Operational notes Observatory

Every Member State was due an AI sandbox by today. The AI Act deadline has slipped to 2027

8 min read

A black-and-white close-up of chain-link fencing, photographed up close with a blurred background
A bounded, supervised space to test in before going out into the world: that is what the AI Act asked for by today.

Today, 2 August 2026, every EU Member State was due to have at least one AI regulatory sandbox operational at national level. That was Article 57(1), first subparagraph of Regulation (EU) 2024/1689 (the AI Act), original text: “Member States shall ensure that their competent authorities establish at least one AI regulatory sandbox at national level, which shall be operational by 2 August 2026.” The deadline has been pushed back a year by a regulation that entered into force barely a week ago, and the sandbox provision is not the part that has made headlines.

What it actually is, and what it is for

An AI regulatory sandbox is not a free pass. Article 57(5) defines it as a “controlled environment that fosters innovation and facilitates the development, training, testing and validation of innovative AI systems for a limited time before their being placed on the market”, under a plan agreed with the competent authority. It may include real-world testing, always under supervision.

What it offers a company that enters one is set out in paragraph 7: the authority gives “guidance on regulatory expectations”, and on request provides “a written proof of the activities successfully carried out” plus “an exit report”, which providers can use to demonstrate compliance during assessment or market surveillance, to be “taken positively into account […] with a view to accelerating conformity assessment procedures to a reasonable extent”. Paragraph 12 adds a concrete safeguard: participants remain liable for damage to third parties under ordinary law, but if they follow the plan and act in good faith on the guidance given, the authority imposes no administrative fines for breaches of the Regulation. That is the difference between testing with someone watching and answering, and testing alone.

There is also a transparency duty that bears directly on this piece: paragraph 15 requires that “the AI Office shall make publicly available a list of planned and existing sandboxes and keep it up to date”. More on that shortly.

The postponement, verbatim

Regulation (EU) 2026/1744 — the Digital Omnibus on AI, in force since 27 July — intervenes right there. Article 1, point 22(a): “in paragraph 1, the first subparagraph is replaced by the following: ‘1. Member States shall ensure that their competent authorities establish at least one AI regulatory sandbox at national level, which shall be operational by 2 August 2027.’” Exactly one year’s extension, on the same sentence.

The Omnibus does not stop at the date: the same point 22 also opens the door to an EU-level sandbox run by the AI Office and strengthens coordination between authorities. But those are governance changes, explained by recitals 23-25 — which justify how sandboxes are coordinated, not why the date slips by a year. The postponement has no dedicated recital: it rests on the general reasoning of recital 2, a “compliance burden that is heavier than expected” caused by “the delayed preparation of standards” and “the delayed establishment of the governance and the conformity assessment frameworks at national level”, applied to the Regulation as a whole.

A more explicit reading, though not the text of the law itself, comes from a specialist legal analysis (Agenda Digitale, 12 June 2026): the postponement “takes into account the largely widespread delay in the designation of competent national authorities by the Member States” — without a designated authority, there is no one to open a sandbox. On the other side of the debate, European Digital Rights called the whole Omnibus package “a major rollback of EU digital protections”, criticising the postponement of high-risk obligations decided “without a clear timeline”. It does not single out Article 57, but the logic applies just the same: every postponement is more time in which a system reaches the market without the intended oversight.

How many states actually have one, today

Here the research produced more absences than answers, and we say so because the absence is itself a data point. Article 57(15) requires the AI Office to publish and keep up to date the list of existing and planned sandboxes. We looked for it on the AI Office’s own public pages, on the Testing and Experimentation Facilities section and on the Commission’s AI Act Service Desk: we did not find it — we cannot rule out that it exists behind a dynamic interface our search did not reach, but today it is not something a company can check with a link.

As far as we could verify, there is no official, primary-source tally of how many Member States actually have an operational sandbox. The only specific public data point we found is Italy’s, and it is negative (below). One unofficial specialist tracker (artificialintelligenceact.eu) cites Denmark as an example of a state with an active sandbox, while describing others as still at early planning stages — but that is a third-party source, not an act of the Commission or of the Danish state, and we have not verified it further. Our research also turned up several sites circulating a precise-sounding figure (“8 of 27 states ready”) with no identifiable official source behind it: numbers of that kind, given how they arose, we do not use.

Italy: the law exists, the space does not

Italy is, on paper, one of the more advanced states: Law No. 132 of 23 September 2025 is the first comprehensive national AI law in a Member State. Its Article 20(1)(c), verified on Normattiva, gives AgID and ACN a precise task: “AgID and ACN, each within its own competence, shall ensure the establishment and joint management of sandboxes aimed at the development of AI systems compliant with national and EU law, having consulted the Ministry of Defence on aspects concerning AI systems usable for dual purposes and the Ministry of Justice on AI models and systems applicable to judicial activity”.

The decree implementing that provision — Government Bill No. 421, which establishes the Italian AI sandbox under Article 26 — is not yet law. The Garante, in opinion No. 532 of 14 July, made public on the 29th, asked for that same Article 26 to be amended to provide for its own participation in projects involving personal data, as required by Article 57(10). At its hearing on 21 July, the draft was still before the Chamber’s IX and X Committees; as far as we could last verify, it has not been published in the Official Gazette. Put simply: had the EU deadline not slipped, Italy would have missed it anyway — the one-year postponement shelters it from an obligation it was not ready to meet on the ground.

What we have not verified

To be clear: the count of states with an operational sandbox is not verifiable from a primary source, and we say so rather than estimate it. We do not know when Government Bill No. 421 will be finally adopted, nor whether the Garante’s conditions will be accepted. The Denmark data point comes from an unofficial specialist source and remains unconfirmed by us against any Danish or Commission act.

How we deal with it

The point for anyone who still has to bring an AI system to market does not change with the postponement: a public sandbox, where it exists, offers a supervised environment and, if things go well, immunity from the administrative fine under paragraph 12. Where it does not exist, or is not yet ready, the trial still has to happen — only it happens alone, inside your own perimeter, with full liability resting on whoever runs it. The practical difference is not whether to test, but whether you end up with the same two documents a competent authority would have produced — written proof of the activities carried out and an exit report — ready to be shown the day someone asks for them.

That is why we do not treat pre-release control of an AI system as an opinion that ends in a report: we build it as a system that runs on the client’s own documents and systems, produces the same trail — test plan, logs, outcome, mitigations applied — and stays ready to show at inspection, even where no public authority ever opened the door. The same system, scaled up, holds together the data that today sit scattered across different systems — ERP, sensors, archives, documents — in a single operational model on which AI agents execute decisions with a human operator in command: for large enterprises, defence, public administration and healthcare, that is the part that remains even after the last compliance deadline has closed. It works in both delivery modes — on-premise, on autonomous machines that do not require deep integration into the client’s network, or dedicated cloud with the data centre in Italy — and always with shared management: whoever joins a project like this does not need to already have someone in-house running AI systems. That is the principle behind our platform.

Want to know whether your next AI system needs a sandbox that does not exist yet, or a control you can build right now? Half an hour with one of our experts is enough for a first map.

Sources