Quick answer

The EU AI Act (Articles 57-60) requires Member States to establish AI regulatory sandboxes — controlled environments where companies can develop and test AI systems under regulatory supervision before market placement. SMEs and startups receive priority access, and cross-border cooperation mechanisms enable sandbox results to be recognized across the EU.

Updated June 2026 · MmowW AI Compliance

EU AI Act Regulatory Sandboxes: Articles 57-60 Explained (2026) | MmowW

What Are AI Regulatory Sandboxes Under the EU AI Act

Articles 57 through 60 of Regulation (EU) 2024/1689 introduce a structured framework for AI regulatory sandboxes across the European Union. These sandboxes are controlled environments established by national competent authorities where providers and prospective providers can develop, train, validate, and test AI systems under regulatory oversight before those systems are placed on the market or put into service.

The concept reflects a deliberate policy choice: rather than forcing innovation to navigate compliance requirements in isolation, the EU AI Act creates supervised spaces where regulators and developers work in proximity. This approach acknowledges that AI systems — particularly those classified as high-risk — benefit from early regulatory engagement during development rather than compliance assessment applied only at the point of market entry.

Article 57(1) establishes the foundational requirement. Each Member State must ensure that its national competent authorities establish at least one AI regulatory sandbox at national level, which shall be operational by August 2, 2026. This deadline aligns with the broader application timeline of the EU AI Act, ensuring that sandbox infrastructure is available when high-risk AI system obligations become enforceable.

Objectives and Design Principles

The regulatory sandbox framework serves dual objectives that the EU AI Act treats as complementary rather than competing. The first objective is fostering innovation in AI development within the Union. The second is ensuring compliance with the requirements of the Regulation and other relevant Union and national law.

Article 57 establishes that sandboxes must provide a controlled environment that facilitates the development, testing, and validation of innovative AI systems for a limited time before their placement on the market or putting into service. This controlled environment operates under a specific sandbox plan agreed between the participants and the competent authority.

The design principles embedded in the legislation reflect lessons from financial regulatory sandboxes. Participation in a sandbox does not exempt participants from regulatory liability. Article 57(8) makes clear that participants remain liable under applicable Union and Member States liability legislation for any harm inflicted on third parties as a result of the experimentation taking place in the sandbox. This provision prevents the sandbox from becoming a compliance-free zone.

Conditions for Participation

Article 58 sets out the conditions under which entities may participate in an AI regulatory sandbox. The competent authority must assess applications based on specific criteria, including the novelty of the AI system, the need for a controlled environment to test the system, and the applicant's preparedness to comply with the requirements of the Regulation.

Participation is not automatic. The national competent authority retains discretion to accept or reject applications, and Article 58 requires that participation conditions be fair, transparent, and non-discriminatory. The sandbox plan — which governs the specific terms of each participant's engagement — must include the objectives of the participation, the conditions for the participation, the methodology, and the timeline.

Participants must comply with the sandbox plan and the instructions of the competent authority. Article 58 also requires that exit conditions be clearly defined. When a participant completes the sandbox process, the results of the testing and validation may be used as part of the conformity assessment procedures under the Regulation. This creates a tangible compliance benefit: sandbox participation can generate evidence that directly supports market placement.

Safeguards for Fundamental Rights and Personal Data

Article 59 addresses the processing of personal data within regulatory sandboxes. Recognizing that AI systems frequently require personal data for training, testing, and validation, the Article establishes specific conditions under which personal data lawfully collected for other purposes may be processed in the sandbox for developing certain AI systems in the public interest.

These conditions include requirements that the AI systems be developed for safeguarding substantial public interest, that the data processed be necessary for complying with the requirements of the Regulation, that effective monitoring mechanisms exist, and that any personal data to be processed in the sandbox be in a functionally separate, isolated, and protected data processing environment. The data processed must not be transmitted, transferred, or otherwise accessed by other parties, and personal data processed in the sandbox must not lead to measures or decisions affecting data subjects.

Article 59 also requires that personal data processed in the sandbox be deleted once the sandbox participation has concluded, and that the data processing logs be kept for the duration necessary for audit and accountability purposes. These safeguards ensure that sandbox innovation does not come at the expense of data protection principles established under the GDPR.

Priority Access for SMEs and Startups

The EU AI Act contains explicit provisions ensuring that small and medium-sized enterprises and startups can meaningfully participate in regulatory sandboxes. Article 57(3) requires that the terms and conditions for sandbox participation take into account the specific needs and circumstances of SME providers and startups.

This priority access reflects a structural concern. Without dedicated provisions, sandbox processes risk being dominated by large enterprises with greater resources to navigate regulatory procedures and dedicate personnel to sandbox engagement. The EU AI Act addresses this by requiring national competent authorities to provide SMEs and startups with awareness-raising activities about the application of the Regulation, and by directing that sandbox participation terms be proportionate to the resources of smaller entities.

Article 62 further reinforces this approach by requiring the AI Office and Member States to undertake specific actions to support SMEs, including providing prioritized access to AI regulatory sandboxes, organizing dedicated awareness-raising activities, and establishing dedicated communication channels for guidance on the implementation of the Regulation.

Cross-Border Cooperation

Article 60 establishes a framework for cross-border cooperation between regulatory sandboxes. Where multiple Member States operate sandboxes, the national competent authorities may agree to jointly operate shared sandbox environments. This cooperation can involve coordinating sandbox activities and sharing relevant information, including through the AI regulatory sandboxes established by the European Data Protection Supervisor.

The cross-border dimension addresses the reality that AI systems are rarely developed or deployed within a single Member State. Providers operating across multiple EU markets benefit from sandbox outcomes that are recognized beyond national borders. Article 60 facilitates this by enabling national competent authorities to recognize the results of testing conducted in another Member State's sandbox, subject to agreed conditions.

The European AI Office plays a coordinating role in cross-border sandbox cooperation. The AI Office may facilitate the sharing of best practices among national competent authorities and promote convergence in sandbox operation, helping to prevent regulatory fragmentation that could undermine the internal market objectives of the Regulation.

Practical Implications for Compliance Planning

For organizations developing AI systems — particularly those likely to be classified as high-risk — sandbox participation represents a structured pathway to compliance. The ability to develop and test systems under regulatory supervision, and to use sandbox outcomes as part of conformity assessment, creates a practical advantage that extends beyond the sandbox period itself.

Organizations considering sandbox participation should begin by identifying the national competent authority responsible for sandbox operation in their primary Member State. The application process requires demonstrating the innovative nature of the AI system, the need for a controlled testing environment, and readiness to engage with regulatory requirements during development.

Maintaining structured records of AI development activities — including risk assessments, testing methodologies, and compliance documentation — strengthens both sandbox applications and subsequent conformity assessment processes. WnowW Trust OS at mmoww.net/ai/app/ provides a daily operations framework for organizations building these compliance habits from the earliest stages of AI system development.

The regulatory sandbox framework, verified against current regulations by Sawai Gyoseishoshi Office, represents one of the EU AI Act's most forward-looking provisions. By creating structured spaces where innovation and compliance develop in parallel, Articles 57-60 establish a model that treats regulatory engagement as a feature of responsible AI development rather than an obstacle to it.

Check your AI compliance readiness — free.

Take the Readiness Check 3 minutes · 10 questions · no signup required

This article is for informational purposes only and does not constitute legal advice. Regulatory requirements change frequently — verify current rules with official sources. Built by Sawai Gyoseishoshi Office, Hiroshima, Japan.