Skip to content

The EU AI Act's Regulatory Sandbox Requirement (Articles 57 and 58)

9 min read · updated August 11, 2026

Article 57 is one of the few provisions of the AI Act that imposes a duty on member states rather than on companies. Understanding it means holding two separate questions apart: what a government owes, and what a provider gets.

What member states must establish

Article 57(1) of Regulation (EU) 2024/1689 requires each member state to ensure that its competent authorities establish at least one AI regulatory sandbox at national level, and that it is operational by 2 August 2026. That date is the same date the bulk of the high-risk regime becomes applicable, which is not a coincidence: the sandbox is meant to exist by the time the obligations it helps with arrive.

The obligation is satisfiable in several ways. A member state may establish its sandbox jointly with one or more other member states, or participate in an existing sandbox to the extent that participation provides an equivalent national level of coverage. Regional and local authorities may establish additional sandboxes, and sandboxes established under other Union law may be used where they achieve the same effect. The single national sandbox is a floor, not a cap. Article 57(16) requires the AI Office to make a single interface available with information about sandboxes, and to enable interaction with them.

Article 58(1) requires the Commission to adopt implementing acts specifying the detailed arrangements for the establishment, development, implementation, operation and supervision of sandboxes, and Article 58(2) sets out what those arrangements must cover: eligibility and selection criteria, the application, participation, monitoring, exit and termination procedures, and the terms and conditions applicable to participants. Until those implementing acts are adopted and national authorities have stood up their schemes, the practical texture of a sandbox varies by member state. Read the Regulation at EUR-Lex and then find the national authority’s scheme, because the national scheme is what you actually apply to.

Article 57 and 58 describe a framework that member states are building. Nothing here is legal advice, and the terms of the sandbox you can actually join are set by a national authority under national law. Check the current national scheme before planning around any of this.

What a sandbox is, procedurally

Article 57(4) defines the substance: a controlled environment that fosters innovation and facilitates the development, training, testing and validation of innovative AI systems for a limited time before their placing on the market or putting into service, pursuant to a specific sandbox plan agreed between the providers or prospective providers and the competent authority. Two constraints in that sentence do most of the work. It is before placing on the market — a sandbox is not a route to keep an already-deployed system running while you fix it. And it is pursuant to an agreed plan, so the scope of what is protected is the scope of what was agreed.

Article 57(6) requires competent authorities to provide guidance, supervision and support within the sandbox to identify risks, in particular to fundamental rights, health and safety, and to provide written proof of the activities successfully carried out — an exit report. That exit report is the most concrete output. Article 57(7) provides that it, and the guidance given, shall be taken into account by market surveillance authorities and notified bodies with a view to accelerating conformity assessment procedures to a reasonable extent. Taken into account, and accelerating — not substituting for. A sandbox exit report is not a conformity assessment and does not become one.

Article 57(9) preserves supervisory powers throughout. Where risks to health, safety or fundamental rights are identified during development and testing, adequate mitigation is required, and where mitigation is not effective the development and testing process is suspended until it is. A sandbox is supervised space, not unsupervised space.

What Article 57(12) protects you from

This is the provision people join for, and it is narrower than the word “sandbox” suggests. Article 57(12) provides that where participants respect the sandbox plan and the terms and conditions of participation, and follow in good faith the guidance given by the national competent authorities, no administrative fines shall be imposed for infringements of the Regulation. Where other competent authorities responsible for other Union or national law were involved in supervising the system in the sandbox and provided guidance on compliance, no administrative fines shall be imposed in relation to that law either.

Now the exclusions, which are the substance of this section. Article 57(12) is about administrative fines. Article 57 also provides in terms that participants remain liable under applicable Union and national liability law for harm inflicted on third parties as a result of the experimentation. So:

  • Civil liability is untouched. A person harmed by a system tested in a sandbox sues under national tort law or product liability law, and the sandbox is not a defence.
  • Conformity is untouched. The system still has to go through conformity assessment before being placed on the market. The sandbox may make that faster; it does not replace it.
  • The protection is conditional and forfeitable. It depends on respecting the plan, respecting the terms, and following guidance in good faith. A participant that deviates from the agreed plan has, by the terms of the paragraph, stepped outside the protection for that deviation.
  • It does not reach Article 5. Nothing in the sandbox provisions authorises a prohibited practice. The prohibitions in Article 5 are not a compliance requirement you can be excused from testing against.

Article 59 and the personal data question

Article 59 is the sleeper provision and, for some organisations, the real reason to use a sandbox. It permits, under conditions, the further processing in a sandbox of personal data lawfully collected for other purposes, for the sole purpose of developing, training and testing certain AI systems in the sandbox, where the system is developed for safeguarding substantial public interest in named areas.

The conditions attached run to a long list, and the important ones for planning are: the public interest purpose must be one of those listed; the data must be necessary for complying with high-risk requirements that cannot effectively be met with anonymised, synthetic or other non-personal data; there must be effective monitoring mechanisms to identify high risks to data subjects during experimentation and response mechanisms to mitigate them; the data must be in a functionally separate, isolated and protected environment under the control of the prospective provider with access only for authorised persons; the data must not be transmitted or otherwise accessed by other parties; the processing must not lead to measures or decisions affecting the data subjects nor affect their rights; and the data must be deleted once participation ends or the retention period expires. A description of the processing must be kept and, in most cases, published.

This is not a general licence to reuse data for training. It is a narrow, supervised, public-interest carve-out with an audit trail, and it applies inside the sandbox only. For the general question of reusing data collected for one purpose, see purpose limitation and AI training.

Whether it is worth applying

The case for applying is strongest where the classification question is genuinely uncertain and you would rather have a supervisor’s view on the record than your own counsel’s view in a memo, or where Article 59 is the only lawful route to the data you need, or where you are an SME and the free access under Article 57(15) makes supervisory engagement affordable that otherwise would not be. Article 62 requires member states to give SMEs, including start-ups, priority access to sandboxes provided they meet the eligibility conditions.

The case against is time and disclosure. A sandbox plan agreed with a regulator is a document that describes your system to a regulator, and the process runs on the authority’s calendar. If your system is clearly out of Annex III, or clearly in it and you know what you have to do, the sandbox adds a supervisory relationship without changing the work. In that case testing under Article 60, outside a sandbox, is the provision to read instead.