SkarpSkarp

Chapter 18 of 25

Sandboxes and Testing in Real-World Conditions

Innovation moves from principle to supervised procedure in Chapter VI. Articles 57–61 establish sandbox access, protected personal-data processing and tightly controlled real-world testing, including plans, consent, incident response and continuing liability.

18 min readen

Chapter VI: The Innovation Pathway

Two supervised routes

Articles 57-61 establish an AI regulatory sandbox route and a separate route for real-world testing outside sandboxes. Neither route removes responsibility or turns experimentation into an unregulated activity.

National sandbox duty

Article 57(1) says Member States shall ensure authorities "establish at least one AI regulatory sandbox at national level, which shall be operational by 2 August 2026". Joint or equivalent-coverage arrangements are permitted.

Currency note

The 8 July 2026 Digital Omnibus on AI, PE-CONS 30/26, is signedpendingpublication and affects Articles 56-60a. It is not in force, so this module teaches the source text's original requirements.

Article 57: What a Sandbox Is and Who Supervises It

A controlled, time-limited setting

Article 57(5) requires "a controlled environment that fosters innovation and facilitates the development, training, testing and validation of innovative AI systems for a limited time" under a sandbox plan agreed with the competent authority.

Not merely a workspace

Competent authorities shall provide guidance, supervision, and support as appropriate. They examine risks, especially to fundamental rights, health, and safety, alongside testing and mitigation measures.

Institutional coordination

Member States shall provide sufficient resources. Authorities shall cooperate where appropriate, including with authorities supervising other regulatory sandboxes and, where relevant, other actors in the AI ecosystem.

Worked Example: A Public-Service Triage Tool in a Sandbox

Plan before experimentation

A municipal triage tool can enter a sandbox only through a specific plan agreed by the provider or prospective provider and the competent authority. The plan frames the time-limited development, training, testing, and validation work.

Bring the right supervisors in

Where personal data or another authority's remit is involved, Article 57(10) requires the relevant data-protection and other competent authorities to be associated with supervision within their powers.

A sandbox can be stopped

Significant risks to health and safety or fundamental rights shall receive adequate mitigation. If no effective mitigation is possible, the national competent authority may suspend testing or participation and shall inform the AI Office.

Knowledge Check: Sandbox Status

Choose the statement that best reflects Article 57.

Which statement is correct under Article 57?

  1. A sandbox removes the provider's liability for damage caused during experimentation.
  2. A sandbox is a time-limited controlled environment under a specific plan agreed with the competent authority.
  3. Only the Commission may establish an AI regulatory sandbox.
  4. Once admitted, a participant cannot be suspended from a sandbox.
Show Answer

Answer: B) A sandbox is a time-limited controlled environment under a specific plan agreed with the competent authority.

Article 57(5) describes a controlled, limited-time environment operating under a specific agreed sandbox plan. Article 57(11) permits suspension where effective mitigation is not possible, while Article 57(12) keeps liability law applicable.

Articles 57(7)-(17) and 58: Evidence, Access, and Governance

Exit evidence, not immunity

On request, successful sandbox activities require written proof. "The competent authority shall also provide an exit report detailing the activities carried out in the sandbox and the related results and learning outcomes."

Access and timing

Article 58 requires transparent, fair eligibility and selection criteria. It states that "national competent authorities inform applicants of their decision within three months of the application".

SME-focused design

"access to the AI regulatory sandboxes is free of charge for SMEs, including start-ups" subject to fair and proportionate recovery of exceptional costs. Procedures shall be simple, intelligible, and clearly communicated.

Flashcards: Sandbox Governance

Flip each card, then explain how the term changes a participant's practical position.

Sandbox plan
The specific plan agreed between the provider or prospective provider and the competent authority for the limited-time sandbox activity.
Exit report
A report the competent authority shall provide, detailing sandbox activities and related results and learning outcomes.
Written proof
On request, proof from the competent authority of activities successfully carried out in the sandbox.
SME access
Access is free of charge for SMEs, including start-ups, except fair and proportionate recovery of exceptional costs.
Annual reporting
National competent authorities submit annual reports to the AI Office and Board from one year after sandbox establishment, every year until termination, plus a final report.

Article 59: Personal Data in the Sandbox

A cumulative gateway

Article 59 permits further use only where all conditions apply: "personal data lawfully collected for other purposes may be processed solely for the purpose of developing, training and testing certain AI systems in the sandbox".

Public interest and necessity

The project shall safeguard substantial public interest in listed areas. Data must be necessary for Chapter III, Section 2 requirements that cannot effectively be fulfilled with anonymised, synthetic, or other non-personal data.

Contain the data

The data must be in "a functionally separate, isolated and protected data processing environment under the control of the prospective provider". Only authorised persons may access them, and sandbox-created data cannot leave the sandbox.

Worked Example: Disease-Detection Model and Data Boundaries

Why this hospital case may qualify

Disease detection is expressly within Article 59's public-health area. But that is only one condition: the hospital must also establish necessity and show why non-personal alternatives cannot effectively fulfil the relevant requirements.

No operational decisions about subjects

Sandbox processing neither leads to measures or decisions affecting data subjects nor affects their rights under Union personal-data law. The sandbox is for development, training, and testing, not for acting on patients.

Deletion and documentation

Personal data are protected and deleted when participation ends or retention ends. Logs, detailed rationale, testing results, technical documentation, and a public project summary create an accountability trail.

Article 60: Starting Real-World Testing Outside a Sandbox

Who can use Article 60?

Article 60 covers providers and prospective providers testing Annex III high-risk AI systems before market placement or service. It does not override Article 5 prohibitions, relevant product-law rules, or legally required ethical review.

Plan and approval

A real-world testing plan shall be submitted to the market-surveillance authority in the Member State of testing. Approval is required, subject to the source text's national-law qualification for tacit approval.

Thirty days and registration

"where the market surveillance authority has not provided an answer within 30 days, the testing in real world conditions and the real-world testing plan shall be understood to have been approved" where national law allows tacit approval. Registration rules also apply.

Worked Example: Testing an AI Hiring Tool

Partnership needs an agreement

Where testing is organised with a deployer or prospective deployer, parties shall agree their roles and responsibilities. The deployer must receive relevant testing information and Article 13 instructions for use.

A hard outer time limit

Testing must be necessary in duration and is "not longer than six months, which may be extended for an additional period of six months" with prior notification and an explanation of need.

Make outcomes reversible

Article 60 requires that "the predictions, recommendations or decisions of the AI system can be effectively reversed and disregarded". A tested recommendation must not become an irreversible real-world outcome.

Articles 60-61: Consent, Incidents, Withdrawal, and Liability

Meaningful, documented consent

"freely-given informed consent shall be obtained from the subjects of testing prior to their participation in such testing". Article 61 specifies the information that must be given, and consent shall be dated, documented, and copied to the subject.

Withdrawal is real

A subject may "withdraw from the testing at any time by revoking their informed consent and may request the immediate and permanent deletion of their personal data" without detriment or justification.

If something goes seriously wrong

Serious incidents shall be reported. The provider shall mitigate immediately or suspend testing until mitigation occurs, otherwise terminate it and establish a prompt-recall procedure. Liability for damage remains applicable.

Final Check: Real-World Testing

Apply Articles 60 and 61 to select the best answer.

A provider receives no response 30 days after submitting its real-world testing plan. What does Article 60(4)(b) say?

  1. Testing is always automatically approved throughout the Union.
  2. Testing is automatically rejected.
  3. The testing and plan are understood to be approved, unless national law does not provide for tacit approval; in that case, authorisation remains required.
  4. The provider may test only inside an AI regulatory sandbox.
Show Answer

Answer: C) The testing and plan are understood to be approved, unless national law does not provide for tacit approval; in that case, authorisation remains required.

Article 60(4)(b) sets a 30-day tacit-approval rule, but expressly preserves national law that does not provide for tacit approval. Where that national-law condition applies, the testing remains subject to authorisation.

Key Terms

exit report
A report detailing sandbox activities and the related results and learning outcomes.
sandbox plan
The specific plan agreed between a provider or prospective provider and the competent authority for sandbox participation.
reversibility
The Article 60 requirement that AI-system predictions, recommendations, or decisions can be effectively reversed and disregarded.
tacit approval
The Article 60 rule under which lack of an answer within 30 days means testing and its plan are understood to be approved, unless national law does not provide for that mechanism.
informed consent
Freely given consent obtained before participation after specified clear and understandable information has been provided.
competent authority
The authority responsible for relevant sandbox functions and supervision under the source text.
prospective provider
An entity preparing to provide an AI system and eligible, alongside a provider, to participate in the processes described in these Articles.
AI regulatory sandbox
A controlled, time-limited setting under a specific sandbox plan in which innovative AI systems may be developed, trained, tested, and validated with competent-authority guidance and supervision.
real-world testing plan
The plan a provider or prospective provider shall submit for Article 60 testing outside a sandbox.
market surveillance authority
The authority that approves, oversees, inspects, and may receive notifications concerning real-world testing under Article 60.

Finished reading?

Test your understanding with a custom practice exam on this chapter.

Test yourself