Traficom is Finland's contact point for the EU AI Act since January 2026. In April 2026 Finland and Estonia agreed to jointly build AI regulatory sandboxes -- a rare cross-border model for small states sharing compliance infrastructure before the Act's August 2026 deadline.
Details
Promoter
Finnish Transport and Communications Agency (Traficom) & Estonian Government Office
Period
January–April 2026
Region (NUTS)
FI1B1
Keywords
AI regulation, digital government, cross-border cooperation, data protection
Context
Under the EU AI Act, every member state must have an operating AI regulatory sandbox by 2 August 2026. Finland designated Traficom, its transport and communications regulator, as the country's single point of contact with sandbox powers from 1 January 2026. This is inherently a joint Finnish-Estonian initiative, not a practice from one country later adopted by the other.
Objectives
Finland and Estonia set out to jointly develop AI regulatory sandboxes so providers operating in both countries could go through one shared controlled-testing process for high-risk AI systems in public services, employment or critical infrastructure, instead of duplicating national infrastructure.
Activities
A high-level Estonian delegation led by Secretary of State Keit Kasemets visited Helsinki on 19-20 April 2026, where the two governments agreed to jointly build their sandbox infrastructure and pursue shared testing tracks for high-risk AI systems.
Conclusions
As of the April 2026 agreement this is a cooperation framework rather than an operating joint sandbox: no cases have been processed, no compliance outcomes are available, and each country's own AI Act implementing legislation was still pending at the time of the agreement.
Implementation
Indicative cost
Low (< €50k)
Time to results
Short (< 1 year)
Staffing & skills
Traficom (Finnish Transport and Communications Agency) — single point of contact since Jan 2026, Estonian Government Office, led by Secretary of State Keit Kasemets
Conditions for success
Legally designated national single point of contact for the AI Act
High-level bilateral political engagement
Agreement on shared testing tracks for high-risk AI systems
Common failure modes
As of April 2026 this remains a cooperation framework with no operating joint sandbox
Each country's own AI Act implementing legislation was still pending at signing
No case throughput or compliance outcomes exist yet
Denmark's data-protection and digitalisation agencies jointly run a regulatory sandbox giving organisations free, project-specific guidance on GDPR and EU AI …