AI Regulatory Sandboxes and Cyber Commons
Panel discussion: The role of open source and cyber commons for preparing for regulatory compliance.
The EU AI Act introduces regulatory sandboxes (Articles 57–59) to help organisations develop, test and validate innovative AI under supervision before market entry. This panel asks how open source and the emerging cyber commons can make this bridge between innovation and compliance more accessible, especially for SMEs, startups, researchers and public bodies.
Bringing together regulators, standardisation and cybersecurity actors, and open-source practitioners, the discussion will explore how shared assets such as datasets, testing tools, reference implementations and conformity-assessment know-how can reduce compliance barriers, and how sandboxes and open commons can reinforce each other: sandboxes provide supervised spaces to experiment, while the commons provides reusable building blocks.
Key questions include: What can a cyber commons realistically offer organisations preparing for AI Act compliance? Where does open source strengthen trust, reproducibility and auditability and where are its limits? How can sandboxes, standards and open commons ensure that lessons learned become shared resources? And how should Europe’s strategic autonomy agenda shape what is built collectively versus procured?
Expected outcome: Attendees will leave with a concrete picture of how open-source tooling and a cyber commons can shorten the path to regulatory readiness, practical entry points for participating in or contributing to these resources, and an understanding of how sandboxes and the commons fit within the broader EU standardisation and compliance landscape.
