements. This guidance can be provided through general guidance documents or individualized advice answering to the innovator’s questions.
Secondly, regulators can also provide no-enforcement letters to participating innovators in sandboxes. These letters serve two main purposes: 1. They can offer guidance by clearly explaining the legal requirements that innovators must follow to avoid facing penalties or legal action. 2. In some cases, no-enforcement letters can promise that regulators won’t take legal action against an innovator for a specific test activity, even if it doesn’t fully comply with certain legal requirements. (However, this type of no-enforcement letter is only allowed when there are proper measures to protect the rights of third parties and to ensure that the innovator remains liable for any causing harm.)
Thirdly, regulatory sandboxes can also provide innovators with exemptions from certain legal requirements. These exemptions allow innovators to temporarily ignore specific legal rules, but only under strict conditions set by the regulators. For example, the regulators may:
1. Closely monitor the innovator’s activities
2. Require the innovator to cooperate and share information
3. Set clear limits on what can be tested, for how long, and under what circumstances
Providing exemptions is different from no-enforcement letters: It exempts innovators from a certain legal duty while no- enforcement letters abstain them only from imposing legal consequences (such as fines).
By carefully balancing the need for flexibility with the need for oversight, these exemptions can help encourage innovation while still ensuring safety. However, not all experts are in favor of regulatory sandboxes. Some argue that they may actually slow down and halt innovation by creating additional bureaucratic hurdles. Practical challenges have also been noted, such as consumers perceiving products tested in a sandbox as if they have been endorsed by authorities, which can have negative legal consequences.
The AI Act’s Framework on Regulatory Sandboxes
The AI Act aims to provide a uniform legal framework for AI, encouraging innovation through legal certainty while ensuring a high level of protection for health, safety, and fundamental rights. The regulatory sandbox framework as one of the ‘measures in support of innovation’ is set out in Articles 57, 58 and 59. It is intended to serve objectives such as fostering innovation, accelerating market access, improving legal certainty, and contributing to evidence-based regulatory learning. Article 57 defines a regulatory sandbox as “a controlled environment that fosters innovation and facilitates the development, training, testing and validation of innovative AI systems for a limited time before their being placed on the market or put into service pursuant to a specific sandbox plan agreed between the providers or prospective providers and the competent authority”. According to the article, Member States shall establish at least one regulatory sandbox. They may also fulfill this obligation by establishing a sandbox jointly with other Member States, or by participating in an existing sandbox. The AI Office shall make a publicly available list of planned and existing sandboxes. National competent authorities shall submit annual reports providing information about the progress and results of the implementation of the sandboxes to the AI Office and the Board (one year after the sandbox was established, every year thereafter, and a final report). Those reports shall be online and available to the public. Regarding the details of establishment, development, implementation, operation and supervision of the AI regulatory sandboxes, Article 58 mandates the Commission to adopt implementing acts that specify them.
The sandbox framework allows for legal guidance, supervision and support from national competent authorities to enhance legal certainty for innovators and ensure compliance with the AI Act and other relevant Union or national legislation. The supervision activity of compliance shall identify the risks in particular to fundamental rights, health, and safety. Any significant risks to them shall result in an adequate mitigation. National competent authorities shall identify the measures and their effectiveness in this manner. If no effective mitigation is possible, national competent authorities may suspend the testing process or the participation in the sandbox, temporarily or permanently. National competent authorities are expected to exercise their discretionary powers flexibly but within the limits of the relevant legislation, and with the aim of supporting innovation. AI systems’ conformity with the requirements of the Act during sandbox testing can later be taken into account during a conformity assessment. This provision could help streamline the market access process for AI innovations.
The AI Act also provides a legal basis for regulators to refrain from imposing administrative fines. Accordingly, if the prospective providers observe the specific plan and the terms and conditions and follow in good faith the guidance of the national competent authority, administrative fines for infringements shall not be imposed. However, the Act also stipulates that liability for damage caused during testing remains with the innovator. This means that while the sandbox provides an exemption from regulatory compliance, it does not shield participants from liability.
Concerns Rising from the Framework
The AI Act’s regulatory sandbox framework raises several concerns that need to be addressed to ensure its effectiveness in fostering innovation while protecting fundamental rights and safety.
First, the sandbox could create a false perception of safety and compliance in the market. An AI system that passes the regulatory requirements during sandbox testing may still pose liability risks or evolve into a high-risk AI through unanticipated applications. The approval from the sandbox should not be understood as a guarantee of safety or absence of liability risks. To avoid misleading consumers and stakeholders, clear communication and disclaimers regarding the limitations of sandbox testing are essential. Additionally, education of the public on AI literacy is vital and should be one of the obligations of Member States.
Secondly, different practices of sandboxes across EU states could lead to uncertainty and confusion in the market. The AI Act does not establish a uniform EU AI regulatory sandbox but allows one or more EU states to establish sandboxes, which may result in different frameworks and implementations. This fragmentation could hinder the development of a harmonized AI market in the EU as opposed to the aim of the Act stated in Article 1. Additionally, the non- uniform structure of regulatory sandboxes could create challenges for AI developers operating across multiple jurisdictions. In order to ensure consistency and to avoid regulatory arbitrage, coordination and cooperation among national regulators and the Board are crucial.
Thirdly, the details about the coordination and cooperation between national regulators and the European Artificial Intelligence Board are not clear in the Act. While some regulations can be made directly by EU institutions rather than by Member States, others, which are enacted by Member States, can be influenced or shaped by the regulations of the EU. Additionally, some regulations can be directly made by Member States. In this context, the creation of common implementing rules may be challenging because Member States’ priorities and approaches vary. However, a clear delineation of responsibilities of Member States and the Board, and a remedy mechanism for resolving potential conflicts would be effective for the operation of AI sandboxes across the EU.
Fourthly, regulatory sandboxes can only exempt innovators from administrative fines but not from any other type of enforcement action. This could be not effective enough for the innovators in certain sectors. A specific example would be a regulatory sandbox for medical AI in Austria. An AI regulatory sandbox for medical AI would require that the AI Act, EU medical device law, and national medical professional law are supervised together. In Austria, Austrian Doctors Act’s principle of direct treatment requires that doctors treat patients generally face-to-face. So, if the doctors participating the experiment in the sandbox use the medical AI to treat patients as a part of the experiment, they would breach the national medical professional law. Unfortunately, the EU AI Act’s regulatory sandbox framework could be used to exempt doctors who breach the principle of direct treatment from administrative fines. However, the doctors could still face temporary disbarment according to Austrian Doctors Act (aka. national medical professional law or ‘that law’ as mentioned in AI Act art. 53/12) Ultimately, a framework that expands the scope of exemptions for innovators beyond only administrative fines is crucial for encouraging participation and fostering innovation.
Finally, the continued imposition of liability on sandbox participants for any damage inflicted on third parties may limit innovation. While developers should not be allowed to use the sandbox as a shield from liability, subjecting them to the same liability regime during sandbox testing could discourage participation. This may discourage AI developers from participating in sandboxes, as they would expose their trade secrets and algorithms without the benefit of liability protection. Eventually, this would hinder the innovation of the AI in the EU. While many stakeholders have raised criticism about this issue and stressed the need for a balanced approach between liability protection and accountability, finding that balanced approach remains a million-dollar question.

Sena Lezgioglu Ozer
Sena Lezgioglu Ozer, a PhD candidate in Public Law at Istanbul Bilgi University, specializes in the intersection of artificial intelligence and human rights. She holds a master's degree in media and communication systems, where her thesis explored the mediatization of the judiciary, focusing on the dynamic between social media and the judicial system in Turkiye. Complementing her scholarly pursuits, Sena brings six years of practical legal experience as an attorney in Istanbul, handling criminal, administrative, and human rights cases.
