If “trust is broken everywhere,” as Vinh Nguyen, a senior fellow for AI at the Council on Foreign Relations, told Tech Policy Press recently, we need to make it whole.
And that’s actually happening right now in spaces called “sandboxes,” where some businesses, government agencies and policymakers around the world are innovating and testing products and policies – together, in real time. In a deep dive I got to take in Lisbon last month, I saw first-hand that sandboxing is a powerful tool for breaking down distrust and enabling co-learning across sectors, borders and cultures.
This was in the 2026 edition of Datasphere Initiative‘s Sandbox Summer School, which I highly recommend to anyone who wants to learn how it’s done from people operating sandboxes in multiple countries. We learned about sandboxing in a sandbox of Datasphere’s brilliant design – a fun, collegial, rich and rigorous experience with peers from more than a dozen countries. In addition to all the information we consumed, we were designing, prototyping and presenting our own sandbox-related concepts to and for each other.
A few other characteristics of the program:
- A felt sense that all participants – hosts, speakers, learners – had brought a learner’s mindset. Because we ourselves demonstrated that, in sandboxes, participants learn on multiple levels, especially one another’s contexts, perspectives, goals and constraints but of course technology and what works for end users and under the law.
- Multiple fields were represented – fintech, energy, healthcare, AI, law & policy, data protection, telecommunications, etc.
- Multiple levels of expertise, from beginners to longstanding practitioners
- A tangible spirit of camaraderie throughout, including on karaoke night :)
So what is a sandbox, exactly? Summer school focused largely on operational and regulatory ones, the latter possibly because there were a number of regulators in our midst (see TUM Think Tank’s very helpful full typology). There’s an alphabet soup of terms being used for similar environments: e.g., “innovation hub,” “technical testbed,” “living lab” and even “decision accelerator lab.” While sandboxes traditionally focus on letting private companies test new products under temporarily relaxed regulation, it’s exciting to see that governments and regulators increasingly use them for “regulatory learning” to see how proposed rules and draft laws perform in the “real world” before formal adoption.
Datasphere’s own definition is “a controlled learning environment designed for structured experimentation under defined governance frameworks, timeframes and built-in safeguards to support iterative, multi-actor collaboration and evidence-based decision making.”
Sandboxing can be very efficient, because the learning is non-linear – people are learning simultaneously in real time, so no waiting for proposal => feedback => testing => feedback => revision => feedback => rinse => repeat. It can be efficient in another way, too. Regulators are increasingly speaking of the need for “harmonization,” or coordination across borders. It can be challenging because laws governing regulators are national, but it’s also logical because of companies and technologies (such as AI models) operating globally.
Just some of my summer school takeaways:
- Advance work needed: Sandboxes are far from one-size-fits-all, of course. Whoever is considering setting one up needs to pre-assess if a sandbox suits the need. A “maturity assessment” should be considered. Are human and financial resources sufficient and what are the benefits to the public or customer? Preliminary budgeting and mapping of the regulatory, stakeholder and innovation ecosystem are needed.
- A global ecosystem: Summer School was a window on the global sandbox ecosystem. For example, we learned that Singapore has “managed to make sandboxes crucial” (informed oversight for regulators and lower costs for startups); so has the UK, with sandboxes in the financial sector, healthcare, data privacy and emerging tech; the Nigerian Communications Commission is strengthening its regulatory sandbox by developing frameworks for onboarding, monitoring and evaluating live technology trials; this year Colombia opened its first cross-institution sandbox; Australia’s age verification project tested a huge number of solutions (48) unprecedentedly quickly with the help of AI; the economic development office of the Swiss canton of Zurich set up a sandbox for providing regulatory guidance, and demand was so high that the office had to turn 19 of the 24 applicants away; and Ireland’s Central Bank went from “inbound email” for feedback to an innovation hub in 2018 to two regulatory sandboxes in 2024, one for financial crime, the other for innovation in payment systems. To name just a few.
- Some numbers: There are now hundreds of sandboxes active around the world, more than 100 in fintech or financial services; 90 in AI, data protection and other areas of tech active in 39 countries; 42 healthcare sandboxes in 19 countries; and at least 2 dozen in health, energy and transportation. The sandbox mandate of Europe’s AI Act will certainly grow that number (here‘s Datasphere’s latest report).
- Highly customizable: Datasphere Executive Director Lorrayne Porciuncula said the depth of engagement among participants can vary, as can the speed. There’s a middle way between moving fast and trying to address all possible risks. It’s called responsible innovation, she said. I was struck by the adaptability of sandboxing, including how well it can be done online, in person or hybrid. It allows for asynchronicity but creates a container for efficient work. And the diversity of sandboxes goes well beyond the four types because of how the various actors – businesses, NGOs, academic institutions and different parts of governments – can be mixed and matched.
- The hardest but best part: In the age-old tension between the public and private sectors, “trust is the missing link.” Effective sandboxes are all about affording and growing that, which in turn enables learning. I’d add that even more fundamental, what affords both trust and learning, is humility. It was, to me, unusually pervasive throughout this program, which I believe is the key to its success.
- All parties have constraints: I’ve always been more exposed to businesses’ and users’ constraints, so it was extremely fortunate for me that there were a number of regulators among us. So I learned first-hand about the constraints they face, such as adding a new program on a limited budget, laws that prevent them from sharing test data across borders, strict “regulatory capture” rules for working with the commercial sector, etc.
- Help if needed: There’s a whole (global) community of sandboxes to tap into, with Datasphere, an international NGO, at its hub, mapping, convening and advising – “building a science and a community of sandboxes,” Porciuncula said.
Finally, I’m sure my bias is obvious, but it did not develop in Lisbon this summer, and no one asked me to write this. After nearly 30 years of following developments in digital safety for children and young people, I am convinced that adversarial approaches, especially those focused strictly on the digital parts of young lives, don’t advance their wellbeing in any meaningful way. Neither do policies and other “solutions” worked out solely by adults without young people’s input.
Since my deep dive into sandboxing started in early 2024 (very late compared to its start in the UK), I’ve had a growing conviction that the characteristics I touched on above are how we move the needle for all parties to solutions, including young people. DataSphere’s work has only confirmed that conviction. If we want to innovate, test, regulate and solve problems, we need to ask ourselves: Does the means foster trust?
Related links
- “From classrooms to communities: What it takes to build a sandbox,” by Datasphere’s Maira Carvalho
- Their latest report: “AI sandboxes and the Private Sector“
- COR Sandbox: for advancing online safety for youth, with youth
- A policy brief on AI sandboxes from the TUM Think Tank at Technical University of Munich
- Lessons from the first four years of sandboxing (mostly in fintech) from people at the World Bank

Leave a Reply