Under Royal Decree 817/2023, Spain became the first EU country to run a live AI Act regulatory sandbox: a 2025 cohort tested 12 high-risk systems — biometric age checks, medical diagnostics, hiring tools — feeding AESIA's 16 public compliance guides published in December 2025.
12
High-risk AI systems selected for first cohort (3 April 2025)
16
Compliance guides published (16 December 2025)
Details
Maturity
Scaling
Promoter
Agencia Española de Supervisión de la Inteligencia Artificial (AESIA)
Period
2023–2026
Keywords
AI regulation, compliance, public administration, EU AI Act
Context
Royal Decree 817/2023, published 9 November 2023, created Spain's national AI regulatory sandbox, run by the Spanish Agency for the Supervision of Artificial Intelligence (AESIA), letting providers and deployers test high-risk AI systems under regulatory supervision ahead of the EU AI Act's enforcement deadlines.
Objectives
Give providers and deployers of high-risk AI systems hands-on regulatory supervision before the AI Act's deadlines, coordinating with the European AI Office.
Activities
The first public call opened December 2024; on 3 April 2025 AESIA provisionally selected 12 high-risk AI systems for the inaugural cohort, spanning biometric age verification, healthcare diagnostics, employment screening and critical-infrastructure monitoring. By 2026 the programme had reached a third call cycle.
Results
On 16 December 2025, AESIA published 16 compliance guides in Spanish and English covering risk management, data governance, transparency and human oversight, drawn from the sandbox's first cohort.
Conclusions
As of mid-2026, no independent outcome evaluation of the 12 tested systems - error rates, harm reduction, or comparable measures - has been published, and the guidance remains non-binding.
Implementation
Indicative cost
Medium (€50k–€500k)
Time to results
Medium (1–3 years)
Staffing & skills
AESIA multi-disciplinary reviewers
Conditions for success
A statutory legal basis (Royal Decree 817/2023) establishing the sandbox before the AI Act's enforcement deadlines
Coordination with the European AI Office
A structured public call-and-selection process run in successive annual cycles
Common failure modes
No independent outcome evaluation of the tested systems has been published
Resulting compliance guidance remains non-binding
Identities and full assessment records of sandboxed systems are not fully public
Australia's Digital Transformation Agency piloted a draft AI impact-assessment framework with 21 volunteer federal agencies, testing whether it caught risks …