Please enable javascript in your browser to view this site

Playing in the regulatory sandbox

Regulatory sandboxes are becoming essential tools for policymakers to balance oversight of, and innovation in, new technologies. We explore key examples and global best practices in the use of sandboxes across tech and telecoms in privacy, spectrum, satellite and AI.

  • Sandboxes enable the testing of new, innovative services and technologies in a controlled environment, giving policymakers an early view on how to adapt to their development, while potentially reducing the need for intense regulatory scrutiny once launched on the market.

  • Google’s attempt to introduce changes to browser privacy was met with strong criticism from regulators in the EU and US. In contrast, the commitments accepted by the CMA in the UK signalled a more positive approach that relied on regular reporting and stakeholder testing.

  • Policymakers in India and the UK have pioneered the use of sandboxes to test spectrum sharing in unlicensed bands, including the in-demand upper 6GHz. However, this has not yet made for a direct link between sandbox results and regulators’ subsequent assignment plans.

  • Regulators in Brazil and Zambia have enabled operators to pilot D2D satellite services in connecting rural areas. However, as countries move ahead to license the technology, testing obligations may delay commercial launches and the resultant benefits from reaching targeted communities.

  • The EC has mandated the creation of sandboxes for assessing compliance of high-risk systems with the EU’s AI Act, while the UK Government wants to see if temporarily relaxing regulation could drive investment and innovation in the domestic AI sector, and in turn power economic growth.

  • While sandboxes tended to focus initially on promoting technical or regulatory innovation, more recent examples have sought to support both priorities. Nevertheless, despite the use of sandboxes across telecoms and tech, they may still be an underused tool at regulators’ disposal.

Sandboxes may help counter the narrative that regulation stifles investment

Regulatory sandboxes provide controlled environments in which to test new, innovative services and products, supporting their commercial development and deployment, while also informing future regulatory approaches. With regulation often cited as a barrier to innovation, there have been calls for the use of sandboxes across the digital economy, resulting in their application in the context of AI, privacy and telecoms (see Table 1). In jurisdictions such as the EU and UK, regulators have faced pressure to adopt a more pro-growth approach to effecting their responsibilities. While this has arguably provided some of the impetus behind an ongoing push for the simplification of rules or outright deregulation within given sectors, the use of sandboxes to encourage growth through innovation has seemingly been underused so far.

Providing regulators early oversight of new technologies enables them to influence the development of new technologies and practices, ensuring that when such new services are rolled out at scale, consumers are protected while markets remain fair and competitive. Although this kind of regulatory influence or intervention may seem unnecessary to some during the product development phase, the alternative could be less productive and more burdensome for both the private sector and regulators. If sandboxes are not established, bringing potentially innovative new practices, goods and services to market could be a slower process that is subject to more intense and ongoing regulatory scrutiny post-launch.

The UK offered a more amenable testing ground for Google’s browser privacy changes compared to the EU and US

In January 2021, in the UK, the Competition and Markets Authority (CMA) opened an investigation into Google over the implementation of a new “privacy sandbox”, which replaced third-party cookies (TPCs) in its Chrome browser and Chromium browser engine. The CMA was concerned about the potential for the changes to concentrate advertising spend on Google’s ecosystem at the expense of its competitors (see Table 2). Following the investigation, Google agreed to a set of commitments that subjected the new advertising practice to supervision from the CMA as well as the Information Commissioner's Office (ICO). This supervisory approach created a de facto regulatory sandbox for Google to test its approach.

Following the acceptance and enforcement of these commitments, Google and the CMA have published quarterly reports on the privacy sandbox’s testing and implementation, with the CMA also issuing guidance to industry stakeholders on how to test its effectiveness. Throughout, Google and the CMA collaborated on revised approaches to advertising and privacy. Eventually, in April 2025, Google announced it would revert to its original approach to TPCs, prompting the CMA to release it from its privacy commitments, subject to a six-month assessment period.

Although Google’s change to browser privacy in the UK was ultimately not adopted permanently, the fact that the CMA enabled Google to test a solution without impacting competition in the wider adtech market highlights the potential benefits and effectiveness of regulatory sandboxes. In the US, the Department of Justice (DOJ) brought a broader antitrust case against Google in January 2023 over its dominance in the adtech market. Google’s privacy sandbox proposals fell within this case’s scope due to the perceived competitive advantage this would give the firm in online advertising. In April 2025, a US District Court ruled that Google held a monopoly in the adtech market, leaving it open to the enforcement of behavioural or structural remedies.

In the EU, the EC’s approach was more similar to that of the DOJ, with a broader antitrust case that began in 2021 leading to a €2.95bn (£2.5bn) fine for Google in September 2025. Again, although this was a wider case related to Google’s adtech monopoly, the CMA’s approach seems more productive, with years of actual testing leading to Google revising its approach, rather than a hefty fine being imposed in the EU after the same amount of time. It is important to note, though, that Google’s approach of attempting to implement its privacy sandbox without prior regulatory assessment led to these cases. This further highlights the need for regulatory sandboxes to be a better-established step in the development of new technologies, practices and services.

Spectrum sandboxes may not be influencing regulatory decisions on the upper 6GHz band

Regulatory sandboxes have also been used in telecoms to explore spectrum sharing in unused bands. Between 2024 and 2025, in the UK, the Department for Science, Innovation and Technology (DSIT) provided £5m of funding for a sandbox to test sharing between licensed, mobile use cases and unlicensed, Wi-Fi use cases in the in-demand upper 6GHz band. Tests were conducted over the course of one year, with DSIT establishing a clear, three-stage process consisting of: i) practical testbeds; ii) simulation and modelling; and iii) an economic and regulatory assessment. The sandbox’s regulatory assessment suggested further research and stakeholder consultation on the issue, while also highlighting the testing’s implications that sharing the band may represent the most effective option.

The choice of upper 6GHz for testing was likely due to the band’s uncertain future at the time. More recently, in July 2026, Ofcom announced its decided approach to the band’s assignment, prioritising the upper 540MHz for mobile and the lower 160MHz for Wi-Fi. Although a positive example of a regulatory sandbox, it is unclear whether the sandbox tests influenced Ofcom’s decision. However, while this was also a one-off project run by DSIT, Ofcom’s 2022 spectrum roadmap and subsequent workplans have stressed the importance of further spectrum sharing, with the regulator stating that it would consider the use of sandboxes for testing in real-world environments.

In March 2024, the Indian Government’s Department of Telecommunications (DoT) issued guidelines on the creation and operation of spectrum regulatory sandboxes. The guidelines established a simple, portal-based system for operators and academia to request permission to launch spectrum sandboxes. In November 2024, the DoT then published draft regulatory sandbox rules that enable it to either lead the creation of sandboxes or to do so upon receipt of proposals from operators. By establishing this process, operators have a clearer route to testing new services and solutions such as spectrum sharing, reducing regulatory uncertainty. Although it is too early to judge the impact of these sandboxes, support for their use has remained. In January 2025, the International Telecommunication Union’s (ITU) India branch recommended that the Government initiate a number of spectrum sandboxes in preparation for the development of 6G by focusing on parts of the upper 6GHz band, as well as the 7025-8400MHz and 14.8-15.35GHz frequency ranges.

Requiring sandboxes for D2D satellite may delay the service’s benefits for rural connectivity

The development of direct-to-device (D2D) satellite services is expected to be key in delivering universal connectivity, with telecoms operators and big tech firms all stepping up their involvement. In 2024, in Brazil, Anatel announced it would be creating a regulatory sandbox for D2D satellite services, reportedly encouraged by Claro and TIM’s plans to conduct their own trials with AST SpaceMobile. From April 2024, Anatel initially allowed these services to temporarily use spectrum bands typically allocated to mobile (i.e. 700MHz, 850MHz, 900MHz, 1.8GHz, 1.9GHz, 2.1GHz, 2.5GHz). In July 2026, Anatel incorporated D2D satellite services into its Frequency Band Allocation, Destination and Distribution Plan (PDFF) – creating the regulatory conditions for these services to be implemented freely by operators across their spectrum portfolio. Similar to the approach taken by the DoT in India, Brazil used an online portal-based system where operators could request the use of the satellite sandbox.

In August 2024, the Zambia Information and Communications Technology Authority (ZICTA) also proposed the use of a temporary regulatory sandbox to test D2D satellite services, focusing on mobile spectrum (similar to Brazil) between 694MHz and 2.7GHz. ZICTA, however, plans to await the conclusions of the World Radiocommunication Conference 2027 (WRC-27) before finalising its approach to the technology.

The use of regulatory sandboxes in these instances may be unnecessary, though, with a number of countries already having adopted regulatory frameworks for the authorisation of D2D satellite services, including Canada and the US. Even in Brazil, where Anatel did use a regulatory sandbox to test D2D satellite services, the regulator cut its testing programme short. Anatel originally planned to continue its sandbox tests until October 2026, but instead implemented a framework for D2D satellite services in July 2026. While sandboxes enable regulators to trial the viability of these services (particularly when sharing spectrum with mobile services) before they are brought to market, their use could potentially delay commercialisation, ultimately delaying the positive impacts of the service such as improving rural connectivity and reducing digital exclusion.

Measures to support AI development must come with appropriate safeguards

Internationally, regulators have begun to explore the use of sandboxes in the development of AI. In the EU, the EC’s Digital Omnibus package has proposed that the European AI Office – the bloc’s centralised body for AI expertise – establish an EU-wide sandbox for AI. Under the EU’s AI Act, Member States are already required to establish their own AI sandboxes or to join another by 2 August 2026 or risk failing to comply, which would potentially open them up to penalties. Spain has led the charge by establishing a three-year pilot sandbox test in 2023 during its presidency of the Council of the EU. The sandbox is focused on testing the AI Act’s requirements for high-risk systems, differing from other examples of regulatory sandboxes, which have focused more on testing new technologies and services (e.g. D2D in Brazil and Zambia) rather than new regulations. Since the adoption of the act, Denmark, Estonia and Luxembourg have also established specific AI sandboxes, while most other Member States remain in the planning and development stage.

In October 2025, in the UK, DSIT announced a regulatory sandbox for AI through its AI Growth Labs initiative. The scheme aims to enable the private sector to test new AI products in real-world conditions (e.g. to reduce bureaucracy in housing development applications), with certain rules temporarily relaxed under government supervision. DSIT also noted the role of AI Growth Labs in shifting the UK’s regulatory frameworks to better reflect the Growth Duty, which requires sectoral regulators to consider the importance of promoting economic growth when carrying out their legislative duties. In May 2026, the Government announced a new Regulating for Growth Bill that would give it broad sandboxing powers, which seem especially focused on driving investment and innovation in the UK’s AI sector. Although little detail has been provided on the focus areas or processes underpinning the sandboxes announced to date, DSIT has ruled out using them in any way that impacts consumer protection and safety provisions, fundamental rights (e.g. privacy), workers’ protections and intellectual property rights.

In the US, Utah has pioneered the creation of a state-level regulatory sandbox for AI, the AI Learning Lab, alongside its own AI Policy Office. The sandbox is already being applied to the healthcare and education sectors, with AI services exempt from certain regulatory requirements, maximum penalties and regular deadlines for compliance with specific laws that the office may deem to inhibit the use of AI. This approach gives firms developing new AI tools regulatory certainty and protection from harsh penalties while also allowing regulators to adapt rules to these new tools before widespread commercial releases. Other US states, such as Connecticut, Oklahoma and Texas, are also developing their own sandboxes for AI.

However, in March 2026, the Trump Administration published a brief national policy framework for AI aimed at halting a fragmented, state-by-state approach to regulating AI, stating that “a patchwork of conflicting state laws would undermine American innovation and our ability to lead in the global AI race”. The framework calls on Congress to establish national-level regulatory sandboxes for AI, which could either support initial state-level initiatives, or potentially preempt them altogether.

Future regulatory sandboxes should look to explore and promote technical and regulatory innovation

Regulatory sandboxes are being applied in different ways across wide-reaching use cases. Examples such as Google’s privacy sandbox are (or were) focused on potential technical innovation, testing new practices under relaxed regulatory scrutiny that would not normally be permitted. Elsewhere, the focus is on regulatory innovation. Spain’s AI sandbox, for instance, invited firms developing AI tools to test compliance with the AI Act’s requirements for high-risk AI systems. It is possible, however, for regulatory sandboxes – including those we have identified – to fit into both of these categories.

While D2D satellite and spectrum sharing sandboxes have enabled pilots of new use cases and approaches to spectrum management (technical innovation), they can also inform regulators on how to develop frameworks that support these technological developments (regulatory innovation). In the UK, the introduction of the Regulating for Growth Bill should better enable regulators such as Ofcom and the CMA to create these dual-focused regulatory sandboxes, allowing them to better foster innovation and test new regulation. If successful, such a broad, legislative framework should be regarded as best practice by other countries.

Such sandboxes have the potential to be used more widely. For example, in telecoms, where most sandboxes so far have focused on spectrum sharing, there have been calls to test network slicing in a similarly controlled environment. Several operators in Europe are keen to deploy network slicing, arguing that it will enable them to leverage the advanced capabilities of 5G networks to offer innovative new services for consumers. Policymakers have been hesitant, however, amid concerns that it would undermine net neutrality. A sandbox could prove useful here, enabling operators to soft-launch network slicing while allowing regulators to evaluate how it works in practice, as well as analyse any impacts on the functioning of the open internet.