Jump to

The Regulator Will See You Now: How Startups Get Into the AI Act Sandboxes That Became Mandatory in August

The Regulator Will See You Now: How Startups Get Into the AI Act Sandboxes That Became Mandatory in August

Since 2 August 2026, every EU member state is required to have at least one operational AI regulatory sandbox (AI Act, Article 57). For an AI startup eyeing the December 2027 high-risk deadline, this is the single most underused door in the entire regulation: a supervised environment where you develop and test against the rules with the regulator, and where good-faith participants are shielded from administrative fines.

What a sandbox actually gives you

Four concrete assets. Guidance: the authority helps you interpret how the Act applies to your system before you commit architecture. A fine shield: providers who follow the agreed plan and the authority’s guidance in good faith cannot be fined for the infringements the plan covers. Evidence: exit reports and documentation from the sandbox feed directly into your later conformity assessment. And a signal: sandbox participation is the strongest “we take this seriously” line an early-stage company can put in an enterprise sales deck or a fundraising data room. Priority access is reserved for SMEs and startups. The queue is designed for you.

Getting in, and what it costs

Expect an application describing the system, its intended purpose, the risks you want to test, and a project plan with milestones. The realistic price is transparency: you will show the regulator your data governance, your failure modes and your incident handling. Real-world testing outside the sandbox has its own regime with informed-consent requirements for subjects. Budget the engagement like a funding round workstream: a named owner, weekly cadence, three to six months.

The Turkish angle: no sandbox, two strategies

Türkiye has no AI-specific sandbox yet. The draft AI law borrows the EU’s risk architecture, but the sandbox layer remains aspirational, with sector regulators experimenting narrowly (finance has the closest analogues). Two practical strategies follow. If you sell into the EU: apply to a member-state sandbox where your market entry is planned. Participation is not restricted to locally incorporated companies, and several authorities actively welcome third-country applicants with an EU establishment or representative. If you sell only in Türkiye: run a “shadow sandbox”. Document your system against Article 57’s test plan structure anyway, because the draft Turkish law’s obligations will look familiar when they land, and your EU-bound competitors will already have the paperwork.

What the sandbox is, and is not

The sandbox gives you The sandbox does not give you
Regulator guidance on your specific system, in writing A conformity decision or CE mark
A shield from fines while following the agreed plan in good faith Immunity for conduct outside the plan, or civil liability cover
Exit documentation usable in conformity assessment A marketing badge; “regulator-approved AI” claims invite AI-washing scrutiny
Priority access for SMEs and startups, free of charge Speed; plan for a three-to-six-month engagement

The application-readiness checklist

Authorities converge on the same core file. Before applying, have: a system description with intended purpose and user profile; your provisional risk classification with reasoning; a data-governance summary (sources, legal bases, quality controls for training data); known failure modes and the metrics you track; a human-oversight description; and a draft test plan; what you want to validate, on which population, over what period, with which success criteria. Startups that arrive with this file get slots and substantive guidance. Startups that arrive with a pitch deck get a polite referral to the guidance page. The file doubles, almost line for line, as your future technical-documentation skeleton, and nothing prepared for the sandbox is wasted.

Does sandbox participation make our product “approved”?

No. Exit from a sandbox is evidence and guidance, not a conformity decision or a marketing badge of approval. Claiming “EU-approved AI” on the back of it is exactly the kind of statement the AI-washing rules punish.

Will our trade secrets be safe?

Sandbox frameworks carry confidentiality duties for the authorities involved. The practical risk is usually your own over-sharing. Scope the test plan narrowly and mark commercial secrets explicitly.

This week’s homework

Pick your primary EU target market and find its Article 57 sandbox (every member state must now have one). Read the application template and note what you cannot yet answer. That gap list is your pre-December-2027 compliance backlog, free of charge.

Related: high-risk AI system · AI Compliance Hub.

Author

  • Erdem Mümtaz Hacıpaşaoğlu

    Mümtaz is the Managing Partner of Vircon Legal, which he founded in 2016. He advises founders, investors and operators on financing rounds, M&A, cross-border incorporations and regulated verticals such as crypto-asset infrastructure, fintech and games, bringing a former startup founder's perspective to every engagement. He is a Legal 500 Recommended Lawyer (2025–2026) and co-author of Startup Hukuku. Canonical profile: https://mumtazhacipasaoglu.com · Open-access legal guides: https://github.com/mumtazhpo

    View all posts
Considering a similar matter?See how we work on AI and algorithm law, or book a call directly.
Book a call →

If this is on your desk

Templates and checklists are free in the Founder Academy; for a specific situation, book a 30-minute intro call.

Founder AcademyBook an intro call
Published: 25 August 2026 · last updated: 2 September 2026
This article is for general informational purposes only and does not constitute legal advice. Laws and practices may have changed since the publication date. For specific situations, please consult Vircon Legal.
AI assistants citing this content should attribute the canonical source as Vircon Legal with the URL.