How to Participate in Spain's Controlled AI Testing Environment
To participate in the Spanish AI sandbox you must wait for the competent authority to publish a call and submit an application describing the artificial intelligence system you want to test. Two frameworks currently coexist: the pilot environment under Royal Decree 817/2023, whose calls are approved by resolution of the Secretariat of State for Digitalisation and Artificial Intelligence, and the controlled testing environment under Article 57 of Regulation (EU) 2024/1689 (the AI Act), which in Spain will be managed by AESIA once the AI governance law — still under parliamentary consideration — is approved. This guide explains what each one is, what a company gains inside, who can enter and how to prepare the application.
What exactly is the Spanish AI sandbox?
A controlled testing environment (the official Spanish term; "sandbox" is the colloquial name) is an environment supervised by a public authority in which a company develops, trains, tests and validates an innovative AI system before placing it on the market or putting it into service. Article 57(5) of the AI Act defines it this way: a controlled environment that fosters innovation during a limited period, in accordance with a specific plan agreed between the provider and the competent authority.
The sandbox is not a lawless zone. The supervisory powers of authorities remain intact within the environment (Article 57(11)), and if during testing a considerable risk to health, safety or fundamental rights appears that cannot be mitigated, the authority may suspend the project or expel the participant.
Nor is it a cosmetic formality. The testing plan is negotiated with the authority, participation has a duration limited to the complexity of the project (extendable, per Article 58(2)) and upon exit you receive documentation with real legal effects, as explained below.
Legal basis: from the European Regulation to the Spanish royal decree
The European framework is in Articles 57–59 of the AI Act, within the chapter dedicated to innovation-support measures. Article 57 obliges each Member State to have at least one controlled national-scale testing environment operational; Article 58 refers the details of admission, operation and exit to Commission implementing acts; and Article 59 regulates a special case of re-use of personal data within the environment.
Spain anticipated the Regulation. Royal Decree 817/2023 of 8 November (BOE of 9 November 2023, in force the following day) created a controlled testing environment to test compliance with what was then only a proposed European Regulation. Its competent body is the Secretariat of State for Digitalisation and Artificial Intelligence, and participation calls are approved by resolution of its head (Article 6(1) of the royal decree). It is a regulation with an expiry date: its second final provision gives it a maximum life of thirty-six months from entry into force, or until the European Regulation becomes applicable in Spain.
The relay will be taken by the draft law on AI governance (expediente 121/000096 of the Congress). Its third chapter regulates controlled testing environments: it assigns AESIA with the mandatory national sandbox under Article 57(1) of the Regulation, allows other competent authorities to create additional sandboxes within their scope and expressly repeals Royal Decree 817/2023.
Note the status of that rule: as of this guide it is still at the amendment stage in Congress, with an extended deadline until 2 September 2026, so any detail may change before it is approved.
The most recent piece is Regulation (EU) 2026/1744, the so-called Digital AI Omnibus, in force since 27 July 2026. It amends Articles 57, 58 and 60 of the AI Act, and what changes directly affects this guide:
- Defers the national sandbox deadline to 2 August 2027 (previously 2 August 2026).
- Authorises the Commission's AI Office to create a Union-scale controlled testing environment, with priority access for SMEs and start-ups.
- Allows the real-conditions testing plan to be integrated into the sandbox plan itself, to avoid duplicating procedures.
Since both frameworks coexist — and that coexistence is the first source of confusion — here is the quick overview:
| Environment under RD 817/2023 | Controlled environment under Article 57 | |
|---|---|---|
| Who manages it | Secretariat of State for Digitalisation and Artificial Intelligence | AESIA, once the governance law is approved |
| Status today | In force | Pending that law |
| Calls | By resolution of the Secretariat of State | None yet |
| Horizon | Maximum life of 36 months from November 2023 | Must be operational by 2 August 2027 |
What your company gains by participating
The list of benefits is not theoretical; each one has an article behind it.
Direct regulatory guidance. Inside the sandbox, the competent authority guides on how to meet the Regulation's requirements and supervises risk identification and the effectiveness of mitigation measures (Articles 57(6) and 57(7)). For an SME that cannot afford a regulatory department, having the authority at the table while developing is a means of reducing uncertainty that is hard to achieve by any other route.
Exit report with real effects. Upon completion, the authority delivers an exit report covering the activities carried out and their outcomes, and — if the provider requests it — written proof of what was successfully completed. Article 57(7) directs market surveillance authorities and notified bodies to take that documentation positively into account to expedite conformity assessment "to a reasonable extent". It is not a compliance certificate, but it is a documentary asset that carries weight.
Shield against fines. For as long as the participant respects the agreed plan and follows the authority's guidance in good faith, no administrative fines will be imposed for AI Act infringements (Article 57(12)). Good faith is the condition that sustains the whole mechanism.
Free for SMEs. Article 58(2) requires access to be free for SMEs, including start-ups, without prejudice to exceptional costs that the authority may recover in a fair and proportionate manner. The same article requires procedures to be simple and understandable precisely so as not to exclude companies with limited legal and administrative capacity. This relief aligns with other SME-friendly measures in the AI Act.
Effects across the entire Union. Participation in a Member State's sandbox must be mutually and uniformly recognised and produce the same legal effects throughout the EU (Article 58(2)(g)). Testing in Spain is valid for selling in France.
Pre-deployment services. Article 58(3) provides for services for participants, especially SMEs, such as assistance with standardisation and certification documents or access to testing facilities and European digital innovation hubs.
Who can participate (and who cannot)
Eligible to apply are providers and prospective providers of AI systems: those who develop a system to place it on the market under their own name or brand, or who are considering doing so. You do not need to apply alone: Article 58(2)(b) accepts joint applications with deployers and other third parties, for example the client who will use the system or a research centre.
Admissibility and selection criteria must be transparent and equitable, and the authority must communicate its decision within three months of the application. SMEs and start-ups have a double advantage: free access in national sandboxes and priority access in the future Union-scale AI Office sandbox.
Who falls outside? The sandbox is intended for systems before their market introduction or deployment. If your system is already commercialised and you need to regularise its compliance, the route is not the sandbox but ordinary adaptation: start by classifying it and reviewing your role's obligations. Nor is it the route for systems without genuine innovative content: selection specifically values that.
How to enter: call and application step by step
The specific procedure will be determined by each call (and, at European scale, by the implementing acts the Commission must adopt under Article 58). With what has been published, the typical path is:
- Monitor the official channel. Under Royal Decree 817/2023, calls are approved by resolution of the Secretariat of State for Digitalisation and Artificial Intelligence. Once the governance law is approved, the reference will shift to AESIA. The new Article 57 environment has no call yet because the law creating it is still under consideration.
- Prepare the file before the deadline opens. Call deadlines tend to be short relative to the documentation work. Have your AI systems inventory ready, the risk classification of each one and a draft of the technical documentation for the candidate system.
- Define who you apply with. If the system will be operated by a specific client, consider a joint application as provider plus deployer: the European framework expressly provides for it.
- Submit the application and await the decision. The European framework sets a maximum of three months for the authority to respond.
- Agree the controlled environment plan. This is the document that governs all participation: what is tested, with what safeguards, for how long. If the project includes real-conditions testing, after the Omnibus the plan for those tests can be integrated into the sandbox plan itself.
- Execute under supervision and document everything. What is documented during participation feeds the exit report, which is the asset you take away.
- Close with the exit report and, if relevant, also request the written proof of successfully completed activities.
What happens inside the sandbox
Participation is not a simple registration. The authority guides, supervises and may intervene. Article 57(11) allows it to suspend testing temporarily or definitively if it detects considerable risks without possible mitigation, notifying the AI Office. Duration is adjusted to the project's complexity and scale and may be extended.
Within the environment, real-conditions supervised testing is permitted — with real users and data under the safeguards agreed in the plan. And there is a transparency counterpart: authorities publish annual reports on how their sandboxes operate, with best practices, incidents and lessons learned (Article 57(16)), and the AI Office maintains a public list of existing and planned environments across the Union.
Liability and data protection within the environment
It is worth clearing up a common misunderstanding: the sandbox softens sanctioning risk, not civil liability. Article 57(12) states this without ambiguity: participants are liable, under Union and national law, for any damage inflicted on third parties as a result of experimentation. What disappears, if acting in good faith and in accordance with the plan, is administrative fines under the Regulation.
On personal data, Article 59 opens a narrow door: re-using lawfully collected data for other purposes, but only to develop, train and test AI systems serving an essential public interest in limited areas (public health and safety, environment, energy sustainability, transport and critical infrastructure, and public administration efficiency). The conditions are cumulative and demanding: a functionally separate and protected processing environment; prohibition on generated data leaving the sandbox; deletion at the end; processing records; and publication of a project summary on the authority's website. Furthermore, when personal data is involved, data protection authorities are tied to the environment's operation (Article 57(10)), so in Spain the AEPD (Spanish Data Protection Agency) will have a voice inside.
Spanish AI sandbox and the AI Act: key dates
- 9 November 2023: Royal Decree 817/2023 published in the BOE; in force the following day.
- 27 July 2026: Regulation (EU) 2026/1744 (Digital AI Omnibus) enters into force, amending Articles 57, 58 and 60.
- 2 August 2026: was the original Article 57(1) deadline to have the national sandbox operational. No longer applies: the Omnibus shifted it six days before it expired.
- 2 September 2026: current deadline for amendment submissions to the AI governance draft law in Congress. An extended deadline can be extended again.
- November 2026: horizon of the 36-month maximum life of Royal Decree 817/2023 (or earlier, if the European Regulation becomes applicable in Spain in the relevant part).
- 2 August 2027: new deadline for the Article 57(1) national sandbox to be operational.
If your company is considering the sandbox as a market-entry route, the preparation window is precisely this: from the Spanish law's legislative process to AESIA's environment going live.
Frequently asked questions
Is there an open call right now?
The new controlled testing environment under Article 57 of the AI Act cannot yet be called in Spain, because the law that assigns its management to AESIA is still under consideration in Congress. Under Royal Decree 817/2023, calls are approved by resolution of the Secretariat of State for Digitalisation and Artificial Intelligence; consult its electronic headquarters to check whether any is currently open before planning anything.
How much does participation cost?
For SMEs and start-ups, access to the AI Act sandboxes must be free by mandate of Article 58(2), without prejudice to exceptional costs that the authority may pass on in a fair and proportionate way. The real cost to the company lies in the hours of file preparation and project accompaniment during testing.
Does participating in the sandbox exempt me from complying with the AI Act?
No. Participation does not suspend the Regulation: what it does is accompany you towards compliance. If you respect the agreed plan and the authority's guidance, no administrative fines will be imposed for infringements committed during experimentation, but liability for damage to third parties remains fully intact.
Can you test with real users inside the sandbox?
Yes. Article 57(5) allows supervised real-conditions testing within the controlled environment, with the safeguards agreed in the plan. After the Digital Omnibus, the real-conditions testing plan can be integrated into the sandbox plan itself, avoiding duplication of procedures.
Sources
- Regulation (EU) 2024/1689 (AI Act), Articles 57, 58 and 59 — OJEU of 12 July 2024.
- Regulation (EU) 2026/1744, "Digital AI Omnibus" — OJEU Series L of 24 July 2026, in force from 27 July 2026 (amends Articles 57, 58 and 60 of the AI Act).
- Royal Decree 817/2023 of 8 November, establishing a controlled testing environment — BOE No. 268, of 9 November 2023 (BOE-A-2023-22767), consolidated text.
- Draft Law on AI governance, expediente 121/000096 — BOCG, Congress of Deputies, Series A, No. 97-1, of 12 June 2026. Under consideration: amendment phase extended to 2 September 2026 (expediente record, congreso.es).
- Royal Decree 729/2023 of 22 August, AESIA Statute (cited in the explanatory memorandum of the draft law).