AI News · Good news ·
UK privacy regulator recommends legal basis for AI testing sandbox

The UK's Information Commissioner's Office published research findings on a proposed Statutory Regulatory Sandbox. It recommends primary legislation to enable time-limited exemptions from certain data protection requirements under ICO oversight, supporting tests of technologies including AI and automated decision-making.
Key points
- The ICO recommends primary legislation to establish a Statutory Regulatory Sandbox.
- The proposal would allow time-limited exemptions from certain data protection requirements under ICO oversight.
- Recommended safeguards include protections for children, transparency requirements and oversight of personal information.
- The sandbox remains a proposal, not an available exemption for AI deployment.
What happened: The UK's Information Commissioner's Office has published research findings recommending a legal framework for supervised testing of emerging technologies, including AI and automated decision-making. Osborne Clarke reported that the privacy regulator is exploring a Statutory Regulatory Sandbox, which would allow temporary exemptions from certain aspects of data protection law under ICO oversight. For businesses assessing AI projects involving personal information, the distinction is important: this is a proposal for a testing framework, not an exemption they can currently use.
The details: The ICO recommends establishing the power to create the sandbox through primary legislation. That legislation would define the regulator's role in operating and governing the scheme, identify where exemptions could be made, and establish criteria for selecting participants. Detailed operating requirements would then be set out in secondary legislation. The proposed arrangement would therefore involve both a legal basis for allowing exemptions and rules governing how testing would work, rather than a general relaxation of data protection requirements for AI development.
Who it affects: The proposed sandbox is aimed at innovators testing emerging technologies and applications, with AI and automated decision-making explicitly included. Its relevance extends to the people whose personal information could be involved in those tests. According to Osborne Clarke, the ICO says the government will need to consider protections for both participants and the public. These include shielding participants from possible civil claims arising from sandbox testing, alongside appropriate oversight and safeguards for individuals' personal information. Such protections remain matters for government consideration, not established rights for prospective participants.
Background: The regulator also recommends legislative protections for children and clear transparency requirements. These recommendations place public safeguards alongside the proposed flexibility for technology testing. The ICO hopes its findings will inform policy development as the government advances the forthcoming Regulating for Growth Bill and the AI Growth Lab. The sandbox research is therefore connected to those policy initiatives, but it does not itself establish the scheme or give businesses permission to depart from existing data protection obligations.
What to watch: For teams choosing or deploying AI, the next questions concern the legislation, the scope of any exemptions and the participant selection rules. A launch date, application process and specific testing limits were not reported. Until a legal framework is established, existing data protection requirements still need to guide deployment decisions. Businesses should distinguish the possibility of future supervised testing from permission to use the same technology outside that setting.
Our take
A supervised sandbox could help teams test sensitive use cases, but this remains a proposal rather than an available exemption. Existing data protection requirements still need to guide deployment decisions.