Skip to content

Regulation Tracker / EU AI Act / Chapter VI

Article 57
AI regulatory sandboxes

Chapter VI — AI regulatory sandboxes. 21 distinct duties, powers or definitions are coded from this article, applying from 2026-08-02 and 2027-08-02.

Amended by Regulation (EU) 2026/1744 (Digital Omnibus on AI), in force 2026-07-27 — about 331 words changed. The text below is the consolidated version of 27 July 2026; the 2024 text and the amending regulation are on EUR-Lex. 1 of the duties below now apply later than Article 113 originally provided; each shows both dates.

official text: EUR-Lex (consolidated 27 Jul 2026) · text © European Union (Decision 2011/833/EU) · coding CC BY 4.0 · data: obligations.json · Hugging Face · GitHub

The text

1. Member States shall ensure that their competent authorities establish at least one AI regulatory sandbox at national level, which shall be operational by 2 August 2027. That sandbox may also be established jointly with the competent authorities of other Member States. The Commission may provide technical support, advice and tools for the establishment and operation of AI regulatory sandboxes.

2. Additional AI regulatory sandboxes at regional or local level, or established jointly with the competent authorities of other Member States may also be established.

3. The European Data Protection Supervisor may establish an AI regulatory sandbox for Union institutions, bodies, offices and agencies. For this purpose, references to national competent authorities in this Chapter shall be construed as references to the European Data Protection Supervisor.

3a. The AI Office may establish an AI regulatory sandbox at Union level for AI systems covered by Article 75(1). For this purpose, references to national competent authorities in this Chapter shall be construed, where relevant, as references to the AI Office. That AI regulatory sandbox shall be implemented in close cooperation with relevant competent authorities, in particular where compliance with Union legislation other than this Regulation is supervised in the AI regulatory sandbox, and shall provide priority access to SMEs, including start-ups, and SMCs.

4. Member States shall ensure that the competent authorities referred to in paragraphs 1 and 2 allocate sufficient resources to comply with this Article effectively and in a timely manner. Where appropriate, national competent authorities shall cooperate with other relevant authorities, and may allow for the involvement of other actors within the AI ecosystem. This Article shall not affect other regulatory sandboxes established under Union or national law. Member States shall ensure an appropriate level of cooperation between the authorities supervising those other sandboxes and the national competent authorities.

5. AI regulatory sandboxes established under this Article shall provide for a controlled environment that fosters innovation and facilitates the development, training, testing and validation of innovative AI systems for a limited time before their being placed on the market or put into service pursuant to a specific sandbox plan agreed between the providers or prospective providers and the competent authorities, ensuring that appropriate safeguards are in place. Such sandboxes may include testing in real world conditions supervised therein. Where applicable, the sandbox plan shall incorporate the real-world testing plan referred to in Articles 60 and 60a.

6. Competent authorities shall provide, as appropriate, guidance, supervision and support within the AI regulatory sandbox with a view to identifying risks, in particular to fundamental rights, health and safety, testing, mitigation measures, and their effectiveness in relation to the obligations and requirements of this Regulation and, where relevant, other Union and national law supervised within the sandbox.

7. Competent authorities shall provide providers and prospective providers participating in the AI regulatory sandbox with guidance on regulatory expectations and how to fulfil the requirements and obligations set out in this Regulation.

8. Subject to the confidentiality provisions in Article 78, and with the agreement of the provider or prospective provider, the Commission and the Board shall be authorised to access the exit reports and shall take them into account, as appropriate, when exercising their tasks under this Regulation. If both the provider or prospective provider and the national competent authority explicitly agree, the exit report may be made publicly available through the single information platform referred to in this Article.

9. The establishment of AI regulatory sandboxes shall aim to contribute to the following objectives:

  1. (a)improving legal certainty to achieve regulatory compliance with this Regulation or, where relevant, other applicable Union and national law;
  2. (b)supporting the sharing of best practices through cooperation with the authorities involved in the AI regulatory sandbox;
  3. (c)fostering innovation and competitiveness and facilitating the development of an AI ecosystem;
  4. (d)contributing to evidence-based regulatory learning;
  5. (e)facilitating and accelerating access to the Union market for AI systems, in particular when provided by SMEs, including start-ups, and SMCs.

10. National competent authorities shall ensure that, to the extent the innovative AI systems involve the processing of personal data or otherwise fall under the supervisory remit of other national authorities or competent authorities providing or supporting access to data, the competent data protection authorities and those other national or competent authorities are associated with the operation of the AI regulatory sandbox and involved in the supervision of those aspects to the extent of their respective tasks and powers.

11. The AI regulatory sandboxes shall not affect the supervisory or corrective powers of the competent authorities supervising the sandboxes, including at regional or local level. Any significant risks to health and safety and fundamental rights identified during the development and testing of such AI systems shall result in an adequate mitigation. National competent authorities shall have the power to temporarily or permanently suspend the testing process, or the participation in the sandbox if no effective mitigation is possible, and shall inform the AI Office of such decision. National competent authorities shall exercise their supervisory powers within the limits of the relevant law, using their discretionary powers when implementing legal provisions in respect of a specific AI regulatory sandbox project, with the objective of supporting innovation in AI in the Union.

12. Providers and prospective providers participating in the AI regulatory sandbox shall remain liable under applicable Union and national liability law for any damage inflicted on third parties as a result of the experimentation taking place in the sandbox. However, provided that the prospective providers observe the specific plan and the terms and conditions for their participation and follow in good faith the guidance given by the national competent authority, no administrative fines shall be imposed by the authorities for infringements of this Regulation. Where other competent authorities responsible for other Union and national law were actively involved in the supervision of the AI system in the sandbox and provided guidance for compliance, no administrative fines shall be imposed regarding that law.

13. The AI regulatory sandboxes shall be designed and implemented in such a way that, where relevant, they facilitate cross-border cooperation between national competent authorities.

14. National competent authorities, the European Data Protection Supervisor and the AI Office, shall, as appropriate and within their respective competences, coordinate their activities and cooperate within the framework of the Board. They may support the joint establishment and operation of AI regulatory sandboxes, including in different sectors, and exchange best practices on related matters.

15. National competent authorities shall inform the AI Office and the Board of the establishment of a sandbox, and may ask them for support and guidance. The AI Office shall make publicly available a list of planned and existing sandboxes and keep it up to date in order to encourage more interaction in the AI regulatory sandboxes and cross-border cooperation.

16. National competent authorities shall submit annual reports to the AI Office and to the Board, from one year after the establishment of the AI regulatory sandbox and every year thereafter until its termination, and a final report. Those reports shall provide information on the progress and results of the implementation of those sandboxes, including best practices, incidents, lessons learnt and recommendations on their setup and, where relevant, on the application and possible revision of this Regulation, including its delegated and implementing acts, and on the application of other Union law supervised by the competent authorities within the sandbox. The national competent authorities shall make those annual reports or abstracts thereof available to the public, online. The Commission shall, where appropriate, take the annual reports into account when exercising its tasks under this Regulation.

17. The Commission shall develop a single and dedicated interface containing all relevant information related to AI regulatory sandboxes to allow stakeholders to interact with AI regulatory sandboxes and to raise enquiries with competent authorities, and to seek non-binding guidance on the conformity of innovative products, services, business models embedding AI technologies, in accordance with Article 62(1), point (c). The Commission shall proactively coordinate with national competent authorities, where relevant.

What it requires, coded

SafeLegalAI's reading of each duty in this article: who, what, from when, under which fine tier, and whether it reaches a firm, chambers, court or legal-AI vendor. Descriptive, not advice; the quoted words are the Regulation's.

  1. Art. 57(1)Support measureNot tier-specific

    Member States must ensure their competent authorities establish at least one national AI regulatory sandbox, operational by 2 August 2027; it may be established jointly with other Member States.

    "Member States shall ensure that their competent authorities establish at least one AI regulatory sandbox at national level, which shall be operational by 2 August 2027"
    Who
    Member State
    From
    (Art. 57(1) operational deadline as amended by Reg. (EU) 2026/1744)As enacted in 2024: (Art. 113 second subparagraph; Art. 57(1) as enacted required operation by 2 August 2026); deferred by Regulation (EU) 2026/1744 (Digital Omnibus on AI).
    Legal practice
    Institutional — Sandbox availability may help legal-AI providers test innovative systems, but this is a Member State infrastructure duty.
  2. Art. 57(1)Support measureNot tier-specific

    The Commission may provide technical support, advice and tools for the establishment and operation of AI regulatory sandboxes.

    "The Commission may provide technical support, advice and tools for the establishment and operation of AI regulatory sandboxes"
    Who
    Commission
    From
    (Art. 113 second subparagraph)
    Legal practice
    Institutional — Institutional support with indirect benefit for legal-AI innovators using sandboxes.
  3. Art. 57(2)Support measureNot tier-specific

    Additional AI regulatory sandboxes may be established at regional or local level, or jointly with competent authorities of other Member States.

    "Additional AI regulatory sandboxes at regional or local level, or established jointly with the competent authorities of other Member States may also be established"
    Who
    Member State, National competent authority
    From
    (Art. 113 second subparagraph)
    Legal practice
    Institutional — Additional sandbox capacity may indirectly support legal-AI providers.
  4. Art. 57(3)Support measureNot tier-specific

    The European Data Protection Supervisor may establish an AI regulatory sandbox for Union institutions, bodies, offices and agencies, with Chapter VI references to national competent authorities construed accordingly.

    "The European Data Protection Supervisor may establish an AI regulatory sandbox for Union institutions, bodies, offices and agencies"
    Who
    Union institution
    From
    (Art. 113 second subparagraph)
    Legal practice
    Institutional — Relevant mainly to EU institutions, with indirect legal-practice relevance for EU public-sector legal functions.
    See
    Chapter VI
  5. Art. 57(3a)Support measureNot tier-specific

    The AI Office may establish a Union-level AI regulatory sandbox for Article 75(1) systems, in close cooperation with relevant authorities and with priority access for SMEs, start-ups and SMCs.

    "The AI Office may establish an AI regulatory sandbox at Union level for AI systems covered by Article 75(1)"
    Who
    AI Office
    From
    (Art. 113 second subparagraph)
    Legal practice
    Institutional — Union-level sandbox may indirectly assist legal-AI SMEs and start-ups whose systems fall under Article 75(1).
    See
    Art. 75(1)
  6. Art. 57(4)Governance institutionalNot tier-specific

    National competent authorities may cooperate with other relevant authorities and involve other AI-ecosystem actors; Member States must ensure cooperation between supervisors of other sandboxes and national competent authorities.

    "Member States shall ensure an appropriate level of cooperation between the authorities supervising those other sandboxes and the national competent authorities"
    Who
    Member State, National competent authority
    From
    (Art. 113 second subparagraph)
    Legal practice
    Institutional — Coordination of sandbox authorities indirectly affects legal-AI innovators seeking multi-regime guidance.
  7. Art. 57(4)Governance institutionalNot tier-specific

    Member States must ensure competent authorities allocate sufficient resources to comply with Article 57 effectively and in a timely manner.

    "Member States shall ensure that the competent authorities referred to in paragraphs 1 and 2 allocate sufficient resources to comply with this Article effectively and in a timely manner"
    Who
    Member State
    From
    (Art. 113 second subparagraph)
    Legal practice
    Institutional — Governance resource duty that indirectly supports sandbox access for legal-AI providers.
    See
    Art. 57(1) · Art. 57(2)
  8. Art. 57(5)Support measureNot tier-specific

    AI regulatory sandboxes must provide a controlled environment that supports development, training, testing and validation of innovative AI systems for a limited time before market placement or service, under an agreed plan with safeguards.

    "AI regulatory sandboxes established under this Article shall provide for a controlled environment that fosters innovation and facilitates the development, training, testing and validation of innovative AI systems"
    Who
    National competent authority
    From
    (Art. 113 second subparagraph)
    Legal practice
    Reaches legal-AI vendors or public bodies — Relevant to legal-AI providers using sandboxes to develop or test innovative legal-sector AI systems.
    See
    Art. 57 sandbox plan
  9. Art. 57(5)DocumentationNot tier-specific

    Where a sandbox includes testing in real world conditions, the sandbox plan must incorporate the real-world testing plan referred to in Articles 60 and 60a where applicable.

    "Where applicable, the sandbox plan shall incorporate the real-world testing plan referred to in Articles 60 and 60a"
    Who
    Provider, National competent authority
    From
    (Art. 113 second subparagraph)
    Fine tier
    Art. 99(4)
    Legal practice
    Reaches legal-AI vendors or public bodies — Relevant to legal-AI providers conducting sandbox-based real-world testing.
    See
    Art. 60 · Art. 60a
  10. Art. 57(6)Support measureNot tier-specific

    Competent authorities must provide guidance, supervision and support within AI regulatory sandboxes to identify risks, testing, mitigation measures and their effectiveness under the AI Act and other supervised law.

    "Competent authorities shall provide, as appropriate, guidance, supervision and support within the AI regulatory sandbox with a view to identifying risks"
    Who
    National competent authority
    From
    (Art. 113 second subparagraph)
    Legal practice
    Institutional — Sandbox guidance may help legal-AI providers understand regulatory expectations.
  11. Art. 57(7)Support measureNot tier-specific

    Competent authorities must provide participating providers and prospective providers with guidance on regulatory expectations and how to fulfil AI Act requirements and obligations.

    "Competent authorities shall provide providers and prospective providers participating in the AI regulatory sandbox with guidance on regulatory expectations and how to fulfil the requirements and obligations set out in this Regulation"
    Who
    National competent authority
    From
    (Art. 113 second subparagraph)
    Legal practice
    Reaches legal-AI vendors or public bodies — Directly useful to legal-AI providers participating in a sandbox.
  12. Art. 57(8)Governance institutionalNot tier-specific

    Subject to confidentiality and provider agreement, the Commission and Board may access sandbox exit reports and consider them when performing AI Act tasks; an exit report may be made public if both provider and authority agree.

    "the Commission and the Board shall be authorised to access the exit reports and shall take them into account, as appropriate, when exercising their tasks under this Regulation"
    Who
    Commission, AI Board
    From
    (Art. 113 second subparagraph)
    Legal practice
    Institutional — Exit reports may inform AI Act governance affecting legal-AI sandbox participants.
    See
    Art. 78
  13. Art. 57(9)Support measureNot tier-specific

    AI regulatory sandboxes must aim to improve legal certainty, share best practices, foster innovation and competitiveness, support evidence-based regulatory learning, and facilitate and accelerate Union-market access, especially for SMEs, start-ups and SMCs.

    "The establishment of AI regulatory sandboxes shall aim to contribute to the following objectives:"
    Who
    Member State, National competent authority
    From
    (Art. 113 second subparagraph)
    Legal practice
    Institutional — Sandbox objectives may benefit legal-AI SMEs and start-ups but are principally institutional.
  14. Art. 57(10)Data governanceNot tier-specific

    National competent authorities must associate data protection authorities and other competent authorities with sandbox operation and supervision when innovative AI systems involve personal-data processing or fall within those authorities’ remits.

    "National competent authorities shall ensure that, to the extent the innovative AI systems involve the processing of personal data or otherwise fall under the supervisory remit of other national authorities"
    Who
    National competent authority
    From
    (Art. 113 second subparagraph)
    Legal practice
    Reaches legal-AI vendors or public bodies — Relevant to legal-AI sandbox projects processing client, employee, court, or public-sector personal data.
    See
    Regulation (EU) 2016/679
  15. Art. 57(11)Enforcement powerNot tier-specific

    Significant health, safety or fundamental-rights risks identified during sandbox development and testing must be adequately mitigated; national competent authorities may temporarily or permanently suspend testing or participation if effective mitigation is impossible and must inform the AI Office.

    "Any significant risks to health and safety and fundamental rights identified during the development and testing of such AI systems shall result in an adequate mitigation"
    Who
    National competent authority
    From
    (Art. 113 second subparagraph)
    Legal practice
    Reaches legal-AI vendors or public bodies — Relevant to legal-AI sandbox tests that may affect fundamental rights or access to justice.
    See
    AI Office
  16. Art. 57(12)Derogation or exemptionNot tier-specific

    Sandbox participants remain liable for third-party damage from experimentation, but no administrative fines are imposed for AI Act infringements when prospective providers follow the plan, participation terms and good-faith authority guidance.

    "Providers and prospective providers participating in the AI regulatory sandbox shall remain liable under applicable Union and national liability law for any damage inflicted on third parties"
    Who
    Provider
    From
    (Art. 113 second subparagraph)
    Legal practice
    Reaches legal-AI vendors or public bodies — Relevant to legal-AI providers experimenting in sandboxes because liability remains despite fine relief.
    See
    Art. 57 sandbox plan
  17. Art. 57(13)Governance institutionalNot tier-specific

    AI regulatory sandboxes must be designed and implemented so that, where relevant, they facilitate cross-border cooperation between national competent authorities.

    "The AI regulatory sandboxes shall be designed and implemented in such a way that, where relevant, they facilitate cross-border cooperation between national competent authorities"
    Who
    National competent authority
    From
    (Art. 113 second subparagraph)
    Legal practice
    Institutional — Cross-border sandbox cooperation may indirectly help legal-AI providers operating in multiple Member States.
  18. Art. 57(14)Governance institutionalNot tier-specific

    National competent authorities, the EDPS and the AI Office must coordinate and cooperate within the Board framework, and may support joint sandbox establishment, operation and exchange of best practices.

    "National competent authorities, the European Data Protection Supervisor and the AI Office, shall, as appropriate and within their respective competences, coordinate their activities and cooperate within the framework of the Board"
    Who
    National competent authority, Union institution, AI Office, AI Board
    From
    (Art. 113 second subparagraph)
    Legal practice
    Institutional — Institutional coordination may improve sandbox consistency for legal-AI providers.
    See
    AI Board
  19. Art. 57(15)Governance institutionalNot tier-specific

    National competent authorities must inform the AI Office and Board when establishing a sandbox and may ask for support; the AI Office must publish and update a list of planned and existing sandboxes.

    "National competent authorities shall inform the AI Office and the Board of the establishment of a sandbox, and may ask them for support and guidance"
    Who
    National competent authority, AI Office
    From
    (Art. 113 second subparagraph)
    Legal practice
    Institutional — Public sandbox information helps legal-AI innovators identify available sandboxes.
    See
    AI Board
  20. Art. 57(16)MonitoringNot tier-specific

    National competent authorities must submit annual and final sandbox reports to the AI Office and Board, publish the reports or abstracts online, and the Commission must consider them where appropriate when exercising AI Act tasks.

    "National competent authorities shall submit annual reports to the AI Office and to the Board, from one year after the establishment of the AI regulatory sandbox and every year thereafter until its termination, and a final report"
    Who
    National competent authority, Commission
    From
    (Art. 113 second subparagraph)
    Legal practice
    Institutional — Sandbox reporting may indirectly surface lessons for legal-AI systems tested in sandboxes.
    See
    AI Office · AI Board
  21. Art. 57(17)Support measureNot tier-specific

    The Commission must develop a single dedicated interface containing relevant sandbox information so stakeholders can interact with sandboxes, raise enquiries and seek non-binding guidance on conformity of innovative AI-embedded offerings.

    "The Commission shall develop a single and dedicated interface containing all relevant information related to AI regulatory sandboxes to allow stakeholders to interact with AI regulatory sandboxes"
    Who
    Commission
    From
    (Art. 113 second subparagraph)
    Legal practice
    Institutional — The interface may help legal-AI providers find sandbox contacts and non-binding conformity guidance.
    See
    Art. 62(1)(c)

Cite

Regulation (EU) 2024/1689, Article 57 (AI regulatory sandboxes), as amended by Regulation (EU) 2026/1744, consolidated text of 27 July 2026, https://eur-lex.europa.eu/eli/reg/2024/1689/2026-07-27/eng#art_57 — text © European Union; only the Official Journal is authentic. Coding: SafeLegalAI (published by Cognesio LLP), "EU AI Act, structured", safelegalai.com/regulation/eu-ai-act/article-57, accessed 2026-09-08, CC BY 4.0.