What Is an AI Regulatory Sandbox Under the EU AI Act?

7 min readAbleneo AI transformation team

Short answer. An AI regulatory sandbox is a controlled environment, run by a national competent authority, where a company can develop, train, and test an AI system under direct supervision before it goes to market. Article 57 of the EU AI Act (Regulation (EU) 2024/1689) requires every Member State to establish at least one national sandbox and have it operational by 2 August 2026. The sandbox gives the participant written guidance, a supervised testing period, and an exit report that documents what was done, which the participant can use as evidence of compliance. As of August 2025, only 1 of the 27 Member States, Spain, had a sandbox up and running.

1What This Means in Practice

An AI regulatory sandbox is a formal supervisory mechanism, not a marketing label. A company applies to the national authority, agrees a sandbox plan, then builds and tests its AI system inside a defined scope while the regulator watches and advises. The point is to remove uncertainty before deployment: the participant learns how the authority reads the rules for its specific use case, and the authority learns how the technology behaves before it reaches the public. At the end, the authority issues an exit report describing the activities, the outcomes, and the lessons, and that document travels with the system into the market.

Article 57 sets out what each sandbox must provide, and Article 59 adds a narrow legal basis to process personal data already lawfully collected, for developing certain AI systems in the public interest, under strict conditions and oversight. The sandbox does not suspend the law. A participant stays liable for harm caused during testing, but supervised, good-faith participation shields it from administrative fines for the breaches the authority identifies and the participant corrects.

2Why This Matters for Regulated Industries

For banks and insurers in Slovakia, the Czech Republic, and Austria, the sandbox lands exactly where the risk sits. The AI systems these firms most want to deploy, credit scoring, anti-money-laundering and sanctions screening, fraud detection, and life and health insurance pricing, are the same ones the AI Act treats as high-risk under Annex III. Those obligations, on data governance, human oversight, transparency, and logging, apply from 2 August 2026, the same date the sandboxes must be running. A sandbox lets a bank validate a high-risk system against a live supervisor before that deadline, rather than discover a gap during an audit afterward.

The financial-sector machinery is being built around this. In 2026 and 2027 the European Banking Authority will support AI Act implementation in the banking and payments sector by promoting a common supervisory approach across national authorities. For a financial entity, the sandbox also interlocks with DORA, which has applied since 17 January 2025 and treats an external AI service as ICT third-party risk. Testing an AI system in a sandbox produces the documentation a firm needs for both regimes at once: the AI Act conformity evidence and the DORA resilience trail.

An AI regulatory sandbox is a supervised environment under Article 57 of the EU AI Act where a company tests an AI system with a regulator before market launch.

3How Is a Sandbox Different From an Ordinary Compliance Review?

A compliance review looks backward at a system that already exists and asks whether it meets the rules. A sandbox runs forward, alongside development, and shapes the system while it is still being built. The difference is timing and dialogue. In a review, a firm submits documentation and waits for a verdict. In a sandbox, the firm and the regulator agree a testing plan, work through the hard questions together, and adjust the system before it ships. The output is also different: a review yields a pass or a finding, while a sandbox yields an exit report that records the testing and can be shown to other authorities as evidence of due diligence.

4What Can a Bank Test Inside a Sandbox?

A bank can test the parts of a high-risk system that are hardest to prove on paper. That includes whether a credit-scoring model treats protected groups fairly, whether a human reviewer can genuinely override an automated decision, and whether the system logs enough to reconstruct why it acted. It can test an anti-money-laundering model against real typologies to measure false-positive rates, or check that a customer-facing assistant stays inside its approved scope. The sandbox is where a firm turns abstract obligations, such as effective human oversight, into measured behavior the supervisor has seen and signed off on.

5How Does a Company Join an AI Regulatory Sandbox?

A company applies to the competent authority designated by its Member State, which for financial use cases is often the financial supervisor working with the national AI authority. The applicant proposes an AI system, a use case, and a testing scope. If accepted, the parties agree a sandbox plan that sets the objectives, the duration, the data to be used, and the safeguards. Testing runs under supervision for the agreed period. The authority issues the exit report at the end. Member States must report annually to the AI Office on their sandboxes, so the practice is tracked and standardized across the Union rather than left to local interpretation.

6What Do Sandboxes Offer SMEs and Startups?

The AI Act gives SMEs and startups priority access to the national sandboxes, free of charge except for exceptional costs, because the law treats the compliance burden as a barrier these firms feel most. A small insurtech or a fintech building a high-risk system can test it under supervision without paying for a private legal opinion on every clause, and can leave with an exit report that signals credibility to partners and to other regulators. For a larger bank, the same mechanism de-risks a vendor relationship: it can ask a smaller AI supplier to validate a model in a sandbox before procurement.

7How Should a Slovak or Czech Financial Institution Prepare?

Start with the inventory. List every AI use case, mark which ones fall under Annex III as high-risk, and identify the two or three where supervised testing would remove the most uncertainty before the 2 August 2026 deadline. Track which national authority will run the sandbox and when it opens, because as of August 2025 most Member States, including several in the region, had not yet confirmed their plans. Prepare the documentation a sandbox expects: a clear use case, a data lineage, a human-oversight design, and a logging approach. A firm that walks in with that structure gets value from the supervised time. A firm that walks in to figure out its own system wastes it.

8The Ableneo Perspective

A sandbox rewards the firm that arrives with a system already built for scrutiny, and that is where most AI programs are weakest. Ableneo designs regulated AI for audit from the first release, with logged decisions, real human oversight, and a documentation trail, across financial-sector clients in Central Europe including ČSOB, Erste, and UNIQA. About 80% of Ableneo projects reach production, against an industry pattern of pilots that stall before they meet a control, and that rate comes from treating governance as part of the build rather than a later add-on. Our work on AI transformation prepares the people, the data, and the system together, so that supervised testing confirms a design rather than exposing one.

Key takeaways

Sources

Planning AI in a regulated business? Ableneo takes systems from classification to governed production.

Talk to Ableneo