Attention Substack users! ETO blog posts are also available on Substack.
⭐️ Overview
In our first edition of the AGORA state AI governance blog series, we covered Utah's lighter-touch model of AI governance spanning state capacity building, experimentation, and targeted consumer protections. This edition explores key elements of AI regulatory sandboxes, which are often brought up in the context of iterative, adaptable AI governance approaches and have been cited in high-level AI policy documents including the AI Action Plan and the White House National Policy Framework for AI. AI regulatory sandboxes are programs that test AI systems in controlled environments to ultimately inform regulatory experimentation.
States including Delaware, Utah, and Texas have adopted AI regulatory sandboxes. Other states like Wyoming host regulatory sandboxes focused on financial technology and medical innovations but have not yet created sandboxes exclusively for AI. The features of AI regulatory sandboxes covered in this blog are drawn from Utah's AI Policy Act and the Texas Responsible AI Governance Act (TRAIGA), both of which were early, influential AI regulatory frameworks that became law. This blog finds that AI regulatory sandboxes established in Utah and Texas share core features such as limits on testing and participant reporting, although their implementation details vary slightly.
AGORA is a collection of AI-related laws, regulations, standards, and similar documents. Each document in AGORA is either an entire law or a thematically distinct, AI-focused portion of a longer text. An AGORA document includes metadata, summaries, and thematic codes developed through rigorous annotation and validation processes. Thematic codes are organized under a taxonomy that consists of several dimensions, including risk factors and governance strategies.
🏛️ Key elements of AI regulatory sandboxes
AI regulatory sandboxes are programs that test AI systems under certain constraints and gather data to inform new regulations or regulatory updates. They provide a flexible learning environment for government and industry stakeholders to jointly shape regulations that are appropriately calibrated to AI risks. AI regulatory sandboxes also temporarily provide regulatory relief to sandbox participants.
Although the precise details of AI regulatory sandboxes vary across jurisdictions, they are usually comprised of at least some of the following features:
Government oversight
Government departments, agencies, or offices typically manage AI regulatory sandboxes. To ensure AI systems operate legally and ethically, these authorities partner with sandbox participants and other regulatory bodies with relevant jurisdictions.
TRAIGA directs the Texas Department of Information Resources to administer an AI regulatory sandbox in coordination with relevant state regulatory agencies and a new AI Council composed of members of the public and state lawmakers. The Council ensures that AI systems are deployed responsibly, identifies existing regulations that hinder innovation and opportunities to improve state government operations through the use of AI, investigates instances of regulatory capture and anti-competitive practices, offers legislative recommendations, and studies the current AI regulatory environment.
The Utah AI Policy Act creates an Office of AI Policy within Utah's Department of Commerce. In collaboration with state government agencies, the Office is responsible for administering an AI regulatory sandbox coined the "AI Learning Laboratory Program." The Office consults with stakeholders about potential regulatory proposals and creates rules for the sandbox that outline participation procedures, data usage and cybersecurity requirements, and participant removal criteria and disclosures to consumers and the state government.
Application process and eligibility criteria
Before participating in an AI regulatory sandbox, applicants such as AI developers must submit information and meet criteria that demonstrate their ability to responsibly participate in the sandbox and contribute to regulatory findings. Applicants must articulate why their expertise, organizational capacity, and planned AI risk mitigations make them a strong candidate to test AI systems in collaboration with the public sector.
Under TRAIGA, an individual or organization seeking to participate in the sandbox program must submit an application to the Texas AI Council. Applications include a detailed description of the AI system and its intended use, plans for mitigating adverse consequences, proof of compliance with applicable federal AI laws and regulations, and a benefit assessment.
In comparison, eligibility requirements for AI regulatory sandbox participants under the Utah AI Policy Act include possessing the technical expertise and resources to responsibly develop and test AI technology; demonstrating that the AI technology provides potential substantial consumer benefits that may outweigh risks that arise from mitigated regulations; crafting an effective plan to monitor and minimize identified risks from testing; and setting appropriate bounds for testing based on risk assessments.
Limits on scale, scope, and duration of testing
AI regulatory sandboxes encourage targeted experimentation by imposing conditions on the scale, scope, and duration of AI testing. These conditions define the environment in which an AI system is deployed, influence how AI testing results are interpreted, and clarify unacceptable behavior that could lead to participant removal from the sandbox.
TRAIGA enables sandbox participants to obtain legal protection and limited access to the Texas market to test AI systems without obtaining a regulatory authorization for three years, with the possibility for an extension. During this time, a state agency or Attorney General cannot hold sandbox participants responsible for violation of laws or regulations waived by the sandbox policies. However, the Texas AI Council or a state agency responsible for regulating a sector impacted by an AI system may recommend to the Department of Information Resources that a participant be removed from the sandbox if their AI system poses risks to public safety or violates regulations not covered by their sandbox participation.
The Utah AI Policy Act permits regulatory mitigation agreements between sandbox participants and Utah's Office of AI Policy. These agreements specify conditions around the participant's AI deployment, including the number and types of users, geographic reach, technical safeguards, and waived regulations. For higher risk AI systems, the Office can impose stricter requirements like additional cybersecurity auditing procedures. Participants can join the sandbox for 12 months with the possibility of a 12 month extension, although the Office can remove participants at any time.
Participant and government reporting
Reports that contain data gleaned from AI regulatory sandboxes are a key driver of regulatory experimentation and smart, adaptive regulation. Federal and state government authorities that host regulatory sandboxes and legislatures that oversee government programs can use these reports to inform updates to regulations, AI systems, or the design of sandboxes themselves. For instance, if reports indicate that an AI system operates within safe bounds in the sandbox when regulations are temporarily curtailed, then the government may amend those regulations to be more lenient.
TRAIGA requires program participants to provide quarterly reports to the Texas Department of Information Resources that include AI system performance metrics, AI risk mitigation measures, and feedback from consumers and impacted stakeholders. The Department of Information Resources also has reporting duties: it must annually report to the Texas legislature on the number of program participants testing an AI system, the overall performance and impact of tested AI systems, and recommendations on regulatory changes.
The Utah AI Policy Act creates specific AI incident reporting requirements for sandbox participants. Participants must report any incidents resulting in consumer harm, privacy breaches, or unauthorized data usage to the Office of AI Policy, which may lead to removal of participants from the sandbox. Additionally, the Office of AI Policy must report to a legislative committee regarding the research agenda and findings of the learning laboratory.
📝 Recap
AI regulatory sandboxes established in Utah and Texas share core features and policy objectives, although their implementation mechanisms and oversight bodies differ slightly across the state governments. Despite varying implementation details, these AI regulatory sandboxes ultimately aim to help government authorities ensure that regulation keeps pace with rapidly changing technologies. For example, Utah's AI regulatory sandbox has already enabled the healthcare platform Doctronic to trial their AI-enabled prescription refill service -- a departure from the state's traditional medical practice rules. Similar trials of AI applications will likely emerge as AI regulatory sandboxes gain greater recognition as an iterative, flexible governance approach.
✉️ Get in touch
As always, we're glad to help you get the most out of AGORA and our other resources. Visit ETO's support hub to contact us, book live support with an ETO staff member, or access the latest documentation for our tools and data. 👋

