The EU’s list of AI sandboxes was due yesterday. We could not find it
6 min read
Yesterday, 2 August 2026, a different obligation kicked in from the one covered here yesterday: not the Member States’ duty — that one has slipped to 2027 — but the Commission’s. Article 57(15) of Regulation (EU) 2024/1689 (the AI Act), verified on the text downloaded from Cellar, reads: “The AI Office shall make publicly available a list of planned and existing sandboxes and keep it up to date in order to encourage more interaction in the AI regulatory sandboxes and cross-border cooperation.” This paragraph has not been postponed. We did not find it published.
Why yesterday, precisely
Article 57 sits in Chapter VI of the AI Act, “Measures in support of innovation”. Article 113 sets the application dates: the general rule is “It shall apply from 2 August 2026”, with strict exceptions for specific chapters. In the original text there were three — point (a) Chapters I and II from 2 February 2025; point (b) Chapter III, Section 4, Chapter V, Chapter VII, Chapter XII and Article 78 from 2 August 2025; point (c) Article 6(1) from 2 August 2027 — and Chapter VI appeared in none of them. The Omnibus (Regulation (EU) 2026/1744) touched exactly these exceptions, in Article 1, point 40: it replaced point (a) and point (c) — the latter now staggers the substantive high-risk obligations to 2 December 2027 and 2 August 2028 — and added a new point (d), for Articles 102 to 110, from 27 July 2026. Even in the rewritten version, Chapter VI stays outside every exception, and recital 40 of the same Omnibus confirms that “the general date of application is 2 August 2026” — unchanged. The duty under paragraph 15 has therefore been in force since yesterday, not from some date a later amendment moved.
What the Omnibus changed in Article 57 — and what it did not
Point 22 of the same Article 1 rewrites seven parts of Article 57, letter by letter: (a) replaces the first subparagraph of paragraph 1, pushing the national obligation already covered yesterday to 2027; (b) replaces paragraph 3, on the European Data Protection Supervisor; (c) inserts a new paragraph 3a, which for the first time lets the AI Office itself set up a Union-level sandbox, but only for systems based on models developed by the same provider under Article 75(1) — in practice, the large frontier models; (d) replaces paragraph 5, widening its scope from paragraph 1 alone to the whole article; (e) replaces point (e) of paragraph 9, adding small mid-cap companies among the beneficiaries of market access; (f) replaces paragraph 10, widening from “national data protection authorities” to “competent data protection authorities”; (g) replaces paragraph 14, bringing the European Data Protection Supervisor and the AI Office into the coordination duty between authorities.
Paragraph 15 does not appear in any of the seven points. It was not touched, here or anywhere else in the text we checked.
Where we looked, and with what result
The method, disclosed in full: the sitemap of digital-strategy.ec.europa.eu (805 URLs, no entry dedicated to a sandbox “list”); the pages “Ecosystem for AI innovation in Europe”, “European AI Office” and “Governance and enforcement of the AI Act”; the homepage of the AI Act Service Desk and, above all, its dedicated page on Article 57, which quotes paragraph 15 word for word but links to no list; the sandbox page of the European Digital Innovation Hubs network. None of these six holds a searchable register. We did not trust the site’s full-text search — the results counter stays identical even for terms that do not exist — nor did we stop at one query: we also checked Google News (7 days) and DuckDuckGo, which surfaces pages on individual national sandboxes already announced (Spain) but no Union-wide register. Said with the correct formula: not findable by this method, not “does not exist”. It may sit behind an interface our search did not reach.
The link that does exist points to a project, not a register
The “AI Regulatory Sandboxes” entry on the “Ecosystem for AI innovation in Europe” page leads to exactly one place: eusair-project.eu. The project’s own official description, in English, reads: “Supporting the implementation of AI regulatory sandboxes across the EU to foster innovation, reduce barriers, and enhance compliance under the AI Act.” It supports the rollout of the sandboxes the AI Act calls for — it is not the register the AI Office must keep. It is a project funded under the Digital Europe Programme, with a consortium made up of ICSC, ACN, UNIBO, CINECA and UNIFI (Italy), BSC and LOBA (Spain), ALLAI, the European DIGITAL SME Alliance, TÜV AI.Lab (Germany), CSC and the University of Turku (Finland). Its operational trials — up to 90 use cases across health, finance, education and manufacturing — ran between October 2025 and March 2026, in two cohorts already closed by the time of this article. The site’s footer still reads “© 2025 EUSAiR”.
What this means for whoever has to decide
It is the same logic as today’s piece on what an “abliterated” model actually is and yesterday’s on the agent that picked its own vulnerability: an assessment, a list, a guarantee always refers to a precise object — and when that object is not the one in front of you, or is not there at all, the checking falls to whoever must decide, not to whoever was supposed to publish it. A list can be missing for entirely ordinary reasons: a technical delay, an interface not yet online, a different priority in the office that must keep it. No reading of intent here. But the fact stands: anyone who today has to choose an AI vendor and wants to know how many sandboxes actually exist in Europe, and which, will not find it written anywhere with a link to prove it.
How we deal with it
When the public register is missing, the checking does not disappear: it moves. It falls to whoever buys or integrates an AI system to build it themselves — on the vendor, on the environment it was tested in, on the gap between what is promised and what the register was supposed to certify — and to leave a trail: not a one-off opinion but a check that runs on the client’s own documents and systems, ready to be shown the day an inspection comes, even where no public authority has ever kept an up-to-date list. The same system, scaled up, holds together the data that today sit scattered — vendors, contracts, technical tests, outcomes — in a single operating model on which AI agents execute decisions with an operator in command: for large enterprises, defence, public administration and healthcare, that is the part that remains even once the list, one day, appears. It works in both delivery modes — on-premise, on autonomous machines that do not require deep integration into the client’s network, or dedicated cloud with a data centre in Italy — and always with shared management: whoever starts a project like this does not need to already have someone in-house running AI systems. That is the principle behind our platform.
Want to know whether the vendor you are assessing would have passed a sandbox you cannot even look up today? Half an hour with one of our experts is enough for a first map.
Sources
- Regulation (EU) 2024/1689 (AI Act), Articles 57 and 113 (EUR-Lex/Cellar, CELEX 32024R1689)
- Regulation (EU) 2026/1744 — Digital Omnibus on AI, Article 1(22) and 1(40), recital 40 (EUR-Lex/Cellar, CELEX 32026R1744)
- European Commission, “Ecosystem for AI innovation in Europe” — AI Regulatory Sandboxes
- AI Act Service Desk — Article 57: AI regulatory sandboxes
- EUSAiR — project funded under the Digital Europe Programme