Spain - National AI Sandbox (Royal Decree 817/2023)
National AI Sandbox
Entorno de pruebas de Inteligencia Artificial
Spain
RAI-ES-NA-NASFSXX-2025Spain's National AI Sandbox is an officially established controlled testing environment (sandbox) created to pilot and validate compliance with the EU Artificial Intelligence Act and associated national requirements. Established by Royal Decree 817/2023 and operationalised through the Ministry for Economic Affairs and Digital Transformation's first call (selection announced April 3, 2025), it selects providers and systems (including high-risk AI) for supervised, evidence-based testing and guidance generation.
Summary
Read full text ↗Plain English
Overview
The National AI Sandbox (Entorno controlado de pruebas para una inteligencia artificial confiable) is established by Real Decreto 817/2023 and operationalised by the Secretaría de Estado de Digitalización e Inteligencia Artificial within the Ministerio de Asuntos Económicos y Transformación Digital. Its purpose is to provide a regulated, supervised environment to test compliance with the EU Artificial Intelligence Act (Regulation (EU) 2024/1689), to generate evidence-based technical guidance and to support SMEs and startups in meeting high-risk AI obligations. The first public call and selection process (publication of the call materials on SE Digitalization portal) resulted in the provisional selection of 12 high-risk AI systems announced on 3 April 2025. The sandbox is designed to combine regulatory oversight with operational testing, capacity building and cooperation with the European AI Office.
Definitions
Key definitions are aligned with the EU AI Act and the Royal Decree: "provider" (entity that develops an AI system and places it under its own name), "user" (entity that deploys or operates a system), "high-risk AI system" (systems that, by sector or intended use, present significant risk to health, safety or fundamental rights), "system of general purpose" and "foundational model" (large-scale models that may be adapted to high-risk uses), and "sandbox" (a time-limited, supervised environment for testing and validating compliance and mitigation measures). The Decree clarifies that participating entities must be resident in Spain or have a permanent establishment in Spain, or designate a Spanish representative for the purposes of the sandbox.
Governance and Institutional Framework
Governance is led by the Ministerio de Asuntos Económicos y Transformación Digital through the Secretaría de Estado de Digitalización e Inteligencia Artificial and is executed via formal calls, selection committees and an expert advisory group (documented on the sandbox portal: press release and Enlaces y Descargas page). The governance model includes: a) a public selection and admission procedure; b) multi-disciplinary expert reviewers; c) continuous monitoring and reporting channels; and d) cooperation mechanisms with the European AI Office and sectoral regulators (health, transport, labour, telecommunications). Data protection oversight is coordinated with the Agencia Española de Protección de Datos (AEPD) where personal data processing is involved. The Decree tasks the administering authority with producing final guidance reports and sharing outcomes with the European Commission and standardisation bodies.
Key Focus Areas
The sandbox concentrates on operationalising several compliance dimensions: technical robustness and cybersecurity (adversarial testing, red-teaming, patching), human oversight and organizational governance (roles, escalation and supervision), transparency and information obligations (documentation, instructions for use, consumer notices), data governance and privacy (quality, provenance, lawful basis and minimisation), conformity assessment pathways (interface with notified bodies and market surveillance), sectoral safety standards (healthcare, critical infrastructure, machinery), post-market monitoring (incident detection, corrective actions), and liability & redress mechanisms. Selected cases include biometric age verification, healthcare diagnostic tools, employment screening systems and critical infrastructure monitoring; the mix is intended to stress-test different high-risk categories and model types including foundational models adapted to high-risk uses.
Implementation Framework
Implementation follows a structured multi-stage approach: application & selection (eligibility checks, documentation review), admission & on-boarding (execution of participation agreements, confidentiality and data-sharing arrangements), testing & validation (controlled deployment, test datasets, monitoring dashboards), technical feed-back (iterative adjustments, expert advisory reviews), reporting & evaluation (delivery of self-assessments, independent validation outputs), and final guidance production (consolidated lessons, draft technical guides). Operational rules require participants to supply technical documentation, risk assessments, human oversight mechanisms and post-market monitoring plans — and to allow supervised testing within sandbox facilities or virtual environments. The administering authority can require remedial measures, restrict deployment within the sandbox or terminate participation for material non-compliance.
Monitoring and Evaluation
Monitoring combines continuous telemetry (secure logs, access records), periodic expert reviews and formal milestone reporting. The sandbox formulates Key Performance Indicators (KPIs) focused on safety incidents, compliance gaps identified and remediation rates. An expert advisory panel provides independent assessments and the Ministry consolidates outcomes into public-facing guidance and non-confidential summary reports. The process design allows feedback loops into Spain's Agenda España Digital 2026 and contributes practical inputs for EU-level guidance via the European AI Office; results are expected to support standardisation and market surveillance frameworks.
Penalties, Liability, and Appeals
The Royal Decree provides administrative tools to exclude or suspend participants for non-compliance with sandbox rules. Material breaches may lead to termination of participation, publication of non-compliance findings and proposed referrals to sectoral supervisors or sanctioning authorities under applicable Spanish and EU laws (including administrative fines and corrective orders envisaged by the Artificial Intelligence Act and related national sanctioning regimes). Participants retain civil liability under general Spanish tort and contract law; the sandbox does not grant exemptions from third-party liability. The Decree establishes appeal channels against administrative decisions within the Spanish administrative justice system.
Relationship to Other Instruments
The sandbox is legally grounded in Real Decreto 817/2023, interacts directly with the EU Artificial Intelligence Act (Regulation (EU) 2024/1689), and aligns with Spain's Agenda España Digital 2026 and the national recovery plan components referenced in the BOE. It complements sectoral safety and data protection regulation (AEPD guidance, healthcare device rules) and feeds into EU standardisation and market surveillance pathways.
International Alignment
The sandbox is explicitly coordinated with the European Commission and the European AI Office to produce guidance that can be shared and potentially harmonised at EU level. The Decree invites comparability with other Member State sandboxes and international best practices on regulatory sandboxes, and aims to provide a model for cross-border cooperation on testing foundational models and high-risk AI systems. Outcomes are intended to inform EU-level standardisation and may be cited in international regulatory dialogues on trustworthy AI.
Implementation Timeline
| Phase | Milestone | Date |
|---|---|---|
| Legal basis published | Real Decreto 817/2023 published in BOE | 2023-11-09 |
| First call published | Convocatoria (first public call) | 2024-12-20 |
| Selection announced | Provisional resolution selecting 12 systems | 2025-04-03 |
| Operational testing | On-boarding & testing commences (first cohort) | 2025-04 (April 2025) |
| Guidance publication | Draft technical guides and final report (expected) | 2025 (following testing period) |
Compliance Checklist
| Requirement | Action for Participant |
|---|---|
| Spanish establishment / representative | Provide proof of residence or permanent establishment in Spain or designate representative |
| Documentation & self-assessment | Submit technical files, risk assessments, human oversight and post-market plans |
| Data protection | Demonstrate GDPR compliance and AEPD coordination |
| Security measures | Provide cybersecurity risk assessment and mitigation plan |
| Reporting | Agree to periodic reports, incident notifications and monitoring |
| Cooperation | Accept expert reviews and remedial instructions |
Sources and References
| Source | Type |
|---|---|
| Real Decreto 817/2023 (BOE) | Primary Source |
| Ministry press release: Government launches first EU AI sandbox | Primary Source |
| Sandbox IA - Enlaces y Descargas (SE Digitalization) | Primary Source |
| Regulation (EU) 2024/1689 (Artificial Intelligence Act) | Primary Source |
Spain's National AI Sandbox is a government-run testing ground for companies developing Artificial Intelligence systems, particularly those deemed "high-risk," to ensure they comply with the upcoming European Union AI Act. This initiative applies to AI providers and users based in Spain or with a designated Spanish representative.
Established by Royal Decree 817/2023 and operational since November 2023, with the first cohort of 12 high-risk AI systems beginning supervised testing in April 2025, the sandbox aims to generate practical guidance for the EU AI Act. Participants, who are selected through a public call, must: - Provide extensive technical documentation, risk assessments, and plans for human oversight and post-market monitoring. - Allow their AI systems to undergo controlled, supervised testing, including cybersecurity and data governance checks. - Cooperate with expert reviewers and implement any required remedial measures. - Ensure strict compliance with data protection laws, such as GDPR.
The Ministry for Economic Affairs and Digital Transformation oversees the sandbox, collaborating with the European AI Office and other sectoral regulators. While participating, companies retain full civil liability for their AI systems; the sandbox does not grant exemptions from third-party claims. A key practical pitfall is that non-compliance with sandbox rules can lead to termination of participation, public disclosure of findings, and potential referrals to national or EU authorities, which could result in significant administrative fines or corrective orders under the EU AI Act. The sandbox is designed to help companies navigate complex AI regulations, but it also acts as a rigorous compliance gateway.
Plain-English rewrite by Regulations.ai — not legal advice. Verify against the official text.
What you must do — compliance checklist
0 / 12 marked completePlain-English obligations under Spain - National AI Sandbox (Royal Decree 817/2023). Not legal advice — verify against the official text before relying on it.
- #1Critical⏰ Before admission to the sandbox
Applies to: Entities participating in the National AI Sandbox.
“participating entities must be resident in Spain or have a permanent establishment in Spain, or designate a Spanish representative for the purposes of the sandbox.”
- #2Critical⏰ Throughout the testing and validation phase
Applies to: Providers participating in the National AI Sandbox.
“Operational rules require participants... to allow supervised testing within sandbox facilities or virtual environments.”
- #3Critical⏰ Throughout sandbox participation
Applies to: Providers participating in the National AI Sandbox processing personal data.
“Data protection oversight is coordinated with the Agencia Española de Protección de Datos (AEPD) where personal data processing is involved.”
- #4Critical⏰ Throughout sandbox participation
Applies to: Providers participating in the National AI Sandbox.
“The administering authority can require remedial measures, restrict deployment within the sandbox or terminate participation for material non-compliance.”
- #5Critical⏰ Throughout sandbox participation
Applies to: Entities participating in the National AI Sandbox.
“The Royal Decree provides administrative tools to exclude or suspend participants for non-compliance with sandbox rules.”
- #6Important⏰ During application and on-boarding
Applies to: Providers participating in the National AI Sandbox.
“Operational rules require participants to supply technical documentation, risk assessments, human oversight mechanisms and post-market monitoring plans”
- #7Important⏰ During application and on-boarding
Applies to: Providers participating in the National AI Sandbox.
“Operational rules require participants to supply technical documentation, risk assessments, human oversight mechanisms and post-market monitoring plans”
- #8Important⏰ During application and on-boarding
Applies to: Providers participating in the National AI Sandbox.
“Operational rules require participants to supply technical documentation, risk assessments, human oversight mechanisms and post-market monitoring plans”
- #9Important⏰ During application and on-boarding
Applies to: Providers participating in the National AI Sandbox.
“Operational rules require participants to supply technical documentation, risk assessments, human oversight mechanisms and post-market monitoring plans”
- #10Important⏰ During application and on-boarding
Applies to: Providers participating in the National AI Sandbox.
“The sandbox concentrates on operationalising several compliance dimensions: technical robustness and cybersecurity (adversarial testing, red-teaming, patching)”
- #11Important⏰ Throughout sandbox participation
Applies to: Providers participating in the National AI Sandbox.
“Monitoring combines continuous telemetry (secure logs, access records), periodic expert reviews and formal milestone reporting.”
- #12Important⏰ Throughout sandbox participation
Applies to: Providers participating in the National AI Sandbox.
“Participants retain civil liability under general Spanish tort and contract law; the sandbox does not grant exemptions from third-party liability.”
Related Regulations
Royal Decree 729/2023 approving the Statute of the Spanish Agency for AI Supervision (Agencia Española de Supervisión de la Inteligencia Artificial - AESIA)
Spain92% similar
AI Regulatory Sandbox Policy
Lithuania92% similar
National Artificial Intelligence Strategy (Estrategia Nacional de Inteligencia Artificial, ENIA)
Spain92% similar
Proyecto de Ley Orgánica para el buen uso y la gobernanza de la inteligencia artificial
Spain92% similar
Spain AI Regulation Overview
Spain92% similar
© Regulations.AI — created on 13-Jun-2026