Back to Blog
EU AI Act

AI regulatory sandboxes: what Articles 57 to 63 set up

Published 30 November 20263 min readBy EmberHound

Every Member State has to run one by August 2027. Here is what a sandbox is, what participating gets you, and the one protection that makes it worth considering.

Sandboxes are the part of the AI Act aimed at the organisations building AI rather than the ones buying it. They are a supervised environment for developing and testing a system before it goes to market, run by a competent authority under an agreed plan.

What has to exist, and by when

Article 57(1) requires Member States to ensure their competent authorities establish at least one AI regulatory sandbox at national level, operational by 2 August 2027. A sandbox may be established jointly with other Member States, and the obligation can be met by participating in an existing one where that gives equivalent national coverage.

The consolidated text marks that paragraph as amended, so the 2027 date is the current one rather than the original. Two further routes appear alongside it, also marked as amended: the European Data Protection Supervisor may establish a sandbox for Union institutions, bodies, offices and agencies, and the AI Office may establish a Union-level sandbox for AI systems covered by Article 75(1).

The Union-level sandbox provision states that it shall provide priority access to SMEs, including start-ups, and SMCs. That is unusual enough in a regulation to be worth noticing if you are small and building something.

What a sandbox actually is

Article 57(5) describes a controlled environment for the development, training, testing and validation of innovative AI systems for a limited time before they are placed on the market or put into service, under a specific sandbox plan agreed between the provider and the competent authorities, with appropriate safeguards in place. It may include testing in real world conditions under supervision.

Three constraints in that sentence are easy to skim past: it is time-limited, it is pre-market, and it runs to a plan agreed with the authority rather than one you set yourself.

The reason to consider one

Article 57(12) is the provision that gives sandboxes practical value. Participants remain liable under applicable Union and national liability law for damage inflicted on third parties as a result of the experimentation. But provided they observe the specific plan and the terms and conditions of participation, and follow in good faith the guidance given by the national competent authority, no administrative fines shall be imposed by the authorities for infringements of this Regulation.

Read those two sentences together, because they point in different directions. Liability to people you harm is untouched. Regulatory fines under the AI Act are lifted, conditionally, for the duration and scope of the sandbox.

What the sandboxes are for

Article 57(9) sets out what sandboxes are meant to achieve, in the regulation's own words:

  • improving legal certainty to achieve regulatory compliance with this Regulation or, where relevant, other applicable Union and national law
  • supporting the sharing of best practices through cooperation with the authorities involved in the AI regulatory sandbox
  • fostering innovation and competitiveness and facilitating the development of an AI ecosystem
  • contributing to evidence-based regulatory learning

The consolidated text adds a further objective, marked as amended, concerning access to the Union market.

The fourth of those is worth reading as a two-way arrangement. The authority is learning from what happens in the sandbox as much as the participant is.

Who this is not for

If you deploy AI systems rather than develop them, sandboxes are not your route. They are pre-market and aimed at providers and prospective providers. Your obligations run through Article 26 if you deploy a high-risk system, and Article 50 depending on how the system interacts with people.

How EmberHound fits

Sandbox participation runs to an agreed plan, which means records: what the system is, what it is being tested for, and what the authority has been told. The AI Act Workspace keeps system records and supporting documents in one place, and is in early access.

This article is general information, not legal advice. It describes Articles 57 to 63 as consolidated at 27 July 2026.

Sources & references

  1. Regulation (EU) 2024/1689 laying down harmonised rules on artificial intelligence (AI Act) - EUR-Lex
  2. Regulation (EU) 2026/1744 amending Regulations (EU) 2024/1689, (EU) 2018/1139 and (EU) 2023/1230 (Digital Omnibus on AI) - EUR-Lex
  3. Regulation (EU) 2024/1689 - consolidated text as at 27 July 2026 - EUR-Lex
  4. AI Act - regulatory framework for artificial intelligence - European Commission

Want more of this in Google?

See what personal data your endpoints are hiding

EmberHound scans your devices for GDPR and PCI data automatically - no manual discovery required.

Your cookie choices

We use cookies to run this site, measure how it is used, and to advertise on other platforms. You can accept or refuse each purpose separately.

Keeps you signed in and remembers this choice. Always on.

Google Analytics, Sentry and Vercel. Which pages are used, and what breaks.

LinkedIn, X and Meta pixels, loaded through Google Tag Manager.

Cookie policy