Chapter 9 of 25
Innovation Support and the Governance Architecture
The Act pairs strict controls with supervised routes for experimentation and institutional support. Its recitals establish sandboxes for innovators while building a multilevel network of Union bodies, national authorities, experts and testing structures.
Why the Act Creates Sandboxes: Recital (138)
The policy balance
Recital (138) responds to rapidly developing AI with both regulatory oversight and a safe, controlled space for experimentation. Innovation is expected to proceed with safeguards and risk mitigation.
At least one sandbox
The recital says: "Member States should ensure that their national competent authorities establish at least one AI regulatory sandbox at national level".
The sandbox supports development and testing under strict oversight before an AI system is placed on the market or otherwise put into service.
Coverage, form, and resources
A State could join an existing or joint sandbox only if national coverage is equivalent. Sandboxes could be physical, digital, or hybrid, and establishing authorities should ensure financial and human resources.
What a Sandbox Does: Recital (139)
A pre-market environment
The objective is "to foster AI innovation by establishing a controlled experimentation and testing environment in the development and pre-marketing phase".
The environment aims to ensure compliance with this Regulation and other relevant Union and national law, while improving legal certainty and authorities' understanding of opportunities, risks, and impacts.
What supervision covers
Supervision should cover development, training, testing, and validation before market placement or putting into service, including whether a substantial modification may require a new conformity assessment.
The risk gate
Significant risks should trigger adequate mitigation. If mitigation fails, development and testing should be suspended. Authorities should cooperate where appropriate, including with fundamental-rights supervisors.
Real-world testing
Upon agreement between national competent authorities and sandbox participants, testing in real-world conditions may also be operated and supervised within the sandbox.
Data Reuse and Real-World Testing: Recitals (140)-(141)
A limited data-reuse basis
Recital (140) permits the possibility to "use personal data collected for other purposes for developing certain AI systems in the public interest within the AI regulatory sandbox, only under specified conditions".
Other controller duties and data-subject rights remain applicable. The recital also says this Regulation should not provide the legal basis described in GDPR Article 22(2)(b).
Safeguards in the sandbox
Providers and prospective providers should use appropriate safeguards, follow authority guidance, cooperate, and act expeditiously and in good faith to mitigate significant safety, health, and fundamental-rights risks.
Testing in real-world conditions
For certain high-risk systems, a specific real-world testing regime may be available without sandbox participation, but it requires appropriate and sufficient guarantees and conditions.
A central safeguard is "requesting informed consent of natural persons to participate in testing in real world conditions, with the exception of law enforcement where the seeking of informed consent would prevent the AI system from being tested."
Quiz: Sandbox Boundaries
Test your reading of Recitals (138)-(141). Select the answer that best follows the source text.
During sandbox testing, a significant risk is identified and cannot be adequately mitigated. What does Recital (139) say should happen?
- The development and testing process should be suspended.
- The provider may continue testing if it publishes a warning.
- The system must automatically be placed on the market for review.
- The risk may be ignored if the participant is an SME.
Show Answer
Answer: A) The development and testing process should be suspended.
Recital (139) states that significant risks should result in adequate mitigation and, failing that, in suspension of the development and testing process. SME status does not remove this expectation.
Innovation Support, SMEs, and Microenterprises: Recitals (142)-(146)
Beneficial outcomes
Member States are encouraged to support AI research and development for accessibility, reduced socio-economic inequality, and environmental targets, using sufficient resources and interdisciplinary cooperation.
Priority, not exclusivity
"Member States should provide SMEs, including start-ups, that have a registered office or a branch in the Union, with priority access to the AI regulatory sandboxes" if eligibility and selection conditions are met.
Priority does not exclude other providers or prospective providers: they may access the sandbox where they fulfil the same eligibility conditions and selection criteria.
Reducing practical burdens
The recital addresses guidance channels, standardisation participation, conformity-assessment fees, certification costs, translation costs, templates, a single information platform, and procurement best practices.
Microenterprises
The source seeks to "allow microenterprises to fulfil one of the most costly obligations, namely to establish a quality management system, in a simplified manner" without lowering protection or high-risk compliance.
Worked Example: A Small Accessibility-AI Provider
The applicant
A Spanish start-up develops an accessibility tool and faces legal uncertainty while developing, training, testing, and validating it before market placement.
It should receive priority sandbox access if it meets eligibility conditions and selection criteria. Priority is not a guaranteed place, and it does not exclude other eligible applicants.
A risk appears
If testing reveals materially poorer outcomes for a regional-language group, that is a significant risk requiring adequate mitigation. If mitigation fails, the process should be suspended.
Proportionality is not exemption
A microenterprise may fulfil the quality-management system in a simplified manner, but Recital (146) preserves the protection level and the need to comply with high-risk requirements.
Union-Level Governance: Recitals (147)-(150)
Testing infrastructure
The Commission should facilitate access, where possible, to testing and experimentation facilities for accredited bodies, groups, and laboratories that perform relevant conformity-assessment tasks.
The framework
The source establishes "a governance framework that both allows to coordinate and support the application of this Regulation at national level, as well as build capabilities at Union level and integrate stakeholders in the field of AI."
AI Office
Its mission is "to develop Union expertise and capabilities in the field of AI and to contribute to the implementation of Union law on AI." Member States should facilitate its tasks.
Board and advisory forum
The Board provides advice and guidance and has standing subgroups for market surveillance and notified bodies. The advisory forum brings stakeholder expertise from commercial and non-commercial interests.
Experts and National Competent Authorities: Recitals (151)-(154)
Scientific panel
Independent experts should have up-to-date scientific or technical AI expertise, act impartially and objectively, and protect confidential information and data.
Member States should be able to request support from the scientific panel's expert pool for their enforcement activities. Union AI testing support structures should also be made available to Member States.
Two authority functions
"each Member State should designate at least one notifying authority and at least one market surveillance authority as national competent authorities".
One public-facing focal point
For efficiency and external coordination, "each Member State should designate a market surveillance authority to act as a single point of contact."
How authorities should act
National competent authorities should exercise powers independently, impartially, and without bias. Their members should avoid incompatible actions and should be subject to confidentiality rules.
Monitoring, Incidents, and Enforcement: Recitals (155)-(157)
Monitoring after deployment
Recital (155) says "all providers should have a post-market monitoring system in place." Where relevant, this includes analysing interaction with other AI systems, devices, and software.
Monitoring should not cover sensitive operational data of law-enforcement deployers. It helps address risks from systems that continue to learn after market placement or putting into service.
What counts as serious
Reportable serious incidents include death or serious health damage, serious irreversible critical-infrastructure disruption, certain fundamental-rights infringements, and serious property or environmental damage.
Enforcement ecosystem
Regulation (EU) 2019/1020 applies in its entirety. Authorities may address all AI systems presenting a risk, while fundamental-rights, equality, and data-protection bodies retain their competences and independence.
Quiz: Governance and Enforcement
Choose the option that accurately matches the source's governance and supervision architecture.
Which statement is correct under Recitals (151)-(157)?
- Each Member State should designate at least one notifying authority and at least one market surveillance authority, and designate a market surveillance authority as a single point of contact.
- Only the AI Office may supervise AI systems, so Member States do not need national competent authorities.
- Post-market monitoring is required only after a serious incident has already occurred.
- National fundamental-rights and data-protection authorities lose their independent powers when the Regulation applies.
Show Answer
Answer: A) Each Member State should designate at least one notifying authority and at least one market surveillance authority, and designate a market surveillance authority as a single point of contact.
Recital (153) calls for at least one notifying authority and at least one market surveillance authority, plus a market surveillance authority serving as the single point of contact. Recital (157) expressly preserves the competences, powers, and independence of relevant national bodies.
Flashcards: Core Architecture
Flip each card and state the source rule before checking the answer.
- AI regulatory sandbox
- A controlled setting for development and testing under strict regulatory oversight before an innovative AI system is placed on the market or put into service.
- Priority access for SMEs
- SMEs, including start-ups, with a registered office or branch in the Union should receive priority access to sandboxes if they fulfil eligibility conditions and selection criteria.
- Microenterprise simplification
- Microenterprises may fulfil the quality-management-system obligation in a simplified manner; this does not remove high-risk compliance requirements or reduce the intended protection level.
- AI Office mission
- To develop Union expertise and capabilities in AI and contribute to implementation of Union law on AI.
- National competent authorities
- Each Member State should designate at least one notifying authority and at least one market surveillance authority.
- Single point of contact
- Each Member State should designate a market surveillance authority to act as a single point of contact.
- Post-market monitoring
- All providers should have a post-market monitoring system in place; where relevant, it includes analysis of interactions with other AI systems, devices, and software.
- General-purpose AI supervision
- The source assigns monitoring support to the AI Office through the scientific panel; the stated rule is that supervision and enforcement powers for providers of general-purpose AI models should be a competence of the Commission.
Capstone: Map an AI System Through the Architecture
Your task
A university spinout develops an AI model that helps hospitals prioritise maintenance of diagnostic equipment. It is still being trained and validated. It wants to use historical data collected for equipment-management purposes, test the system in two hospitals, and later commercialise it across several Member States.
Build a short compliance-and-support map using only the recitals studied:
- Experimentation route: Would a national sandbox be useful? Identify the legal uncertainty or pre-market activity that Recital (139) says sandbox supervision should cover.
- Data question: If historical personal data are involved, state the narrow condition in Recital (140) and name two protections that still matter.
- Testing question: If natural persons take part in real-world testing, identify the consent safeguard from Recital (141), and distinguish participation consent from data-processing consent.
- Support question: If the spinout is an SME with a Union branch, identify its sandbox-access position. If it is a microenterprise, explain what Recital (146) simplifies and what it does not simplify.
- Governance question: Name the national bodies that should be designated and the Union-level bodies or structures that could provide expertise, guidance, testing capacity, or stakeholder input.
- After deployment: Identify the monitoring system and the kinds of serious outcomes that should be reportable.
Self-check
A strong answer distinguishes support from exemption. Sandboxes, templates, testing facilities, expert support, and simplified quality-management fulfilment can reduce uncertainty or burden. They do not eliminate the source's expectations for safeguards, risk mitigation, independent enforcement, post-market monitoring, or serious-incident reporting.
Key Terms
- provider
- An actor referred to in the source as responsible for placing or otherwise making an AI system available; the supplied recitals discuss provider duties but do not provide a full definition.
- advisory forum
- A stakeholder body that should advise and provide technical expertise to the Board and the Commission.
- scientific panel
- A panel of independent AI experts established to support implementation and enforcement, particularly AI Office monitoring of general-purpose AI models.
- serious incident
- An incident or malfunctioning with outcomes such as death or serious health damage, serious irreversible critical-infrastructure disruption, certain fundamental-rights infringements, or serious property or environmental damage.
- notifying authority
- A national competent authority that each Member State should designate at least once under Recital (153).
- prospective provider
- An actor intending to develop or provide an AI system and seeking to innovate, experiment, or test before market placement or putting the system into service.
- AI regulatory sandbox
- A controlled experimentation and testing environment for innovative AI systems during development and the pre-marketing phase, operating under regulatory oversight.
- post-market monitoring
- A system that all providers should have in place to learn from use after market placement or putting into service and to support timely corrective action.
- single point of contact
- The market surveillance authority that each Member State should designate for communication with the public and other Member State and Union counterparts.
- substantial modification
- A change whose notion and occurrence should be covered in sandbox supervision because it may require a new conformity assessment procedure.
- quality management system
- An obligation identified in Recital (146) as especially costly; microenterprises may fulfil it in a simplified manner under the conditions described there.
- market surveillance authority
- A national competent authority involved in supervising application and implementation; one should be designated by each Member State as the single point of contact.