TL;DR: The EU AI Act includes dedicated support measures for micro, small, and medium enterprises under Articles 57-63. Regulatory sandboxes allow SMEs to test AI in a supervised environment with relaxed enforcement. Smaller companies also get lighter technical documentation requirements and proportionate information obligations. However, sandboxes do not eliminate liability for harm, the application process takes months, and most startups are better served by the standard compliance pathway combined with the AI Office's free SME helpdesk resources.
Most EU AI Act coverage focuses on large companies: platform operators, medical device manufacturers, financial institutions. But the EU legislature was aware that the regulation's compliance requirements could disadvantage startups and smaller companies competing with better-resourced incumbents. Articles 57 through 63 are the result: a set of support measures and special pathways designed to reduce compliance costs for smaller players without creating safety loopholes.
This guide explains what those measures actually are, how they differ from standard requirements, which countries have sandbox programmes running, and how to decide whether applying for a sandbox makes sense for your business.
Why the EU AI Act includes SME support measures
The political rationale for SME provisions is straightforward. If the EU AI Act makes compliance so expensive that only large companies can afford it, innovation moves to non-EU jurisdictions and EU users are still exposed to AI systems built by companies that do not face EU requirements at all. That outcome was explicitly flagged as a risk during the legislative process.
The support measures are not charity. They are designed to lower the cost of entry to compliance without removing the substantive safety and transparency obligations that apply to AI in high-risk contexts. A micro-enterprise building a hiring AI still cannot discriminate; it just gets to produce shorter documentation proving it does not.
It is worth being direct about the limits of SME support. The EU AI Act's reduced obligations apply to documentation and procedural requirements, not to the fundamental rights or safety obligations. An SME whose high-risk AI system causes harm faces the same liability exposure as a large company. The lighter documentation requirements do not create a lower bar for system performance.
Regulatory sandboxes: what they are and how they work
A regulatory sandbox under Article 57 is a supervised real-world testing environment. The national market surveillance authority collaborates directly with participating companies to:
- Allow the AI system to be tested with real users and data before full conformity documentation is required
- Provide direct regulatory feedback on the system design, data handling, and governance approach
- Create a record of the testing process that feeds into the eventual conformity assessment
Sandbox participation is supervised, not unsupervised. The authority has visibility into what you are testing and how. In exchange for this transparency, you get regulatory input early enough to shape your system, rather than discovering problems after you have committed to an architecture.
The sandbox does not suspend the substantive EU AI Act requirements. Prohibited practices (Article 5) are still prohibited inside a sandbox. Human oversight requirements still apply. What the sandbox relaxes is the formal documentation and conformity assessment process, giving you time to develop and refine those materials while testing.
National vs. pan-EU sandboxes
Spain: the most advanced national sandbox
Spain's Agency for the Supervision of Artificial Intelligence (AESIA) launched what became the first operational EU AI Act sandbox in 2023. AESIA's sandbox has accepted participants across several sectors and has published guidance based on what it learned from early cohorts. If you are testing AI in Spain or serving Spanish users, AESIA's sandbox is the most mature option.
The Netherlands
The Dutch Authority for Digital Infrastructure (RDI) piloted an AI sandbox programme drawing on experience from earlier digital regulation sandboxes. The Netherlands sandbox is particularly relevant for companies building AI for logistics, agriculture, or water management given those sectors' prominence in the Dutch economy.
France and Germany
Both countries have announced sandbox frameworks but were still developing operational capacity as of mid-2026. Germany's BNetzA has indicated it will operate a sandbox alongside its enforcement function. France's sandbox will sit within whichever authority is ultimately designated as the lead MSA.
The AI Office's pan-EU coordination role
Article 58 creates an EU-level coordination mechanism for sandboxes. The AI Office does not run its own sandbox but coordinates between national sandboxes to facilitate cross-border testing. If your AI system needs to be tested across multiple EU markets, the AI Office can help connect you with multiple national sandbox programmes.
The AI Office also runs what it calls a "virtual sandbox" for cross-border cases where a physical national sandbox is not available. This is less mature than the national programmes but is useful for companies that operate across the EU without a specific anchor country.
How to apply for sandbox access
Eligibility criteria under Article 57 require applicants to be:
- A provider or prospective provider of a high-risk AI system (or an AI system that may fall in that category)
- An SME or startup in most national programmes (though some programmes allow larger companies in limited-capacity roles)
- Willing to operate transparently with the national authority throughout the testing period
The application process typically involves:
- A written application describing the AI system, its intended use case, the Annex III category you believe applies, and your current compliance maturity level.
- A preliminary technical description of the system including its training data, outputs, and how decisions are made.
- A proposed testing plan describing what you intend to test, with which users or populations, and what data you will collect.
- A description of the governance and oversight arrangements you will have in place during testing.
Application timelines vary. Spain's AESIA reports that initial screening takes four to six weeks, with full entry into the sandbox taking up to three months from application. Plan for the full sandbox process to run six to twelve months before you have the outputs you need for a conformity assessment.
What sandbox participation does and does not exempt you from
What it does: Delays the conformity assessment until after sandbox exit. Provides direct engagement with the regulator, reducing uncertainty about how your system will be assessed. In some national programmes, participating companies receive written guidance from the authority that can be used as evidence of good faith in any subsequent enforcement action.
What it does not do: Exempt you from prohibited practice prohibitions (Article 5). Suspend your obligation to implement human oversight measures. Remove your liability if the AI system causes harm to users or third parties during testing. Replace the eventual conformity assessment.
On the liability point: companies sometimes apply for sandbox participation under the mistaken belief that it provides a regulatory shield. It does not. If your hiring AI discriminates against candidates during a sandbox test, the affected candidates retain their legal rights regardless of your sandbox status.
Lighter compliance obligations for micro and small enterprises
Even outside sandbox programmes, micro and small enterprises qualify for reduced obligations in two specific areas.
Proportionate technical documentation (Article 53(4)). Micro and small enterprises can produce a simplified version of the technical documentation required under Annex IV. The simplified version must still cover the system description, intended purpose, risk management approach, and conformity evidence, but the level of detail required is proportionate to the company's resources and the complexity of the system.
This is meaningful for early-stage companies. The full Annex IV technical documentation can run to dozens of pages per system. A simplified version for a small company with a clear, limited-purpose AI system might be a fraction of that.
Reduced information obligations (Article 13(4)). The transparency information that high-risk AI systems must provide to deployers can be simplified for small enterprises. The core content requirements remain (system purpose, limitations, oversight requirements), but the format and depth can be adjusted.
Note that these reductions apply to the provider's own obligations. They do not reduce the obligations that apply when the small enterprise acts as a deployer of a third-party high-risk AI system.
Omnibus update: small mid-cap (SMC) extension. The Digital Omnibus provisional agreement (May 7, 2026) extends these SME support measures to a new category: "small mid-cap" enterprises defined as companies with fewer than 750 employees and annual turnover not exceeding €150 million (or balance sheet not exceeding €129 million). Small mid-caps that previously fell outside the SME definition now qualify for proportionate technical documentation, priority sandbox access, and more tailored penalty calculations. This extension applies once the Omnibus is formally adopted.
SME-specific guidance from the AI Office
The AI Office operates several resources specifically for smaller companies:
AI Act SME helpdesk. A free inquiry service where companies can submit questions about how the AI Act applies to their specific case. Response times are not guaranteed, but the service is designed for companies without in-house compliance teams.
Plain language guidance. The AI Office has committed to publishing sector-specific guidance in formats accessible to non-legal readers. As of mid-2026, guidance documents for health, hiring, and financial services sectors were in development.
Standardisation participation. The AI Office coordinates SME participation in the European standardisation work (CEN/CENELEC) that develops the harmonised standards under the AI Act. Complying with harmonised standards creates a presumption of conformity, which is valuable for smaller companies that cannot afford full legal analysis of every compliance question.
Priority sectors for sandbox testing
National sandbox programmes have concentrated on sectors where both the public interest in testing and the commercial demand from SMEs are highest:
- Agriculture and food. AI for crop monitoring, yield prediction, and food safety inspection.
- Health and wellbeing. AI diagnostic tools, patient triage, and mental health support apps below the full medical device threshold.
- Transport and logistics. AI for route optimisation, fleet management, and autonomous vehicle components.
- Public sector services. AI for administrative decision support, document processing, and citizen services.
If your AI system falls in one of these sectors, you are more likely to find a receptive national sandbox programme and published guidance specific to your use case.
Is a regulatory sandbox worth it for most startups?
For the majority of early-stage startups, the honest answer is probably no, at least not as a first step.
The application process is time-consuming. The sandbox adds months to your compliance timeline before you can place your system on the market. And the benefits, direct regulatory feedback and delayed conformity assessment, are most valuable when your compliance pathway is genuinely unclear or when you are operating in a highly regulated sector where getting the documentation wrong is expensive.
The sandbox makes the most sense when:
- You are building high-risk AI in health, recruitment, credit, or law enforcement
- Your system's Annex III classification is ambiguous and you want official guidance before committing to a compliance approach
- You have real users available for structured testing under supervision
- Your product roadmap allows for a 9-18 month runway before market launch
For most startups building AI productivity tools, coding assistants, or customer service applications, the minimal-risk or limited-risk pathways are more direct. The AI Office's free helpdesk resources and the AI compliance cost guide at AI compliance cost for small teams in 2026 are better starting points than a sandbox application.
See also the EU AI Act deployer evidence gaps guide for the documentation gaps most commonly found in SME compliance audits.
What lighter documentation actually looks like in practice
The proportionate technical documentation option under Article 53(4) is one of the more practical benefits for genuine micro and small enterprises. To make it concrete, here is what the simplification allows.
The full Annex IV technical documentation for a high-risk AI system includes: a detailed system description with architecture diagrams, training data documentation including data governance procedures and data sourcing records, development methodology including the testing approach and evaluation metrics, post-market monitoring plan, risk management records, instructions for use, EU declaration of conformity, and records of the conformity assessment process.
For a small enterprise, the AI Office's guidance allows a streamlined version that covers the same topics but at a depth proportionate to the system's complexity and the company's size. A startup with five engineers building an AI-assisted recruitment screening tool does not need enterprise-scale documentation. What it does need is documentation that addresses each topic, even briefly, in a way an authority can evaluate.
The key is that "proportionate" does not mean "absent." An authority reviewing simplified documentation still expects to see evidence of: what data trained the model, how the model was tested before deployment, what the risk management process identified as the main risks, and how those risks are monitored. The simplification is in depth, not in scope.
Micro enterprises should be especially careful about interpreting the simplification as permission to skip risk management entirely. The risk management system under Article 9 is a substantive requirement. The documentation of it can be simpler for a small company, but the process itself must happen.
Getting help from the AI Office helpdesk
The AI Office runs a dedicated helpdesk for companies seeking guidance on EU AI Act obligations. The service is free and covers questions about system classification, documentation requirements, and conformity assessment procedures.
In practice, the helpdesk is most useful for classification questions (is my system Annex III high-risk?), for understanding what the simplified documentation requirements mean for a specific system, and for identifying which national authority to contact for further guidance.
The helpdesk does not provide binding legal opinions. Its answers are guidance, not authoritative determinations. If you are making a major investment decision based on your AI Act classification, treat the helpdesk as a starting point and get a formal legal opinion from counsel with EU AI Act expertise.
The AI Office also maintains a library of sector-specific guidance documents, many of which are specifically written for SMEs. As of mid-2026, guidance for healthcare AI, recruitment AI, and educational technology was published or in draft. These documents are free and written in more accessible language than the regulation text itself.
For a full picture of how compliance obligations translate into actual costs for a small company, see the AI compliance cost for small teams in 2026 guide, which breaks down legal, documentation, and tooling costs by company size and risk tier.
Related Reading
- EU AI Act August 2026 compliance checklist
- High-risk AI documentation templates for August 2026
- Deployer evidence gaps for SMEs
- GPAI compliance checklist for August 2026
- AI compliance cost for small teams in 2026
- Annex III high-risk AI systems explained
- AI governance for small teams complete guide
- EU AI Act Conformity Assessment: What It Is and Who Must Do It
- EU AI Act national competent authorities: who enforces in each EU memb
- EU AI Act post-market monitoring: what Article 72 requires for high-ri
- EU AI Act enforcement starts August 2, 2026: what it means and what to
- EU AI Act GPAI Codes of Conduct: What They Require and How to Use Them
- EU AI Act Article 13 transparency: what deployers must tell users of h
- EU AI Act high-risk classification: what the May 2026 draft guidelines
- EU AI Act prohibited AI practices: the 8 banned uses as of August 2, 2
- EU AI Act August 2026: 6-week compliance sprint checklist
