Summary
- The amended AI Act preserves three distinct routes: a national sandbox for systems under Member State supervision, the EDPS’s institutional work for Union bodies, and an optional AI Office sandbox whose perimeter is limited by Article 75(1). A shared label does not merge their mandates.
- Sandbox participation is controlled and conditional. It does not remove corrective powers or third-party liability, and the Act’s limited fine treatment depends on compliance with the agreed plan and, for other laws, active supervision and guidance by the authority responsible for those laws.
One label, three sources of authority
A sandbox sounds like a place where an innovator can test a system under regulatory supervision. The legal question is more specific: which public body has authority over the system, the experiment and the rules implicated by its use? The European Union’s revised AI Act does not answer that question with one all-purpose entrance.
At national level, Article 57 requires each Member State to ensure that at least one AI regulatory sandbox is operational by 2 August 2027. States may cooperate to establish one, and participation in an existing sandbox that provides equivalent coverage may satisfy the obligation. The requirement is therefore not that every country build a separate facility. It is that an accessible national route exist for systems within national supervisory competence.
The Union-level route is different. Article 57(3a) says the AI Office may establish a sandbox for systems within Article 75(1). That provision assigns the AI Office exclusive supervision and enforcement for defined groups of systems: certain systems built on a general-purpose AI model by the same provider or within the same undertaking, subject to listed exceptions, and systems that constitute or are integrated into a designated very large online platform or search engine. The rule also reaches a deployer only when it is itself the provider or belongs to the same undertaking. It is not a general route for every high-risk system, every large technology company or every provider selling across borders.
The distinction matters to applicants before they prepare a dossier. An organisation may face several authorities because a system touches different laws or public functions. The AI Office’s possible sandbox concerns its narrow Article 75(1) supervisory perimeter; it does not absorb national authority over systems outside that perimeter. Nor does the amended text establish that the AI Office has already opened the route or accepted applications. A permissive legal power is not evidence of operational capacity.
The EDPS pilot is a different institutional experiment
The EDPS has another role: supervision of EU institutions, bodies, offices and agencies. Its public account of a preliminary pilot, launched in 2025, describes an effort to test procedures and build practical experience for possible use cases proposed by Union institutions. The EDPS’s March 2026 AI Act Compass says the pilot is intended to help it decide whether it can offer a sandbox in the strict Article 57 sense.
Article 57(3) expressly authorises the EDPS to establish a sandbox for Union institutions, bodies, offices and agencies; the pilot is evidence of preparation for that mandate, not proof that a full statutory facility is already operating.
That description is useful precisely because it separates a pilot from a fully operational statutory facility. A regulator can test intake, documentation, technical dialogue and internal coordination before it commits to a formal service. Such preparation may reveal staffing or process problems. But those lessons do not establish that applicants have a mature, generally available route, and the EDPS pilot is not the AI Office sandbox. The two institutions serve different regulated populations and exercise different legal powers.
The Commission’s September 2026 proposal for a Council Recommendation adds a wider policy layer. COM(2026)568 proposes common principles for regulatory sandboxes across sectors. Its subject is cross-sector coordination; it is not the AI Act’s Article 58 implementing act and does not itself create an AI Office sandbox. Treating the instruments as interchangeable would turn a proposal about shared practice into a false claim about the operation of a specific statutory route.
Cooperation can connect authorities without pooling their powers
The Act expects authorities to work together. Article 57 requires national competent authorities to involve data-protection authorities and other relevant regulators when an experiment falls within their responsibilities, and it provides for coordination among national authorities, the EDPS and the AI Office through the AI Board where appropriate. These are coordination duties bounded by each institution’s own tasks and powers.
That boundary is operational, not merely constitutional. A provider needs to know who approves the plan, who gives compliance guidance, who monitors the test and who can stop it. A second authority’s attendance at a meeting does not necessarily mean that it has supervised the activity under its own law. That distinction can determine whether guidance is legally relevant, whether a risk has been addressed and who remains accountable when the experiment crosses a regulatory boundary.
Article 57 describes a controlled, time-limited environment operating under a specific plan agreed by the provider or prospective provider and the competent authority. Appropriate safeguards are required; supervised real-world testing may be included when applicable. A sandbox is therefore not a permission to deploy first and regularise later. The agreed plan is the control surface: it should identify the test, its duration, safeguards, monitoring, reporting and conditions for ending participation.
Participation changes some enforcement exposure, not the underlying risk
The legal effects are narrower than a general promise of regulatory comfort. Article 57 preserves supervisory and corrective powers. Significant health, safety or fundamental-rights risks must be mitigated, and the competent national authority may suspend testing or participation if effective mitigation is not possible. The Act also keeps participants liable under Union and national law for damage to third parties caused by experimentation.
The fine provision is conditional. A prospective provider that observes the agreed plan and participation terms and follows the authority’s guidance in good faith is not subject to administrative fines for AI Act infringements covered by the rule. For infringements of other Union or national law, the protection applies only where the authority responsible under that law was actively involved in supervision and supplied compliance guidance. That is not immunity from civil liability, other remedies, or every law that may apply to the system.
The incentives follow from those limits. A credible sandbox can make regulatory expectations more concrete and surface problems earlier. But the value depends on the quality of guidance and the clarity of the plan. If an applicant mistakes a bounded discussion for approval, it may make investment or deployment decisions on a signal the authority never intended to give. Conversely, a process requiring several regulators without naming a lead decision-maker can make participation costly without making risk ownership clearer.
The test is whether the route can be read before it is used
The immediate evidence to watch is institutional rather than promotional: publication of the Article 58 implementing rules and their application materials; a clear account of whether the AI Office has established its optional route; national explanations of which existing or joint sandboxes satisfy the 2027 obligation; and EDPS reporting that continues to distinguish capacity-building from a statutory service. The Article 58 consultation ran from December 2025 into January 2026, but the official material reviewed here does not establish whether a final implementing act was adopted afterward.
For applicants, practical access will turn on how these decisions are made visible. A public map of competent authorities, explicit referral procedures and standardised exit reports could help participants distinguish an experiment from a regulatory endorsement. Those are implementation options, not existing guarantees. Until the operating rules and routes are documented, the legal architecture can be described more confidently than its day-to-day availability.
The three routes can support experimentation without becoming a single European fast lane. Their legitimacy will depend on a traceable connection between jurisdiction, guidance, monitoring and responsibility. The number of facilities opened is an incomplete measure. A better one is whether a participant—and a person affected by the system—can identify who supervised which decision, under what safeguards, and with what authority to intervene.
The legal analysis uses the AI Act consolidated as of 27 July 2026 and Regulation 2026/1744. The EDPS pilot account is from its AI Act Compass 2026–2027. The cross-sector proposal is COM(2026)568, with its status recorded in the EUR-Lex procedure file. The consultation on an Article 58 draft is not treated as evidence that a final act was adopted.
Further sources for the Article 58 consultation and EDPS institutional context: European Commission consultation on the draft Article 58 implementing act; European Commission AI innovation ecosystem; consolidated AI Act ELI record; Regulation (EU) 2026/1744 EUR-Lex text; Commission draft implementing regulation Ares(2025)10569703; EDPS AI supervision page; EDPS Institutional Agenda; EDPS Annual Report 2025 press release.
Member Briefing
Deeper Profile Context
Sign in with the right membership level to unlock the full briefing and source notes.
Only for Strategic Circle
Strategic Circle
Open to all readers. Unlock profile briefings after joining and signing in.
Join Strategic CircleOnly for Leadership Alliance
Leadership Alliance
For qualified IP-asset owners and management; sign in to unlock alliance briefings.
Join Leadership Alliance
