Germany AI Regulatory Sandbox

German National AI Regulatory Sandbox Program of the Bundesnetzagentur

Deutsches Nationales KI-Reallabor-Programm der Bundesnetzagentur

Germany

RAI-DE-NA-REGULAT-2026
Possible change, not yet verified. An automated check on 8 Sep 2026 read an official page suggesting that this instrument may now be In Force. We could not confirm it. The status shown is the last verified. Source page. If you know this instrument, use “Report an issue” to confirm or correct it.
Awaiting Entry(Awaiting Entry)As published at bundesnetzagentur.de · checked 9 Sep 2026

Germany AI Regulatory Sandbox is Awaiting Entry in Germany as of 9 Sep 2026, according to gesetze-im-internet.de.

PolicySafety, Testing, and EvaluationGovernance and Oversight
Export PDF

Germany is developing a national AI regulatory sandbox program, led by the Bundesnetzagentur, to foster innovation and ensure compliance with the EU AI Act by August 2027.

Summary

Germany is establishing a national AI regulatory sandbox program, KI-Reallabore, under the Bundesnetzagentur, mandated by the EU AI Act. This initiative aims to foster AI innovation by providing a controlled environment for testing AI systems, ensuring compliance with upcoming regulations, and supporting SMEs and start-ups. The program is currently awaiting entry, with an operational target of August 2027.

Full article

Read full text ↗

Overview

Germany is in the process of establishing a national AI regulatory sandbox program, known as KI-Reallabore, under the stewardship of the Bundesnetzagentur (Federal Network Agency). This initiative is a direct response to the mandate set forth by the European Union's AI Act, which requires each Member State to establish at least one national AI regulatory sandbox. The Bundesnetzagentur is designated as a key authority in Germany's AI ecosystem, tasked with implementing these provisions through the national Gesetz zur Marktüberwachung und Innovationsförderung von künstlicher Intelligenz (KI-MIG), or AI Market Surveillance and Innovation Promotion Act. The program's overarching goal is to foster innovation in artificial intelligence by providing a controlled environment for the development, testing, and validation of AI systems, particularly for Small and Medium-sized Enterprises (SMEs) and start-ups, while ensuring compliance with the forthcoming AI Act and other relevant legal frameworks.

While the statutory duty for Germany to establish an AI regulatory sandbox is in force, the national sandbox program itself is currently in the 'Awaiting Entry' status. This means that although preparatory activities are well underway, and a significant trilateral pilot project has been successfully concluded, no official opening or application date for the operational national AI regulatory sandbox has been announced yet. The European AI Act initially mandated that Member States have at least one sandbox operational by 2 August 2026. However, this deadline was subsequently amended to 2 August 2027 by the Digital Omnibus on AI, Regulation (EU) 2026/1744, which entered into force on 27 July 2026. The Bundesnetzagentur explicitly references this amended deadline, indicating the target for the full establishment and operationalization of its national AI regulatory sandbox program.

Definitions

An 'AI regulatory sandbox' is defined by the Bundesnetzagentur as a modern regulatory tool designed to foster innovation. It achieves this by facilitating the testing of innovative services, products, or technologies under conditions that are as close to real-world scenarios as possible, all while being overseen by competent authorities. Specifically, AI regulatory sandboxes established under the EU AI Act provide a controlled environment for the development, training, testing, and validation of innovative AI systems for a limited period. This testing can occur even before these systems are placed on the market or put into service, based on a sandbox plan mutually agreed upon with the competent authority. The aim is to examine new and complex legal questions from businesses under expert guidance, ensuring the AI systems comply with the AI Act and other applicable laws.

Key aspects of this definition include the requirement for an 'exit report,' which details the activities carried out in the sandbox and summarizes the results and learning outcomes. This report is crucial for facilitating and accelerating market access, particularly for SMEs and start-ups, by providing documented proof of regulatory compliance efforts. AI regulatory sandboxes can be established in physical, digital, or hybrid forms, accommodating both physical and digital products. The concept also extends to 'testing in real-world conditions,' which can be supervised within the framework of these sandboxes. The focus is on creating a supportive yet rigorously controlled environment where regulatory learning occurs for both authorities and undertakings, ultimately enhancing legal certainty and promoting trustworthy AI innovation.

Governance and Institutional Framework

The Bundesnetzagentur has been designated to play a pivotal role in the implementation of the AI Act in Germany, particularly concerning the national AI regulatory sandbox program. This responsibility is underpinned by the national Gesetz zur Marktüberwachung und Innovationsförderung von künstlicher Intelligenz (KI-MIG), which mandates the Bundesnetzagentur to establish and operate at least one regulatory sandbox (Reallabor). To manage its extensive responsibilities, the Bundesnetzagentur operates an AI Service Desk, which supports companies, authorities, and organizations in navigating AI regulation in Germany. Within this structure, a new unit for AI, the Coordination and Competency Centre for the AI Act (KoKIVO), is being established and staffed to serve as the market surveillance and notifying authority under the AI Act.

The governance model emphasizes close cooperation and exchange among various authorities. This collaborative approach was prominently demonstrated in the trilateral pilot project for AI regulatory sandbox simulation, which involved the Bundesnetzagentur, the Hessian Ministry for Digitalisation and Innovation, and the Federal Commissioner for Data Protection and Freedom of Information. This pilot project highlighted the importance of inter-authority collaboration to address complex legal and technical issues arising from the intersection of the AI Act and other sector-specific regulations. The findings from such collaborative efforts are intended to inform the future operational arrangements of the Bundesnetzagentur’s AI regulatory sandbox, ensuring a cohesive and effective regulatory environment that balances innovation with fundamental rights and data protection concerns.

Key Focus Areas

The establishment and operation of the German National AI Regulatory Sandbox program are strategically designed to address several key objectives, as outlined by the Bundesnetzagentur. A primary focus is 'Fostering innovation' by providing a controlled environment that facilitates the development, training, testing, and validation of innovative AI systems. The program aims to make the learning outcomes derived from these regulatory sandboxes accessible to all AI innovators, thereby disseminating best practices and accelerating technological advancement across the industry. This environment is particularly beneficial for novel AI applications that might face significant regulatory hurdles or uncertainties if introduced directly to the market without prior supervised testing.

Another critical area is 'Enhancing legal certainty.' Through the oversight provided by competent authorities, the sandbox ensures that participating AI systems comply with the AI Act and other applicable laws, significantly reducing legal ambiguity for developers and deployers. This proactive approach helps businesses understand and meet regulatory requirements before market entry, mitigating risks of non-compliance. Furthermore, the sandboxes are intended to 'Facilitate regulatory learning' for both authorities and undertakings. The practical experience gained from operating these sandboxes will inform future adaptations of the legal framework, ensuring that regulations remain relevant and effective in a rapidly evolving technological landscape. Finally, the program aims to 'Accelerate access to the market,' especially for SMEs and start-ups, by removing barriers and improving their ability to bring compliant AI systems to the Union market, while also 'Promoting exchange' and sharing best practices among all involved authorities.

Implementation Framework

The implementation framework for Germany's national AI regulatory sandbox program is built upon the foundational principles and insights derived from the trilateral pilot project. This pilot, launched in May 2025 by the Bundesnetzagentur, the Hessian Ministry for Digitalisation and Innovation, and the Federal Commissioner for Data Protection and Freedom of Information, aimed to simulate key requirements, processes, and challenges of AI regulatory sandboxes under realistic conditions. The successful conclusion of this project in March 2026, including the publication of a final report, provides crucial guidance for the future establishment and operation of the actual national sandboxes. The pilot specifically examined two use cases from the medical AI field, resulting in a detailed roadmap outlining high-risk AI requirements for AI-based medical devices, which will be invaluable for future participants.

The operational model for the sandboxes involves undertakings developing, testing, and validating innovative AI systems under regulatory supervision. This process requires a 'sandbox plan' agreed upon with the competent authority, outlining the scope and methodology of testing. Upon completion, participants must submit an 'exit report' detailing the activities, results, and learning outcomes, which can significantly speed up the conformity assessment process and assist in drawing up technical documentation. The program prioritizes access for SMEs, start-ups, and research institutions, recognizing their potential for innovation. The European Commission is also expected to adopt implementing acts specifying detailed arrangements for the establishment, development, implementation, operation, and supervision of AI regulatory sandboxes, which will further shape Germany's national framework and ensure alignment across the EU.

Monitoring and Evaluation

Monitoring and evaluation are integral to the German National AI Regulatory Sandbox program, ensuring its effectiveness in fostering innovation while upholding regulatory compliance. The trilateral pilot project served as a crucial initial phase for this, providing significant insights into the conception and successful operation of AI regulatory sandboxes. The experience from this pilot demonstrated that projects suitable for the sandbox should exhibit high innovation potential, a broad application perspective, and address outstanding regulatory issues, often intersecting with other legal domains. The findings from this project, including a detailed roadmap for high-risk AI in medical devices, are intended to serve as a practical guide for future monitoring and evaluation processes within the operational sandboxes.

A key aspect identified for successful regulatory oversight is the implementation of a 'structured maturity model' that accounts for the development status of AI systems. This approach enhances efficiency by allowing for the targeted bundling of legal, expert, and technical AI competence within the authorities. Furthermore, the collaborative nature of the sandbox, involving multiple authorities, facilitates shared learning and the development of practical solutions where the AI Act intersects with sector-specific regulations. For participating providers, the comprehensive 'exit report' serves as a vital evaluation document, providing written proof of activities and findings, which can significantly aid in their technical documentation and accelerate the conformity assessment process, thereby demonstrating compliance and mitigating future risks.

Penalties, Liability, and Appeals

The primary objective of the German National AI Regulatory Sandbox is to prevent non-compliance with the AI Act and other applicable laws before AI systems are placed on the market or put into service. By offering a controlled environment for development, testing, and validation under regulatory oversight, the sandbox aims to guide innovators, particularly SMEs and start-ups, toward full compliance. This proactive approach is designed to mitigate the risk of future penalties and liability that would otherwise arise from non-compliant AI systems. The sandbox provides a mechanism for businesses to identify and address potential legal issues, including those related to data protection and fundamental rights, in a supervised setting, thus reducing the likelihood of infringements that could lead to sanctions.

While the sandbox itself is a pre-market compliance tool and does not directly specify penalties for activities within the sandbox, the overarching legal framework, the Gesetz zur Marktüberwachung und Innovationsförderung von künstlicher Intelligenz (KI-MIG), will define the enforcement powers, penalties, and liability provisions for non-compliance with the AI Act in Germany. The sandbox's role is to facilitate the development of AI systems that are inherently compliant, thereby helping participants avoid these future penalties. The 'exit report' generated from sandbox activities is intended to serve as valuable documentation to support conformity assessment, further reducing the risk of regulatory breaches. Any appeals related to the interpretation or application of the AI Act would ultimately fall under the jurisdiction of national courts and the Court of Justice of the European Union, as the Bundesnetzagentur's guidance is non-binding.

Relationship to Other Instruments

The German National AI Regulatory Sandbox program is intrinsically linked to several key legal instruments at both the European and national levels. Its very existence is mandated by the Regulation (EU) 2024/1689 on Artificial Intelligence (AI Act), which requires all Member States to establish at least one AI regulatory sandbox. This foundational EU regulation sets the overarching goals, principles, and requirements for AI systems across the Union, and the national sandboxes are designed to help undertakings comply with these provisions, particularly for high-risk AI systems. The sandbox serves as a practical implementation mechanism for the AI Act's innovation-friendly measures, ensuring that regulatory burdens do not stifle technological advancement.

At the national level, the program's legal basis is the Gesetz zur Marktüberwachung und Innovationsförderung von künstlicher Intelligenz (KI-MIG), or AI Market Surveillance and Innovation Promotion Act. This national law designates the Bundesnetzagentur as the authority responsible for establishing and operating the sandboxes, outlining the specific provisions for their functioning within the German legal landscape. Furthermore, the program's development has been influenced by other relevant regulations, such as the Medical Devices Regulation, as demonstrated by the trilateral pilot project's focus on AI-based medical devices. A critical amendment impacting the program's timeline was introduced by the Digital Omnibus on AI, Regulation (EU) 2026/1744, which revised the deadline for national sandbox establishment from 2 August 2026 to 2 August 2027, highlighting the dynamic interplay between various legislative instruments.

International Alignment

The German National AI Regulatory Sandbox program demonstrates a strong commitment to international alignment, particularly within the European Union framework. As a direct response to the EU AI Act's mandate, the program is inherently designed to align with broader European efforts to foster trustworthy AI innovation. The Bundesnetzagentur actively participates in and contributes to EU-level initiatives, such as the European Artificial Intelligence Board’s sub-group on regulatory sandboxes, which supports the European Commission in developing implementing acts for these sandboxes. This engagement ensures that Germany's national approach is harmonized with the detailed arrangements and best practices being developed across the Union.

Further illustrating this international alignment is Germany's participation in the EUSAiR pilot project for AI regulatory sandboxes. This EU-funded project, part of the Digital Europe programme, offers companies the opportunity to test their innovative AI systems for regulatory compliance under the AI Act in real or simulated environments. By engaging in such cross-border pilot programs, Germany contributes to and benefits from shared learning, expert advice, and practical feedback, which helps shape the future implementation of AI regulatory sandboxes across the EU. This collaborative spirit promotes the sharing of best practices and ensures that national sandboxes contribute to a coherent and effective European AI regulatory landscape, fostering innovation while maintaining high standards of safety and ethical conduct.

Implementation Timeline

MilestoneDateNotes
Trilateral pilot project launched2025-05-09Joint initiative by the Bundesnetzagentur, the Hessian Ministry for Digitalisation and Innovation and the Federal Commissioner for Data Protection and Freedom of Information (BfDI), announced by joint press release. A seven-month simulation, not a live sandbox.
Trilateral pilot project concluded, final report published2026-03-17Provided key findings and guidance for future national sandboxes, including a roadmap for high-risk AI in medical devices.
KI-MIG enters into force; §13 obliges the Bundesnetzagentur to establish and operate at least one AI regulatory sandbox2026-07-29Promulgated 22 July 2026, BGBl. 2026 I Nr. 223. §13 itself sets no deadline. The original Article 57 deadline of 2 August 2026 was superseded by Regulation (EU) 2026/1744 before it fell due.
Amended deadline for national AI regulatory sandboxes to be established and operational2027-08-02Current binding deadline for each Member State to ensure at least one national AI regulatory sandbox is operational.
Bundesnetzagentur's preparatory activitiesOngoingPreparatory work for the national AI regulatory sandbox is underway, but no official opening or application date announced.

Sources and References

SourceType
Innovation and AI regulatory sandboxes - Bundesnetzagenturgovernment
Trilateral pilot project for AI regulatory sandbox simulation successfully concluded - Bundesnetzagenturgovernment
AI Service Desk - Bundesnetzagenturgovernment
Final report on the AI regulatory sandboxes pilot project (pdf / 1 MB) - Bundesnetzagenturgovernment

Requirements for a company

What an organisation has to do under Germany AI Regulatory Sandbox, at a glance. Not legal advice — the table below gives the provision and deadline for each item.

Not yet in force (Awaiting Entry). These requirements apply once the instrument takes effect and may change before then.

Must do

7
  • +1 more in the table below

Must not do

0

Nothing in this category.

Should do

0

Nothing in this category.

Should not do

0

Nothing in this category.

Who must do what

The obligations under Germany AI Regulatory Sandbox, most serious first. Not legal advice — verify against the official text before relying on it.

#WhoRequirementBy whenWhereSeverity
1Aug 2, 2027—Important
2Aug 2, 2027—Important
3——Important
4upon completion—Important
5——Important
6——Important
7——Important

© Regulations.AI — created on 26 Aug 2026 using Gemini 2.5 Flash · reviewed against official sources on 9 Sep 2026