Skip to content

Main Insight

The Future Society has been advocating for regulatory sandboxes to be implemented via the EU AI Act and designed a three-phase roll out program.

TFS champions Regulatory Sandboxes in the EU AI Act

June 28, 2022

What are regulatory sandboxes?

Since early 2020, The Future Society (TFS) has been advocating for regulatory sandboxes to be implemented in the EU legislative ecosystem. Regulatory sandboxes are programs that enable entrepreneurs to test new products and services in the market while maintaining close rapport with regulators. Sometimes, entrepreneurs’ regulatory obligations are temporarily reduced to provide authorities the chance to understand the technological environment and design and enforce more effective, tailor-made safeguards.

If properly designed and managed, regulatory sandboxes can fulfill multiple functions, such as providing:

  • Monitored regulatory flexibility for entrepreneurs to “live” test their innovations on the market.
  • Regulators with a better understanding of cutting-edge technologies, value chains, and business models.
  • Customers (B2B or B2C) with the confidence to do business with disruptive technology providers.

Regulatory sandboxes have proved beneficial across a broad range of sectors undergoing digitalization over the past 15 years, including finance, energy, health, transportation, and legal services. However, their effectiveness—for regulators, entrepreneurs, and society at large—depends on careful design, engineering, and management. For example, undue influence on the selection process, lack of safeguards, or miscalibrated scope could undermine the rule of law or create anti-competitive distortions. Regulatory sandboxes are also resource-intensive, so return on investment must be carefully assessed. That is why TFS has advocated not only for the implementation of regulatory sandboxes but also for specific design features to improve their likelihood of success.

Our work on regulatory sandboxes in the EU

In February 2020, the European Commission published a White Paper on Artificial Intelligence. In response, TFS published a memo titled “Experimentation, testing & audit as a cornerstone for trust and excellence,” advocating for numerous changes including the addition of regulatory sandboxes, which, notably, were not referenced in the white paper.

When the European Commission’s proposed AI Act was unveiled in April 2021, we were pleased to see regulatory sandboxes included as a measure to “reduce the regulatory burden and to support Small and Medium-Sized Enterprises (‘SMEs’) and start-ups.” However, details concerning the rollout plan were left open for discussion. To aid in clarifying these concepts, in August 2021, TFS published a memo titled “Trust in Excellence & Excellence in Trust”, which called for a more ambitious regulatory sandbox system, among other recommendations, such as testing and experimentation facilities, national- to EU-level information flows, and incident reporting, to foster innovative and agile governance.

Sandboxes without the quicksand

In February 2022, as the European Commission and the French Presidency of the Council both began to reflect on the design of the sandboxes system, TFS published a memo titled “Sandboxes without the quicksand: making EU AI sandboxing work for regulators, entrepreneurs and society.” In this memo, aimed to help policymakers implement regulatory sandboxes, we proposed a three-phase program:

  • Phase 1: Generate demand for sandboxes (2023-2024). Rolling out the basic features of the sandboxing ecosystem to generate demand for sandboxes from both entrepreneurs and regulators.
  • Phase 2: Boost regulators’ capacity & foresight and customers’ confidence (2025). Investing in the “institutional infrastructure” surrounding regulatory sandboxes to tap the value that a sandboxing system can generate for regulators and society at large.
  • Phase 3: Assess, improve, streamline and scale (2026). Evaluate and improve the ecosystem based on information generated by impact assessments, documentation processes, and the experience of the individuals involved. Determine whether the ecosystem is fulfilling its objectives, how to address any shortcomings, and what budget should be allocated for its near-term future.

In July 2022, our proposal was further institutionalized in a communication of the European Commission, The New European Innovation Agenda:

The Commission will issue a guidance document in the first half of 2023 that will clarify relevant use cases of regulatory sandboxes, test beds and living labs in order to support policymakers and innovators in their approach to experimentation in the EU. A staff working document will provide an overview of the main existing experimentation clauses and regulatory sandboxes in EU law, and support will be provided for innovators to identify areas and establish an experimentation space, such as regulatory sandboxes, living labs or test beds, which could facilitate the deployment of disruptive technologies through future calls

The Commission will also support the creation of the GovTech Incubator in 2023: an agreement for cross-border collaboration between digitalisation agencies for the deployment of innovative digital government solutions through Digital Europe programme.

In addition, the Commission will pilot an Innovation-Friendly Regulations Advisory Group, a group that provides upstream policy advice on new technologies in relation to the regulatory environment and business models, to focus on the use of advanced digital technologies within public services. This will include, in particular, the implementation of selected use cases in the public sector and interoperability requirements for digital solutions adopted by public administrations in the EU. Advice from the group may also support actions and programmes related to public procurement and experimentation with advanced emerging digital technologies by public authorities in controlled environments (regulatory sandboxes).”

We are honored that our research has been well-received by policymakers and that our recommendations for the design and operationalization of sandboxes are carried into negotiations within the European Parliament. We look forward to continuing to contribute to the development of regulatory sandboxes, among other innovative elements of the EU AI Act, as they are ironed out.

Are you an EU regulator or policymaker interested in learning more about regulatory sandboxes? Contact Nicolas Moës at nicolas.moes@thefuturesociety.org.


Feature image by DeepMind on Unsplash.

Team members

Nick Moës

Nick Moës

Samuel Curtis

Related resources

How To Make International AI Verification a Reality

How To Make International AI Verification a Reality

Countries outside the U.S.–China AI race can build the verification technologies needed to make an international agreement to slow AI development enforceable. This memo suggests research priorities.

What compute on European soil might buy Europe and what it depends on

What compute on European soil might buy Europe and what it depends on

Across Europe, there is growing appetite for locating large compute capacity at home. This post maps what the benefits' proponents claim such a buildout might bring and the key open questions these claims stand or fall on.

Buyer Beware: What AI-Enabled Weapons in Africa Reveal About Verification

Buyer Beware: What AI-Enabled Weapons in Africa Reveal About Verification

AI rules cannot reliably protect people when compliance cannot be checked. In a new CIGI policy brief co-authored by George Gor (TFS) and Kofi Yeboah (Mozilla), AI-enabled weapons in Africa serve as a case study of how procurement and regional verification can test supplier claims, reduce risks to civilians and...

The Case for Cross-Border AI Incident Infrastructure

The Case for Cross-Border AI Incident Infrastructure

AI incidents are scaling fast, and coordinated global governance is lagging behind. This report proposes addressing this challenge through the development of internationally-distributed incident management infrastructure. Our recommendations aim to enable governments, multilateral bodies, and frontier AI companies to jointly detect, prepare for, and respond to AI incidents across jurisdictions.

Determining the State of the Art in General-Purpose AI Risk Management: From Code to Practice

Determining the State of the Art in General-Purpose AI Risk Management: From Code to Practice

The EU's AI Act and Code of Practice requires providers of the most advanced AI models to meet the ‘state of the art’ (SOTA) in safety and security. In a new policy memo, we argue that SOTA is best understood as a process-driven concept, advanced by the broader expert ecosystem.

EU AI Act meets AI Agents

EU AI Act meets AI Agents

Highlights from Tech Policy Press article “The EU AI Act is Not Ready for Agents,” examining how the EU AI Act applies to AI agents and governance challenges.