Why Regulators Are Rethinking the 'Sandbox' Approach to AI Governance
Regulatory sandboxes, once hailed as the solution for testing artificial intelligence safely, may be creating more problems than they solve. A critical assessment from George Washington University's Regulatory Studies Center challenges the widespread enthusiasm for these controlled testing zones, arguing that they often introduce bureaucratic overhead, regulatory capture risks, and democratic deficits without necessarily delivering better AI governance.
The European Union AI Act mandated that member states establish at least one AI regulatory sandbox by August 2026, while the United States has seen similar proposals at both state and federal levels. Texas passed the AI Governance Act with a 36-month sandbox, and Brazil's Data Protection Agency launched a sandbox focused on personal data applications. Yet this global momentum may be misplaced, according to researchers who have conducted a comparative analysis of sandbox initiatives across Spain, Brazil, Singapore, and the United Kingdom.
What Are the Hidden Costs of Regulatory Sandboxes?
The appeal of sandboxes is straightforward: they allow regulators to observe how new AI systems behave in controlled environments before broader deployment. However, the research reveals that this approach carries significant downsides that policymakers often overlook. When regulators create special zones for "innovative" companies, they implicitly signal that lax regulation is necessary for technology to thrive, potentially weakening broader regulatory frameworks.
The operational challenges are substantial. Sandboxes require extensive application processes and complex governance structures that multiply bureaucratic overhead rather than streamline it. Perhaps more troubling, sandbox learnings often fail to translate into broader regulatory improvements. Insights gained from testing rarely inform general regulatory frameworks, meaning the investment in these programs may not yield systemic benefits.
Beyond administrative inefficiency, sandboxes create three critical governance risks:
- Regulatory Capture: Industry participants gain privileged access to regulators, potentially influencing policy development in their favor
- Democratic Deficits: Policy development occurs behind closed doors rather than through transparent, inclusive processes
- Participation Bias: Sandbox participants typically represent well-resourced organizations, excluding smaller innovators and affected communities from the conversation
Are There Better Alternatives to Sandboxes?
The research proposes that regulators can achieve sandbox-like benefits through less resource-intensive tools. Rather than creating special zones, governments can adjust enforcement priorities based on emerging technology characteristics through what researchers call "adaptive enforcement strategies." Regular stakeholder consultations and technical advisory committees can reduce information gaps more democratically than closed sandbox environments.
The analysis draws on responsive regulation theory while challenging its application to sandbox contexts. While regulatory flexibility and stakeholder engagement are valuable, they do not necessarily require sandbox structures. The study applies "smart regulation" principles that emphasize achieving regulatory objectives through the most efficient means possible.
How Should Regulators Decide Whether to Use a Sandbox?
Rather than abandoning sandboxes entirely, the research proposes a decision framework to help regulators assess whether a sandbox is genuinely warranted before committing resources. The framework addresses three core questions:
- Genuine Value: Under what circumstances do regulatory sandboxes provide real advantages over alternative approaches?
- Opportunity Costs: What are the costs of choosing sandboxes over other experimental regulatory tools?
- Efficiency: How can regulators achieve stated benefits through less bureaucratic means?
The conclusion is nuanced: what AI governance needs is not necessarily fewer sandboxes, but more rigorous use, monitoring, and evaluation of sandboxes alongside the full range of experimental regulatory instruments available to regulators.
How Are Policymakers Responding to AI Governance Concerns?
The sandbox debate unfolds against a backdrop of intensifying pressure on Congress to act on AI regulation. More than 20 members of Congress called for new or stronger AI regulation this week after a researcher warned that major AI companies are "gambling with our lives." Jacob Coxon, who quit his job at Anthropic on Tuesday, posted that people building AI "earnestly believe that it could kill us all by the end of the decade." His announcement garnered more than 150 million views on social media.
The response from lawmakers has been swift and bipartisan. Rep. Lori Trahan, D-Massachusetts, told CNBC that support for AI regulation has reached a "tipping point." "My phone has rung off the hook this week with rank-and-file Democrats and Republicans who want to see action," she stated.
Several bills have been introduced to address AI risks. Rep. Trahan and Rep. Jay Obernolte, R-California, introduced the Frontier Act, which aims to establish a framework for governing advanced AI model deployment. Rep. Nathaniel Moran, R-Texas, and Rep. Ted Lieu, D-California, introduced the "AI Kill Switch Act," requiring AI companies to maintain the ability to shut down, throttle, or suspend their models. Sen. Bernie Sanders, I-Vermont, and Rep. Greg Casar, D-Texas, announced the Ban Artificial Superintelligence Act, which would temporarily pause advanced AI development until the federal government establishes safety rules.
However, both the Senate and House are mostly out of session until the midterms, meaning there is a slim chance that any AI legislation will pass in the near future. Some lawmakers are already looking ahead to next year. Sen. Ruben Gallego, D-Arizona, urged Senate leadership to establish a bipartisan Senate Select Committee on AI at the start of the next Congress, noting that "jurisdiction over AI is scattered across multiple Senate committees, each with a focused lens but none with the full picture".
Ruben Gallego, D-Arizona
How Are Organizations Implementing AI Governance in Practice?
While policymakers debate regulatory frameworks, organizations across the Asia-Pacific region are grappling with how to govern AI in their own workplaces. Many companies are adopting AI tools faster than they are building the frameworks needed to manage them effectively.
A practical checklist for employers highlights the key governance steps organizations should take before and after deploying AI. The foundation is a clear workplace AI policy that establishes the purpose of AI use, acceptable use parameters, and governance processes. However, organizations must view this as more than a compliance exercise; the policy must remain relevant to the business, and those responsible for applying it must understand its purpose and intended outcome.
Organizations should also establish cross-functional AI governance committees that bring together representatives from legal, human resources, privacy, security, and risk management. These groups can oversee AI deployment, review higher-risk use cases, and ensure consistent decision-making across the organization.
Before deploying AI, employers should conduct checks to ensure fairness and robustness and to remove bias. Local and cultural contexts, including multilingual inputs, should be taken into account, and systems should be retested periodically to continue verifying performance. Auditable records should also be kept.
The challenge facing both regulators and organizations is the same: how to enable innovation while managing genuine risks. Whether through reformed regulatory sandboxes, alternative experimental tools, or organizational governance frameworks, the consensus is clear. The time for ad hoc approaches to AI governance has passed. What is needed now is deliberate, thoughtful, and systematic oversight that balances innovation with accountability.