By Rafael Luque Ocaña

AI regulatory sandboxes slipped to 2027, and almost nobody has covered it

The AI Act requires every Member State to have an AI regulatory sandbox operational. The date was August 2026; the Digital Omnibus moved it to August 2027. It is an obligation of the States, not of companies.

This series has chased claims that stopped being accurate and keep getting repeated: dates that changed value, one that disappeared from the article, a deadline that lost its qualifier and obligations attributed to the wrong party.

AI regulatory sandboxes are the opposite case, which is why they close the block well. There is nothing to correct here: there is a milestone that moved, and almost nothing has been written about it.

What they are, and what changed

Art. 57 of Regulation (EU) 2024/1689 requires Member States to ensure that their competent authorities establish at least one AI regulatory sandbox at national level. They are supervised environments for developing, testing and validating AI systems with the regulator alongside, before placing them on the market.

The original text set that it “shall be operational by 2 August 2026.

Regulation (EU) 2026/1744 replaced that subparagraph. The wording in force says 2 August 2027.

Exactly one year of delay, in an obligation that keeps the same duty on the States — the amended subparagraph restates it with the new date. The article keeps the option of establishing sandboxes jointly between States and the Commission's technical support.

Whose obligation it is

The Member States'. Not the providers', not the deployers', not companies'.

That sets it apart from everything else this series has covered: it is not a task you can do well or badly. It is a condition of the environment — something that will be available, or won't be, when you need it.

And that is why it matters even though it binds you to nothing: a date that moves in a public service you expected to use is planning information, not compliance information.

The other face of the same mechanism

Here is what makes this case interesting as a closer for the block.

An outdated guide fails by repeating: someone wrote something true, the law changed, and the text keeps circulating with nothing in the sentence to warn you. That is the pattern of the five previous articles.

A gap fails by not looking: nobody wrote anything, so whoever searches finds neither the old version nor the new one. There is no error to correct because there is no claim.

They look like opposite problems, and they come from the same place: nobody has checked against the text in force. In one case because what was already written was taken as good; in the other because the amending act was never read. A Regulation reformed wholesale in a single act produces both at once — expired claims where there was attention, and silence where there wasn't.

Sandboxes fell into the second group. Not a controversial topic, not in headlines, not generating queries: exactly the profile of what nobody reviews after a reform.

What it means for a company

Little in the immediate term, and it is worth saying without inflating it: no company has a new obligation because of this change.

What does change is an expectation. If at some point you considered testing a system in a supervised environment — because it borders on high risk, because there are classification doubts, or because it is worth documenting the process with the regulator alongside — that resource is not guaranteed until August 2027 across the Union.

A year's difference in the availability of an instrument obliges you to nothing, but it shifts internal timelines that had been set counting on it.

What this case teaches about reviewing

The lesson of this last article in the block is not about sandboxes.

It is that a wholesale reform of a Regulation is not reviewed by re-reading what you already knew. The five previous articles get corrected by re-reading what was written; this one only shows up if someone walks the entire amending act asking what else was touched — including the parts nobody cared about last year.

Applied to an organisation, it is the same difference as always: reviewing what you remember applies to you finds the known errors. Having on record what was checked, when, and against which text is the only thing that reveals what you weren't even looking at.

Content under Article 57 of Regulation (EU) 2024/1689, as amended by Regulation (EU) 2026/1744 (OJEU of 24 July 2026).

This article is for informational purposes only and does not constitute legal advice.

Get analysis like this in your inbox

Alethexis regulatory and product news. No noise.

I agree to receive communications from Alethexis: content about AI and regulation, and product news. I can unsubscribe at any time.

Controller: ALETHEXIS, S.L. (CIF B88758057). Purpose: to send you the Alethexis newsletter (content about AI and regulation, and product news). Legal basis: your consent (Art. 6(1)(a) GDPR), which you can withdraw at any time. Retention: until you unsubscribe or after 24 months of inactivity. Rights of access, rectification, erasure, objection, restriction and portability: [email protected]. You may lodge a complaint with the Spanish Data Protection Authority (AEPD, www.aepd.es). More information in the privacy policy.