Jump to content

Sandboxing

From Justice Definitions

WHAT IS SANDBOXING

In AI and data governance, a sandbox is a controlled, supervised, and time-bound environment in which a technology, dataset, AI model, digital service, or regulatory approach can be tested, monitored, and reviewed prior to full-scale deployment. The core idea is simple: rather than allowing an untested AI system to run in a real environment, the system is first placed in a confined space where its behavior, risks, failure modes, and compliance posture can be systematically analyzed under controlled conditions.

In computer science context a sandbox is a type of environment that keeps a program or model separated from parts of a system. This environment gives the program limited access to things, like system resources, networks, databases and real-life systems. The sandbox sets a limit which is usually created using virtualization, containers or process isolation so that code can run safely without causing problems. If the software breaks acts in a way or gives wrong answers the damage stays inside the sandbox[1]. It does not hurt systems, user data or other services. In AI engineering keeping things separated is very important. It helps test how models react to inputs track how much they use resources check how good their answers are and find security problems. This all happens without risking data or stopping normal work.

In law and policy a sandbox also known as a "regulatory sandbox" it is a supervised area where a regulator allows limited short-term testing of a new technology, product, service or business model under adjusted or less strict rules[2]. This is done with rules to protect everyone involved proper monitoring and clear steps to end the experiment. The regulatory sandbox does not stop the law from being in place. Instead it creates an area where new ideas can be tested. The regulator watches, learns and then writes the rules for the future.

The idea started in the industry. The United Kingdoms Financial Conduct Authority (FCA) created the official regulatory sandbox in 2015. After that many regulators over the world started using the same idea. Some examples include the Reserve Bank of India (RBI) the Insurance Regulatory and Development Authority of India (IRDAI) and the Securities and Exchange Board of India (SEBI). [3]

The European Unions Artificial Intelligence Act 2024 has the advanced rules for AI regulatory sandboxes. The Act includes sections 57 to 63 that say EU Member States must create AI sandboxes. These sandboxes are places where new AI systems can be developed, tested and checked. They are watched over by the government groups. There are rules like time limits, regular checks and protection for basic human rights. [4] Section 57(1) says that being in a sandbox does not mean a company is free from following the law. Instead the sandbox helps companies show they are doing the thing and gather proof, for the regulators. [5]

In the field of intelligence governance the technical and regulatory sides are closely connected. A good artificial intelligence sandbox needs to have important features. It must be technically isolated so it does not cause any problems for the systems that are being used and the live data. It needs to be supervised to make sure that the experiments are being done within the limits of the law. It has to be time-bound so that the experiments do not go on forever without anyone being held accountable.[6] It should be actively monitored so that we can get evidence of how the system is behaving. It needs to be designed so that we can get useful information, about whether the system is safe and reliable.

Sandboxes are very important for AI systems because a lot of them can't be completely checked by looking at the code or using static analysis. The risks happen in time because of how training data, where the system is used how people interact with it different languages, how organizations work and unusual situations that are hard to predict. [7]The images below show the kinds of problems that sandbox testing is meant to find.

A sandbox should not be confused with a way to avoid following the law. It is not a place where privacy rules, fairness, fair treatment or people's rights can be ignored just because someone wants to be innovative. [8]The idea of a sandbox is to make sure that rules are followed in a real and based-on-facts way by letting tests happen in a controlled environment with supervision. It's not about making excuses for rights-breaking research without being responsible. Sandboxing should be seen as a way to make sure that rules are followed properly in areas that care a lot about rights, like courts, health care helping people, financial services, schools, and police work. It's not a way to avoid following the rules. [9]

OFFICIAL DEFINITION OF SANDBOXING

Statutory Definitions

A regulatory sandbox is a time-limited, controlled setting where a novel product, service, or business plan can be evaluated with a small user base and under predetermined regulatory relaxations while still being subject to ongoing regulatory oversight and stated protections. [10]The goal of a sandbox is to allow controlled experimentation under supervision rather than to exclude players from the law. This allows regulators to monitor real-world consequences, collect data, and create suitable regulations prior to the innovation's full-scale distribution.

In the context of artificial intelligence, a sandbox combines this regulatory role with technical isolation: the AI system being tested is contained within a limited computational environment that keeps it from accessing real-time production data, interfering with operational infrastructure, or endangering end users while it is being tested. Definitions found in law, definitions or descriptions found in regulations and regulatory circulars, descriptions found in government reports and policy documents, and definitions put forth in scholarly literature should all be distinguished at the outset. It is not appropriate to describe each of these sources as a legally binding legislative definition because they do not share the same legal authority. [11]

The Telecommunications Act 2023

There is a sector-specific statutory definition of "regulatory sandbox" in Indian law. The central government may create a regulatory sandbox for the telecom industry under Section 27 of the Telecommunications Act of 2023. [12]The clause permits the establishment of a framework that permits the testing of new telecommunications technologies, goods, services, or business models under modified regulatory conditions for a brief time, subject to any terms, conditions, and safeguards that the Central Government may specify. [13]As of July 2026, this is the sole explicit statutory use of the word "regulatory sandbox" in Indian primary legislation. However, its use is restricted to the telecommunications industry; it does not include data security, the legal system, or AI systems in general.

The Digital Personal Data Protection Act 2023

Neither "AI sandbox" nor "data protection sandbox" are. Provided for under the Digital Personal Data Protection Act of 2023. [14]There is no part in the Act that's similar to the regulatory sandbox clause that was in the previous Personal Data Protection Bill 2019. The DPDP Acts Section 40 gives the Central Government the power to create rules to put the Acts rules into effect. [15]

Other parts of the Act create the data protection rules: Section 5s notice; Section 6s consent and lawful reasons for processing; Section 8s duties of data fiduciaries including proper security steps and reporting breaches; Section 9s duties about childrens data and the hiring of Data Protection Officers; Section 10s Significant Data Fiduciary system; and Sections 11, through 14s rights of data principals including ways to handle complaints. [16] No sandbox setup is created, allowed or talked about in any of these parts.

Legal Provisions Conceptually Relating to Sandboxing

Although an AI sandbox is not specifically required or defined by any Indian statute, a number of current legal provisions establish the parameters that sandboxing may work inside or to which sandbox players would remain subject:

Provision Relevance to Sandboxing Status as of July 2026
DPDP Act 2023, s 5 (notice) Sandbox participants processing personal data would remain subject to notice obligations. In force
DPDP Act 2023, s 6 (consent) Sandbox participants would require a lawful basis for processing, including consent where applicable. In force
DPDP Act 2023, s 8(5)–(6) (security safeguards; breach notification) Sandbox environments must implement reasonable security safeguards; breaches within a sandbox would trigger notification obligations upon commencement. In force
DPDP Act 2023, s 10 (Significant Data Fiduciaries) Where sandbox testing involves large-scale or sensitive data processing, SDF obligations may apply upon commencement and notification. In force
IT Act 2000, s 43A and SPDI Rules 2011 Currently operative data-protection obligations; sandbox participants handling sensitive personal data remain subject to reasonable security practice requirements. In force.
Telecommunications Act 2023, s 27 Sector-specific statutory authority for regulatory sandboxes in telecommunications. In force.
IT (Intermediary Guidelines) Rules 2021 Intermediary due-diligence obligations apply to platforms testing AI features, including within sandbox environments. In force.

Official Documents, Government Reports, and Regulatory Frameworks

IndiaAI Governance Guidelines

The Ministry of Electronics and Information Technologys IndiaAI Governance Guidelines provide a way to discuss AI sandboxing in India. [17]Setting up testing areas in high-risk areas is seen as something that should be done in the few years with the goal of creating a safe place to try new ideas. [18] The Guidelines do not create any laws or have legal power; instead they are a document that gives advice but is not required. Of telling people what to do they show where the government wants to go.

AIKosh: Operational AI Sandbox Infrastructure

The IndiaAI Mission's platform for datasets, models, use cases, and AI artifacts, AIKosh, offers a technical realization of the sandbox concept. AIKosh provides safe API access and an AI Sandbox environment for model testing and training, according to its own literature. [19] AIKosh serves as an operational technical sandbox for testing and developing AI models. AIKosh offers computational infrastructure for experimentation, but it does not grant regulatory permissions, alter legal obligations, or provide supervised regulatory relaxation. This sets it apart from a regulator-led legal sandbox of the type created under the EU AI Act or the Telecommunications Act 2023.

Sectoral Regulatory Sandbox Frameworks

Indian financial and insurance regulators have established various sector-specific regulatory sandbox frameworks through its regulatory circulars and mechanisms:

Regulator Instrument Scope
Reserve Bank of India Framework for Regulatory Sandbox (RBI/2019-20/88, 16 August 2019) Fintech products and services in the financial sector. [20]
IRDAI IRDAI (Regulatory Sandbox) Regulations 2019 Insurance products and services.
SEBI Framework for Regulatory Sandbox (SEBI/HO/MRD2/CIR/P/2020/168, 2 September 2020) Securities market innovations.

International Instruments

European Union Artificial Intelligence Act 2024, Articles 57–63

The European Union has a good system for controlling artificial intelligence. The EU Artificial Intelligence Act 2024 is the law for artificial intelligence regulatory sandboxes in any country. The European Union member states have to set up at least one artificial intelligence regulatory sandbox in their country according to the EU Artificial Intelligence Act 2024[21]. This artificial intelligence regulatory sandbox is like a place where people can try out new artificial intelligence systems for a little while before they are available to everyone.

Participation in a sandbox shall not affect the supervisory and corrective powers of the competent authorities and shall not exempt providers from compliance with applicable Union or national law, as provided for in Article 58(1). [22]This statutory model, which combines technical containment, regulatory supervision, time limits and an explicit preservation of legal obligations, is the most comprehensive legislative treatment of AI sandboxing currently in force globally.

OECD AI Principles & United Kingdom Financial Conduct Authority

The OECD Recommendation on Artificial Intelligence does not define "sandbox," but it does support the idea by encouraging regulatory methods that promote innovation while controlling risk and by upholding the principles of robustness, security, and safety throughout the AI lifecycle. [23]India is one of the member and partner nations whose regulatory sandbox projects are monitored by the OECD's AI Policy Observatory.

The contemporary regulatory sandbox model originated with the UK FCA's regulatory sandbox, which was introduced in 2015 and has since been adopted or modified by regulators in more than 70 jurisdictions worldwide. [24]The EU AI Act and other AI-specific sandbox regulations have been influenced by the FCA model, even though it was first created for fintech.

TYPES OF SANDBOXING

Sandboxing may be classified by regulatory domain, technical design, level of real-world exposure, data sensitivity, institutional authority and deployment sector.

Data-Protection Sandbox

The data-protection sandbox allows for supervised testing of technologies that process personal data, anonymized data, synthetic data, consent-management systems, privacy-enhancing technologies, data-sharing agreements, or AI models trained on sensitive datasets. As of July 2026, there was no statutory provision under Indian law that created a data protection sandbox. The Personal Data Protection Bill 2019, which proposed a regulatory sandbox in Clause 40, was not passed in that form, and the Digital Personal Data Protection Act 2023 does not have an express sandbox regime.

The IndiaAI Governance Guidelines have piloted regulatory sandboxes in high-risk domains as a medium-term policy goal, but it remains a non-binding policy direction rather than a functional legal framework[25]. Any future data-protection sandbox in India would come under the institutional domain of the Ministry of Electronics and Information Technology (MeitY), the nodal ministry for data-protection policy, and the Data Protection Board of India (DPBI), constituted under Section 18 of the DPDP Act 2023[26]. The data-protection sandbox should be viewed as a policy possibility under consideration, not a settled legal institution, until expressly established by statute, regulation or published rule[27].

Financial Sector Sandbox

The financial sector sandbox is brought up in a controlled environment for testing of fintech products, credit-scoring models, fraud-detection systems, insurance underwriting algorithms, robo-advisory tools, algorithmic trading systems, regulatory technology (RegTech), and supervisory technology (SupTech). The major four Indian financial regulators, which have each established their regulatory sandbox frameworks under their respective statutory powers:

Regulator Instrument Date Statutory Basis
Reserve Bank of India (RBI) Framework for Regulatory Sandbox (RBI/2019-20/88) 16 August 2019 Reserve Bank of India Act 1934; Banking Regulation Act 1949 [28]
Securities and Exchange Board of India (SEBI) Framework for Regulatory Sandbox (SEBI/HO/MRD2/CIR/P/2020/168) 2 September 2020 Securities and Exchange Board of India Act 1992, s 30 [29]
Insurance Regulatory and Development Authority of India (IRDAI) IRDAI (Regulatory Sandbox) Regulations 2019 2019 Insurance Regulatory and Development Authority Act 1999, s 14(2) [30]
International Financial Services Centres Authority (IFSCA) IFSCA (Regulatory Sandbox) Framework 2021 2021 International Financial Services Centres Authority Act 2019, s 12[31]

These frameworks work and how long they have been around these four frameworks are the most advanced type of regulatory sandboxing in India. The RBI framework is an example. It started in 2019. Has had many groups of companies apply to test certain products under certain rules. The SEBI framework lets people try out ideas for the securities market in a safe environment where SEBI can keep an eye on things[32]. The IRDAI [33]Regulations say it is okay to test insurance products and procedures in a sandbox.[34] The IFSCA Framework gives sandbox facilities to companies that work in International Financial Services Centers. The regulators can look at products that use Artificial Intelligence, such as credit scoring that uses algorithms, fraud detection that uses Artificial Intelligence or insurance underwriting that is automated as long as they fall under the rules of the regulator[35]. Regulatory sandboxing, in India includes these four frameworks.

Judicial AI Sandbox

Before they are used in real court work court-facing AI tools are tried out in a place called a judicial AI sandbox. This is where people test tools like the ones that help with research translate things transcribe what people say check court papers, sort cases, manage lists of things that need to be done and summarize what happens in court. These are all tools that courts use.[36] The Supreme Court and the National Informatics Centre in India are making tools like LegRAA for legal research SUPACE to help courts work better Digital Courts 2.1, for virtual hearings ASR-SHRUTI to transcribe what people say in court and PANINI to help with translation. These are all court-facing AI tools. The Supreme Court e-Committee and the National Informatics Centre are working on these court-facing AI tools.

The judicial AI sandbox needs to do more than just be technically correct. It also has to make sure it follows the constitution. This means it has to respect natural justice principles[37]. It has to give people the right to a trial under Article 21.[38] It has to make sure everyone is equal before the law under Article 14. It also has to follow the rules for evidence that are outlined in the Bharatiya Sakshya Adhiniyam 2023. As of July 2026 there is no law and no order, from the Supreme Court that has officially created an AI sandbox. However the Supreme Court e-Committees AI White Paper says that judicial AI tools need to be tested before they are used.

Health AI Sandbox

Clinical decision-support systems, diagnostic AI, radiology AI, pathology AI, triage systems, hospital workflow tools, and disease-prediction models can all be tested in a controlled setting called a health AI sandbox. A health AI sandbox would require medical validation, informed consent procedures, data minimization, clinical oversight, and a clear division of liability between developers, deploying institutions, and treating clinicians because health data is sensitive and clinical errors could result in immediate and irreversible harm to patients. [39]

The Indian Council of Medical Research (ICMR), which oversees biomedical research ethics, the Central Drugs Standard Control Organization (CDSCO), which regulates medical devices under the Medical Devices Rules 2017, and the National Health Authority (NHA), which manages the Ayushman Bharat Digital Mission (ABDM) health-data ecosystem, are the regulatory bodies in India that are pertinent to a health AI sandbox. [40]As of July 2026, none of these organizations has set up a specialized AI-specific health sandbox; nonetheless, the security-and-privacy-by-design approach of the ABDM Health Data Management Policy offers a conceptual basis for such a system. [41]

Public Sector AI Sandbox

A controlled pilot environment for testing AI systems used in welfare eligibility determination, grievance redressal, agricultural advice services, educational evaluation, policing, smart-city governance, tax administration, and public service delivery is known as a public sector AI sandbox. Because public-sector AI systems directly impact people' access to entitlements, benefits, and services, this domain has increased constitutional sensitivity. In addition to technical accuracy, a public sector AI sandbox must evaluate exclusion errors, appeal mechanisms' accessibility and availability, local language access in all 22 scheduled languages, and nondiscrimination based on caste, tribe, religion, gender, disability, and geography.

Articles 14 (equality), 15 (non-discrimination), 21 (life and personal liberty), and 38 (directive principle of social welfare) comprise the constitutional framework that governs this area.[42] As of July 2026, there is no official public-sector AI sandbox in India; however, state-level policy foundations for pre-deployment[43] testing of public-sector AI systems are provided by the Tamil Nadu Safe and Ethical AI Policy (2020) and the Telangana AI Roadmap (September 2024). [44]

Synthetic-Content Sandbox

A controlled setting for testing AI-generated text, audio, video, and images; political content moderation systems; content-provenance tools; watermarking systems; and deepfake detection techniques is known as a synthetic-content sandbox. Since the Information Technology (Intermediary Guidelines and Digital Media Ethics Code) Rules were amended in 2026, this domain has become especially important.

These amendments require platforms and intermediaries to identify, label, and mark the provenance of information that is synthetically generated.[45] The ability of detection and labeling algorithms to endure adversary manipulation—such as screenshot capture, compression, reposting, cropping, translation, and cross-platform sharing—while maintaining the integrity of provenance markers would need to be tested in a synthetic-content sandbox. [46] The Ministry of Information and Broadcasting, where synthetic content interacts with media regulation, the Election Commission of India, where it interacts with electoral integrity, and MeitY, which oversees the IT Rules, are the pertinent regulatory bodies.[47]

India-Specific Classification Table

Sandbox Type Regulatory / Institutional Anchor Indian Application Context What Should Be Tested Inside the Sandbox Key Risks / Failure Modes Minimum Safeguards Before Exit
AIKosh / AIKosha Data and Model Sandbox IndiaAI Mission / MeitY India-specific datasets, AI models, use cases, API-based data access and model experimentation Dataset quality, metadata completeness, model performance, language coverage, benchmark reliability, API access controls, documentation quality[48] Poor-quality datasets; underrepresentation of regional languages; re-identification risk; weak documentation; model trained on non-representative data Dataset sheets; anonymisation review; access logs; usage restrictions; metadata standards; bias and language-coverage testing
Future DPDP / Data-Protection Sandbox DPBI / MeitY, if formally created later Consent systems, privacy-enhancing technologies, synthetic data, de-identification tools, AI trained on sensitive or personal data Whether consent, notice, purpose limitation, deletion, security safeguards and breach-notification processes actually work in practice Treating sandbox as privacy waiver; personal-data leakage; re-identification; children’s data exposure; weak grievance redressal DPDP compliance plan; privacy impact assessment; synthetic/de-identified data; breach protocol; independent audit; no suspension of core safety duties
Financial AI Sandbox RBI, SEBI, IRDAI, IFSCA, IoRS AI credit scoring, fraud detection, KYC automation, insurance underwriting, robo-advice, algorithmic trading, RegTech and SupTech Model drift, fairness, explainability, consumer consent, fraud evasion, cyber risk, stress behaviour in volatile markets Discriminatory lending; denial to thin-file borrowers; flash-crash risk; correlated model failure; hidden proxy discrimination Human override; audit trails; consumer notice; bias testing; stress testing; regulator access; incident reporting; limited cohort rollout
SEBI Innovation / Regulatory Sandbox SEBI Securities-market data testing, investor onboarding, market surveillance, algorithmic trading, portfolio tools Whether market-data access, trading algorithms, surveillance tools and investor-facing AI can operate without market abuse or investor harm Market manipulation; unfair access to data; investor profiling; automated trading errors; systemic risk Exchange/broker controls; kill switches; market-abuse testing; audit logs; limited testing period; clear exit conditions
Judicial AI Sandbox Supreme Court e-Committee, NIC, Department of Justice, High Courts LegRAA, SUPACE, Digital Courts 2.1, ASR-SHRUTI, PANINI, e-filing defect tools, case summarisation and translation Citation accuracy, hallucination, translation accuracy, transcription quality, e-filing defect detection, summarisation completeness, court-staff usability Fake citations; mistranslation; omission of material facts; confidentiality breach; unequal performance across languages; overreliance by users Human verification; no autonomous decision-making; legal hallucination tests; language-wise performance reports; court data anonymisation; audit logs
NJDG-Linked Judicial Data Sandbox Supreme Court e-Committee / NIC Controlled access to anonymised or synthetic judicial metadata for research and AI testing Data quality, OCR errors, missing fields, cause-code consistency, bias in case categories, privacy risk from party information Re-identification of litigants; biased models trained on incomplete records; misuse for prediction of case outcomes; privacy concerns Synthetic datasets; strict access rules; research ethics review; no raw party identifiers; court approval; public learning report
Health AI Sandbox Ministry of Health, ICMR, CDSCO, hospitals Diagnostic AI, radiology, pathology, triage, disease prediction, clinical decision support, hospital workflow tools Clinical accuracy, false negatives, false positives, bias across gender/caste/rural groups, informed consent, health-data security Misdiagnosis; unsafe triage; health-data leakage; poor performance on underrepresented populations; unclear liability Clinical validation; ethics committee approval; doctor-in-loop; health-data safeguards; adverse-event reporting; post-sandbox monitoring
Public-Welfare AI Sandbox MeitY, line ministries, state governments DBT eligibility, ration/PDS systems, Aadhaar-linked services, grievance redressal, education, agriculture and public employment tools Exclusion errors, language barriers, appeal mechanisms, accessibility, false positives, false negatives, local administrative usability Denial of benefits; inability to appeal; exclusion of rural or marginalised users; surveillance creep; automated arbitrariness Human review; appeal channel; local-language testing; accessibility audit; grievance redressal; rights-impact assessment
Policing / Public-Safety AI Sandbox State police, MHA, NCRB, state governments, courts where relevant Crime analytics, facial recognition, predictive policing, suspect matching, public-order tools False positives, demographic error rates, evidentiary reliability, surveillance necessity, proportionality and auditability Religious/caste profiling; wrongful suspicion; mass surveillance; poor accuracy on certain groups; chilling effect on liberty Court/legal oversight; strict purpose limitation; bias testing; audit logs; deletion periods; independent review
Education AI Sandbox Ministry of Education, state education departments, universities AI proctoring, admissions screening, personalised learning, student-risk prediction, academic integrity tools Bias in evaluation, false cheating flags, language access, disability access, student privacy, explainability Wrong accusations; exclusion of disabled students; privacy invasion; unequal access to AI tools; opaque scoring Human appeal; disability accommodations; student notice; data minimisation; bias audit; limited pilot
Synthetic-Content / Deepfake Sandbox MeitY, platforms, Election Commission context, CERT-In for cyber incidents Deepfake detection, watermarking, provenance metadata, synthetic political content, voice cloning and image generation Whether labels survive screenshots, compression, reposting, cropping, translation, meme formats and cross-platform sharing Electoral misinformation; impersonation; communal incitement; label removal; detection bypass; false positives against genuine content Metadata/watermark stress tests; complaint channel; provenance logs; content-review escalation; election-period safeguards
IndiaAI Compute Sandbox IndiaAI Mission / MeitY Startups, researchers and public-interest developers testing models on compute infrastructure Access control, permitted use, logging, model-safety checks, misuse prevention, secure storage and IP protection Misuse of compute; weak audit trails; model theft; unsafe model training; unclear accountability User vetting; usage logs; model-risk declaration; safety checks; project-level access controls
Tribal / Rural Governance Sandbox State governments, Ministry of Tribal Affairs, rural development bodies AI for land records, welfare access, forest rights, health outreach, agriculture and local-language governance Whether AI works in low-connectivity, low-literacy, local-language and community-specific contexts Exclusion of Adivasi users; poor local-language support; land/welfare denial; cultural misclassification Community consultation; offline fallback; local-language testing; legal aid linkages; grievance mechanisms
Regulatory-Learning Sandbox MeitY, AISI, DPBI, sector regulators Cross-sector learning from AI pilots, failures, incidents and red-team findings Whether sandbox evidence improves future rules, benchmarks, procurement standards and risk taxonomies Private learning without public accountability; regulatory capture; repetition of failures across sectors Public sandbox registry; anonymised learning reports; conflict-of-interest rules; parliamentary/sectoral oversight

APPEARANCE IN OFFICIAL DATABASES

India does not yet have a single official AI sandbox registry. The institutional architecture is scattered across AIKosh, IndiaAI Compute, the IndiaAI Governance Guidelines, financial-sector sandboxes, SEBI’s frameworks, RBI’s interoperable sandbox model, eCourts pilots and future AI incident systems. This is not necessarily a weakness, but it means the document should avoid saying that India already has a complete AI sandbox regime.

Institutional Architecture

Institution Present Role How It Relates to Sandboxing Caution in Wording
MeitY / IndiaAI Mission National AI governance and mission architecture Identifies regulatory sandboxes in high-risk domains as a medium-term action item; supports AIKosh, compute access and responsible AI infrastructure Say “policy action item,” not “statutory mandate”
AIKosh / AIKosha Dataset, model and use-case platform Provides datasets, models, tools and sandbox capabilities for AI training and experimentation Treat it as operational infrastructure, not a regulator-led legal sandbox
AI Safety Institute (AISI) AI safety testing and standards institution under the IndiaAI vision Should develop testing protocols, benchmarks, safety metrics and evaluation methods for future sandboxes Avoid claiming it already runs a complete sandbox registry unless verified
DPBI Data-protection adjudicatory body under DPDP Act Relevant if sandbox experiments involve personal data, breaches or Significant Data Fiduciary obligations Do not claim an existing DPBI sandbox
RBI / IoRS Financial-sector sandboxing and inter-regulator coordination Defines sandboxing as live testing in a controlled/test regulatory environment; supports hybrid products across regulators Useful as Indian precedent for sandbox design
SEBI Securities-market innovation and regulatory sandbox frameworks Provides controlled testing models for market innovation, trading systems and investor-facing tools Strong precedent, but sector-specific
Supreme Court e-Committee / NIC eCourts, judicial AI tools and court technology infrastructure Natural institutional base for judicial AI sandboxes involving LegRAA, SUPACE, translation, transcription and filing tools Use “pilot” or “future sandbox,” not full judicial sandbox unless formally created
CERT-In Cybersecurity incident response Relevant where sandbox testing reveals cyber vulnerabilities or AI-enabled security incidents Not an AI sandbox authority by itself
Sector regulators Health, insurance, telecom, education and other sectors Needed for domain-specific sandbox governance Each sector needs different testing criteria

Sandboxing in Key Repositories

AIKosh / AIKosha: AIKosh is the most visible Indian AI sandbox infrastructure. It provides a repository of datasets, models, and use cases, while official documentation describes secure API access and an AI Sandbox environment for model training and experimentation. [49] For this reason, AIKosh should be considered the primary operational platform for future sandbox-ready datasets, model testing, and controlled experimentation.

IndiaAI Governance Guidelines: The Guidelines establish a broad policy framework for AI sandboxing. The authors advocate for pilot regulatory sandboxes in high-risk domains, incorporating incident reporting, safe experimentation, standards, and feedback loops[50].

The Guidelines recommend establishing a national AI incidents database. This database should include sandbox failures, controlled-pilot incidents, and red-team findings, allowing regulators to learn from failures before full deployment.

NJDG and eCourts: NJDG should not be referred to as a "sandbox." It is a judicial data repository. However, eCourts Phase III, SUPACE, LegRAA, Digital Courts 2.1, and other judicial AI tools create a strong case for a future judicial data sandbox using anonymized or synthetic judicial data [51].

SEBI's Innovation Sandbox and Regulatory Sandbox work is an example of a system with rules and limits. SEBI's Innovation Sandbox was started in 2019. It lets companies try out technology for the securities market in a safe space with a small group of users and a deadline[52]. The regulatory sandbox was introduced in September 2020. It takes the idea and applies it to products, services, and business ideas that need temporary changes to SEBI rules[53]. In the securities market, SEBI's Innovation Sandbox and Regulatory Sandbox show how a system with rules and limits can work. This includes who can participate, what the limits are, how things are supervised, how to protect users, and how to end the test in a way.

For hybrid financial products that span several regulatory jurisdictions, the RBI's Framework for Inter-operable Regulatory Sandbox (IoRS), published in 2023, offers an illustration of cross-regulatory coordination. [54] The IoRS reduces the regulatory fragmentation that would otherwise necessitate separate applications to each regulator by enabling entities to test goods or services that fall under the concurrent regulatory scope of two or more financial regulators, for instance, a product combining banking, insurance, and securities features within a single coordinated sandbox environment. [55]The scope of the IoRS is restricted to financial products and services that are under the purview of the participating regulators; it does not provide a general-purpose AI sandbox.

RESEARCH ENGAGING WITH SANDBOXING

Regulatory Sandbox Theory

The basic sandbox literature sees the regulatory sandbox as a supervised testing space with two aims. One is to facilitate innovation under controlled conditions and the other is to generate regulatory learning to protect consumers. [56]The United Kingdom’s Financial Conduct Authority (FCA) launched the first formal regulatory sandbox in the world in 2015, and has published a series of cohort evaluation reports that have documented outcomes for participants, adaptations to regulation, and consumer-protection measures. [57]The FCA’s review of the first cohort (2016) found that the sandbox model allowed firms to test products with real consumers under relaxed regulatory conditions, while the FCA kept supervisory oversight and the ability to intervene. [58]In 2019 the UK Information Commissioner’s Office (ICO) introduced a data-protection regulatory sandbox, specifically focusing on how organisations can comply with the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018, while developing innovative data-processing technologies. [59]

EU AI Act and AI Regulatory Sandboxes

The ICO sandbox model is relevant for the Indian context, as it shows how a data-protection regulator can offer structured guidance on privacy-by-design, data minimisation and lawful processing in a sandbox environment, rather than treating the sandbox as a relaxation of data-protection obligations. [60]The ICO’s reports on specific projects on data sharing, anonymisation and AI-driven processing (see, in particular, the sandbox reports) provide empirical evidence of how participation in sandboxes interacted with data-protection compliance. AI Regulatory Sandboxes and the EU AI Act Under Articles 57 to 63 of the EU Artificial Intelligence Act 2024, the establishment of AI regulatory sandboxes has become a statutory obligation for EU Member States. [61]Post-implementation research has identified three key implementation challenges: regulatory capacity (whether national authorities have the technical expertise, staffing and tools to effectively supervise AI sandboxes); inter-authority coordination (how sandboxes operate where multiple regulators share jurisdiction over a single AI system); and provider uptake (whether the conditions, costs and time limits of sandbox participation are sufficiently attractive to incentivise voluntary enrolment by AI developers). [62]These challenges have a direct bearing on India. A sandbox set up by a policy document or a statutory provision will not work unless the supervising authority has adequate technical personnel, data-access protocols, evaluation methodologies and institutional capacity to assess complex AI systems. [63]The European Commission’s ongoing work on harmonised implementation guidelines for AI sandboxes, including the development of common templates and best-practice documentation, can serve as a comparative reference for any future Indian sandbox design. [64]

Indian Data-Protection Sandbox Debate

India's data-protection sandbox debate originated with Clause 40 of the Personal Data Protection Bill 2019, which proposed that the Data Protection Authority may create a sandbox to encourage innovation in artificial intelligence, machine learning, and other emerging technologies. [16] Civil-society organisations, including the Internet Freedom Foundation (IFF) and the Centre for Internet and Society (CIS), raised concerns during the parliamentary consultation process that a sandbox provision in a nascent data-protection regime could create a mechanism through which privacy safeguards might be weakened if the conditions, oversight mechanisms, and limitations of sandbox participation were not clearly defined and enforced. [65]This concern was not directed at the concept of sandboxing per se, but at the risk that insufficiently regulated sandbox arrangements could function as de facto exemptions from data-protection obligations. [66]The debate remains relevant because any future Indian AI sandbox must address the structural conditions—clear eligibility criteria, defined time limits, mandatory reporting, preservation of fundamental rights, and enforceable exit conditions—necessary to prevent sandbox participation from undermining the data-protection framework it is intended to complement.

Financial and Sectoral Sandboxes in India

The financial sector constitutes the most operationally established category of regulatory sandboxing in India. The RBI, SEBI, IRDAI, and IFSCA have each created sandbox frameworks under their respective statutory powers, as detailed in the preceding section. [19] Research on these frameworks has focused on their structural design—eligibility criteria, testing boundaries, consumer-protection requirements, risk-management protocols, and exit conditions—rather than on comprehensive outcome evaluation. The RBI's published cohort reports document the categories of products tested, the number of entities admitted, and the regulatory observations arising from sandbox participation. [67]Academic commentary has noted that the Indian financial sandbox model provides a structural template—demonstrating how bounded testing, supervisory oversight, and consumer safeguards can be operationalised within a regulated market—that may inform the design of sandboxes in other sectors, including AI, health, and public services. [68]However, the transferability of the financial sandbox model to AI governance has not been empirically tested, and the technical complexity of AI systems presents challenges—such as model opacity, training-data sensitivity, and emergent behaviour—that are not fully addressed by the financial sandbox architecture.

Judicial and Public-Sector AI Sandboxing

Research on judicial AI sandboxing in India remains limited. The Supreme Court e-Committee's AI White Paper (2025) addresses the need for rigorous pre-deployment testing of judicial AI tools but does not expressly prescribe a sandbox methodology. [69]Academic and policy commentary on judicial AI, including work by DAKSH and the Vidhi Centre for Legal Policy, has recommended that AI tools intended for judicial deployment undergo controlled pilot testing with anonymised data, synthetic datasets, human oversight, audit logs, and documented error analysis before being considered for live court operations. [70]These recommendations are consistent with the sandbox model but have not been formally adopted as policy by the e-Committee or the Department of Justice as of July 2026.

The recommendation that India should commence judicial AI sandboxing with lower-risk administrative functions—such as translation, transcription, e-filing scrutiny, and case summarisation—before considering more sensitive adjudicatory workflows is a policy proposal advanced by civil-society researchers and academic commentators. [25] It is not an established finding of empirical research, nor has it been adopted as official policy. This proposal is more appropriately situated within the "Way Ahead" section of this article as a recommendation for future action, rather than within the research summary.

DATA CHALLENGES

Gap Description Relevant Source
Dataset quality in Indian contexts OCR errors in regional scripts, inconsistent metadata across courts, and incomplete case records create foundational data-quality challenges that affect any AI system trained on Indian judicial or administrative data. DAKSH, 'State of the Indian Judiciary: A Data-Driven Analysis' (2024); AI4Bharat, 'IndicTrans2' (2023) (documenting data scarcity for low-resource languages). [71]
Re-identification risks Neural, health, and biometric data are difficult to anonymise completely; re-identification risk increases in small communities, rare-disorder populations, and forensic contexts. Szoszkiewicz, 'Mental Privacy: Navigating Risks, Rights and Regulation' (2025) 2 Nature Communications Medicine 1; Sweeney, 'Simple Demographics Often Identify People Uniquely' (2000) Carnegie Mellon University Data Privacy Working Paper 3. [72]
Demographic under-representation AI models trained predominantly on urban, English-language, upper-caste, or male-dominated datasets may perform poorly for rural, tribal, low-income, disabled, or linguistically diverse populations. AI4Bharat (n 26); UNESCO, 'Recommendation on the Ethics of AI' (2021) paras 37–40. [73]
Vendor opacity Proprietary AI vendors frequently do not disclose training-data composition, error rates, validation methodologies, or uncertainty measures, preventing meaningful independent evaluation. European Parliament, 'The Protection of Mental Privacy in the Area of Neuroscience' (Study PE 757.807, 2024) 22–24; NIST AI RMF 1.0 (2023) 15–17 (transparency and explainability requirements). [74]
Regulatory capacity Indian regulators and judicial institutions currently lack the dedicated technical personnel, evaluation infrastructure, and data-access protocols necessary to supervise complex AI sandbox exercises. OECD, 'AI Policy Observatory: Regulatory Capacity and AI Governance' (2024); EU AI Act implementation reports (n 13). [75]

WAY AHEAD

Correct Legal Framing

The document should not say that the DPDP Act 2023 already creates a statutory data-protection sandbox. The correct position is: clause 40 of the 2019 PDP Bill proposed one; the final DPDP Act omitted it; IndiaAI Guidelines now revive sandboxing as a policy action for high-risk AI domains.

Indian AI Sandbox Standard

MeitY, AISI, DPBI, RBI, SEBI, ICMR, and the Supreme Court e-Committee should develop a common Indian AI Sandbox Standard. It should define eligibility, duration, data access, privacy safeguards, human oversight, red teaming, incident reporting, public reporting and exit criteria.

Public Sandbox Registry

India should maintain a public sandbox registry. It should disclose the participant, sector, testing purpose, regulator, duration, broad risk category, safeguards and learning outcomes. Sensitive technical details may remain confidential, but the existence and purpose of the sandbox should be public.

Judicial AI Sandbox

India should create a judicial AI sandbox using synthetic or anonymized judicial data. It should test hallucinated citations, translation accuracy, transcription reliability, e-filing defect detection, summarization quality, privacy leakage and unequal performance across Indian languages.

AIKosh as Sandbox Infrastructure

AIKosh should host sandbox-ready datasets, benchmark suites, privacy-preserving synthetic datasets, Indian-language test sets, legal hallucination datasets, bias probes and sector-specific evaluation tools.

Incident-Learning Loop

Sandbox findings should feed into the future National AI Incidents Database. The goal should be regulatory learning, not only punishment. If one sandbox reveals a recurring failure, that lesson should improve benchmarks and safeguards across other sectors.

Constitutional Safeguards

Sandboxing is not an exemption from constitutional law. Any sandbox involving courts, welfare, policing, health, finance, or education must be assessed against Article 14 equality, Article 21[76] privacy, dignity and due process, and the broader principle of non-arbitrariness. A sandbox should be a supervised route to rights-compatible innovation, not a shortcut around rights.

  1. The technical definition of sandboxing as process isolation is standard in computer science literature. See, eg, John Viega and Gary McGraw, Building Secure Software (Addison-Wesley 2002) ch 12.https://archive.org/details/buildingsecureso0000john
  2. Financial Conduct Authority (UK), 'Regulatory Sandbox' (FCA, 2015) https://www.fca.org.uk/firms/innovation/regulatory-sandbox accessed 30 July 2026.
  3. Reserve Bank of India, 'Framework for Regulatory Sandbox' (RBI/2019-20/88, 16 August 2019) https://www.rbi.org.in/Scripts/NotificationUser.aspx?Id=11615 accessed 30 July 2026; Insurance Regulatory and Development Authority of India, 'IRDAI (Regulatory Sandbox) Regulations, 2019'; Securities and Exchange Board of India, 'Framework for Regulatory Sandbox' (SEBI/HO/MRD2/CIR/P/2020/168, 2 September 2020).
  4. Regulation (EU) 2024/1689 of the European Parliament and of the Council of 13 June 2024 laying down harmonised rules on artificial intelligence (Artificial Intelligence Act), OJ L 2024/1689, arts 57–63. https://eur-lex.europa.eu/eli/reg/2024/1689/oj/eng
  5. ibid art 57(1): "Member States shall ensure that their competent authorities establish at least one AI regulatory sandbox at national level… The sandbox shall provide a controlled environment that facilitates the development, testing and validation of innovative AI systems for a limited time before their placing on the market or putting into service pursuant to a specific plan."
  6. This formulation draws on the EU AI Act sandbox conditions (n 5, arts 58–60) and the OECD AI Principles (OECD/LEGAL/0449, Principle 1.5 on robustness and safety throughout the lifecycle). https://artificialintelligenceact.eu/article/58/
  7. National Institute of Standards and Technology, 'Artificial Intelligence Risk Management Framework (AI RMF 1.0)' (NIST 2023) 7–9 https://nvlpubs.nist.gov/nistpubs/ai/NIST.AI.100-1.pdf accessed 30 July 2026.
  8. Regulation (EU) 2024/1689 (n 5) art 57(1) (sandbox participation does not exempt providers from applicable law); OECD/LEGAL/0449 (n 7) Principle 1.5. https://www.regulation-ai.eu/en/articles/article-57/
  9. Constitution of India 1950, arts 14, 21. The principle that innovation cannot override fundamental rights is well established: see Justice K.S. Puttaswamy v Union of India (2017) 10 SCC 1, [297] (privacy as a fundamental right that cannot be subordinated to technological convenience).
  10. Financial Conduct Authority (UK), 'Regulatory Sandbox' (FCA, 2015) https://www.fca.org.uk/firms/innovation/regulatory-sandbox accessed 30 July 2026. The FCA describes a regulatory sandbox as "a 'safe space' in which businesses can test innovative products, services, business models and delivery mechanisms without immediately incurring all the normal regulatory consequences of engaging in the activity in question."
  11. State of Madhya Pradesh v Thakur Bharat Singh AIR 1967 SC 1170 (distinguishing statutory authority from executive guidance). https://indiankanoon.org/doc/766560/
  12. Telecommunications Act 2023, s 27. https://www.indiacode.nic.in/bitstream/123456789/20101/1/A2023-44.pdf
  13. ibid s 27(1)–(2).
  14. Digital Personal Data Protection Act 2023. The term "sandbox" does not appear in any section of the Act. https://www.meity.gov.in/static/uploads/2024/06/2bf1f0e9f04e6fb4f8fef35e82c42aa5.pdf
  15. ibid s 40: "The Central Government may, by notification, make rules for carrying out the provisions of this Act."
  16. ibid ss 5, 6, 8, 9, 10, 11–14.
  17. Ministry of Electronics and Information Technology, 'IndiaAI Governance Guidelines' (Government of India, November 2025).https://static.pib.gov.in/WriteReadData/specificdocs/documents/2025/nov/doc2025115685601.pdf
  18. ibid (medium-term action item: piloting regulatory sandboxes in high-risk domains).
  19. IndiaAI Mission, 'AI Kosh: The National Dataset Platform' https://indiaai.gov.in accessed 30 July 2026.
  20. Reserve Bank of India, 'Framework for Regulatory Sandbox' (RBI/2019-20/88, 16 August 2019) https://www.rbi.org.in/Scripts/NotificationUser.aspx?Id=11615 accessed 30 July 2026.
  21. Regulation (EU) 2024/1689 of the European Parliament and of the Council of 13 June 2024 laying down harmonised rules on artificial intelligence (Artificial Intelligence Act), OJ L 2024/1689, arts 57–63. https://eur-lex.europa.eu/eli/reg/2024/1689/oj/eng
  22. ibid art 58(1).
  23. OECD, 'Recommendation of the Council on Artificial Intelligence' (adopted 21 May 2019, updated 2023) OECD/LEGAL/0449 https://legalinstruments.oecd.org/en/instruments/OECD-LEGAL-0449 accessed 30 July 2026.
  24. Financial Conduct Authority (UK) (n 1). https://register.fca.org.uk/s/
  25. Digital Personal Data Protection Act 2023 (the term "sandbox" does not appear); Personal Data Protection Bill 2019, cl 40 (proposed sandbox; not retained in the enacted statute). https://www.meity.gov.in/static/uploads/2024/06/2bf1f0e9f04e6fb4f8fef35e82c42aa5.pdf
  26. Ministry of Electronics and Information Technology, 'IndiaAI Governance Guidelines' (Government of India, November 2025) (medium-term action item: piloting regulatory sandboxes in high-risk domains).https://static.pib.gov.in/WriteReadData/specificdocs/documents/2025/nov/doc2025115685601.pdf
  27. Reserve Bank of India, 'Framework for Regulatory Sandbox' (RBI/2019-20/88, 16 August 2019) https://www.rbi.org.in/Scripts/NotificationUser.aspx?Id=11615 accessed 30 July 2026.
  28. Reserve Bank of India, 'Framework for Regulatory Sandbox' (RBI/2019-20/88, 16 August 2019) https://www.rbi.org.in/Scripts/NotificationUser.aspx?Id=11615 accessed 30 July 2026. https://www.pib.gov.in/PressReleasePage.aspx?PRID=2286607&reg=48&lang=1 https://ypfsresourcelibrary.blob.core.windows.net/fcic/YPFS/Report%20on%20Trend%20and%20Progress%20of%20Banking%20in%20India%202019-20.pdf
  29. Securities and Exchange Board of India, 'Framework for Regulatory Sandbox' (SEBI/HO/MRD2/CIR/P/2020/168, 2 September 2020) https://www.sebi.gov.in/legal/circulars/sep-2020/framework-for-regulatory-sandbox_47622.html accessed 30 July 2026.
  30. Insurance Regulatory and Development Authority of India, 'IRDAI (Regulatory Sandbox) Regulations, 2019' (IRDAI, 2019) https://www.irdai.gov.in accessed 30 July 2026.
  31. International Financial Services Centres Authority, 'IFSCA (Regulatory Sandbox) Framework, 2021' (IFSCA, 2021) https://ifsca.gov.in accessed 30 July 2026.
  32. Securities and Exchange Board of India, 'Framework for Regulatory Sandbox' (SEBI/HO/MRD2/CIR/P/2020/168, 2 September 2020) https://www.sebi.gov.in/web/?file=/sebi_data/attachdocs/jun-2021/1623665266705.pdf
  33. Insurance Regulatory and Development Authority of India, 'IRDAI (Regulatory Sandbox) Regulations, 2019' (IRDAI, 2019) https://www.lexology.com/library/detail.aspx?g=998219c6-d719-413f-bdf4-5a316f834433
  34. Reserve Bank of India, 'Framework for Regulatory Sandbox' (RBI/2019-20/88, 16 August 2019) https://www.rbi.org.in/Scripts/NotificationUser.aspx?Id=11615 accessed 30 July 2026. https://www.pib.gov.in/PressReleasePage.aspx?PRID=2286607&reg=48&lang=1 https://ypfsresourcelibrary.blob.core.windows.net/fcic/YPFS/Report%20on%20Trend%20and%20Progress%20of%20Banking%20in%20India%202019-20.pdf
  35. International Financial Services Centres Authority, 'IFSCA (Regulatory Sandbox) Framework, 2021' (IFSCA, 2021)https://ifsca.gov.in/CommonDirect/ViewFile?id=21626bde60601ef44a0ed02201da7b0c&fileName=Draft_Public_Consultation_Paper__FinTech_Sandbox_Framework_Approved_19092025_20250919_0655.pdf
  36. Supreme Court of India, e-Committee, 'White Paper on AI and the Judiciary' (2025). https://cdnbbsr.s3waas.gov.in/s3ec0490f1f4972d133619a60c30f3559e/uploads/2025/11/2025112244.pdf
  37. ibid; National Informatics Centre, 'eCourts Phase III: Technical Architecture and AI Tools Documentation' (NIC, 2025).
  38. Constitution of India 1950, arts 14, 21; Bharatiya Sakshya Adhiniyam 2023, ss 39–45 (expert and scientific evidence).
  39. See Medical Devices Rules 2017, SI 2017/GSR 648(E); Indian Council of Medical Research, National Ethical Guidelines for Biomedical and Health Research Involving Human Participants (ICMR 2017). https://ethics.ncdirindia.org/asset/pdf/ICMR_National_Ethical_Guidelines.pdf
  40. Medical Devices Rules 2017 (CDSCO); ICMR National Ethical Guidelines 2017 (ICMR); National Health Authority, 'Ayushman Bharat Digital Mission: Health Data Management Policy' (2021) (NHA). https://cdsco.gov.in/opencms/resources/UploadCDSCOWeb/2022/m_device/Medical%20Devices%20Rules,%202017.pdf
  41. National Health Authority (n 14).https://sandbox.abdm.gov.in/sandbox/v3 https://www.india.gov.in/category/health-wellness/subcategory/health-care-promotion-products/details/ayushman-bharat-digital-mission-abdm-sandbox-guidelines
  42. Constitution of India 1950, arts 14, 15, 21; Constitution of India 1950, Eighth Schedule (22 scheduled languages).
  43. ibid arts 14, 15, 21, 38.
  44. Government of Telangana, 'Telangana AI Roadmap' (September 2024); Government of Tamil Nadu, 'Tamil Nadu Safe and Ethical AI Policy' (2020).https://it.tn.gov.in/sites/default/files/2021-06/TN_Safe_Ethical_AI_policy_2020.pdf
  45. Information Technology (Intermediary Guidelines and Digital Media Ethics Code) Amendment Rules 2026 (synthetic content provisions).https://www.meity.gov.in/static/uploads/2026/02/550681ab908f8afb135b0ad42816a1c9.pdf
  46. Content Authenticity Initiative, 'C2PA Technical Specification' (2024) https://c2pa.org/specifications/specifications/2.0/index.html accessed 30 July 2026.
  47. Information Technology Act 2000; Ministry of Electronics and Information Technology (Allocation of Business) Rules; Representation of the People Act 1951 (electoral integrity); Cable Television Networks (Regulation) Act 1995 (media regulation).
  48. IndiaAI, ‘Now Open: Expression of Interest (EOI) to Contribute Datasets and AI Artefacts to AIKosh’ (7 July 2025) https://indiaai.gov.in/article/now-open-expression-of-interest-eoi-to-contribute-datasets-and-ai-artefacts-to-aikosh accessed 29 June 2026.
  49. Ministry of Electronics and Information Technology, ‘AI models developed under IndiaAI Mission’ (n 4).
  50. Ministry of Electronics and Information Technology, India AI Governance Guidelines (n 3) 27, 39–40.
  51. e-Committee, Supreme Court of India, ‘Vision Document for Phase III of eCourts Project’ https://ecommitteesci.gov.in/vision-document-for-phase-iii-of-ecourts-project/ accessed 29 June 2026; Centre for Research and Planning, Supreme Court of India, White Paper on Artificial Intelligence and Judiciary (n 11) 49–50.
  52. Securities and Exchange Board of India, 'Framework for Regulatory Sandbox' (SEBI/HO/MRD2/CIR/P/2020/168, 2 September 2020) https://www.sebi.gov.in/web/?file=/sebi_data/attachdocs/jun-2021/1623665266705.pdf
  53. Securities and Exchange Board of India, 'Framework for Innovation Sandbox' (SEBI, 2019) https://www.sebi.gov.in/sebi_data/meetingfiles/feb-2020/1582714278455_1.pdf
  54. Reserve Bank of India, 'Framework for Inter-operable Regulatory Sandbox (IoRS)' (RBI/2023-24/75, 22 https://www.rbi.org.in/commonman/English/Scripts/FAQs.aspx?Id=3822
  55. ibid para 2: "The IoRS framework enables entities to test products or services that fall within the regulatory purview of more than one regulator in a single coordinated sandbox environment."
  56. Financial Conduct Authority (UK), 'Regulatory Sandbox' (FCA, 2015) https://www.fca.org.uk/firms/innovation/regulatory-sandbox accessed 30 July 2026.
  57. Financial Conduct Authority (UK), 'Regulatory Sandbox: Cohort Reports' (FCA, 2016–2024) https://www.fca.org.uk/firms/innovation/regulatory-sandbox accessed 30 July 2026.
  58. Financial Conduct Authority (UK), 'Regulatory Sandbox: First Cohort Report' (FCA, June 2017) https://www.fca.org.uk/publication/research/regulatory-sandbox-first-cohort-report.pdf accessed 30 July 2026.
  59. Information Commissioner's Office (UK), 'ICO Regulatory Sandbox' (ICO, 2019) https://ico.org.uk/for-organisations/advice-and-services/regulatory-sandbox/accessed 30 July 2026.
  60. ibid: "The ICO sandbox provides a space for organisations to develop and test innovative products and services… while ensuring compliance with data protection law."
  61. Regulation (EU) 2024/1689 of the European Parliament and of the Council of 13 June 2024 laying down harmonised rules on artificial intelligence (Artificial Intelligence Act), OJ L 2024/1689, arts 57–63.
  62. See, eg, Michael Veale and Frederik Zu Borgesius, 'Demystifying the Draft EU Artificial Intelligence Act' (2021) 14(4) European Journal of Risk Regulation 97; European Parliament, 'Implementation of the AI Act: Challenges and Recommendations' (Study PE 764.893, 2024).
  63. OECD, 'AI Policy Observatory: Building Regulatory Capacity for AI Governance' (OECD, 2024) https://oecd.ai accessed 30 July 2026.
  64. European Commission, 'AI Act: Implementation and Harmonised Guidelines' (2025–2026) https://ec.europa.eu/commission/presscorner/detail/de/ip_26_1714
  65. Internet Freedom Foundation, 'Submissions on the Personal Data Protection Bill, 2019' (IFF, 2020) https://internetfreedom.in accessed 30 July 2026; Centre for Internet and Society, 'Comments on the Personal Data Protection Bill, 2019' (CIS, 2020) https://cis-india.org accessed 30 July 2026.
  66. ibid. The concern was directed at the structural conditions of sandbox participation, not at the concept of sandboxing itself.
  67. See, eg, Shehnaz Ahmed and others, 'Regulatory Sandboxes: A Global Review and Indian Perspective' (2020) 55(12) Economic and Political Weekly 34.
  68. Reserve Bank of India, 'Regulatory Sandbox: Cohort Reports' (RBI, 2020–2024) https://www.rbi.org.in/commonman/English/Scripts/FAQs.aspx?Id=3822
  69. Supreme Court of India, e-Committee, 'White Paper on AI and the Judiciary' (2025).
  70. DAKSH, 'AI and the Indian Judiciary: Opportunities and Risks' (DAKSH, 2024); Vidhi Centre for Legal Policy, 'Responsible AI for the Indian Justice System' (Vidhi, 2024) https://vidhilegalpolicy.in accessed 30 July 2026.
  71. DAKSH, 'State of the Indian Judiciary: A Data-Driven Analysis' (DAKSH, 2024) https://dakshindia.org accessed 30 July 2026; AI4Bharat, 'IndicTrans2: Towards Open-Source Neural Machine Translation for Indian Languages' (2023) https://ai4bharat.iitm.ac.in accessed 30 July 2026.
  72. Szoszkiewicz, 'Mental Privacy: Navigating Risks, Rights and Regulation' (2025) 2 Nature Communications Medicine 1 https://link.springer.com/article/10.1038/s44319-025-00505-6 accessed 30 July 2026; Latanya Sweeney, 'Simple Demographics Often Identify People Uniquely' (2000) Carnegie Mellon University Data Privacy Working Paper 3 https://dataprivacylab.org/projects/identifiability/ accessed 30 July 2026.
  73. UNESCO, 'Recommendation on the Ethics of Artificial Intelligence' (adopted 23 November 2021, 41st General Conference) paras 37–40 https://unesdoc.unesco.org/ark:/48223/pf0000381137 accessed 30 July 2026.
  74. European Parliament, 'The Protection of Mental Privacy in the Area of Neuroscience' (Study PE 757.807, 2024) 22–24; National Institute of Standards and Technology, 'Artificial Intelligence Risk Management Framework (AI RMF 1.0)' (NIST 2023) 15–17 https://nvlpubs.nist.gov/nistpubs/ai/NIST.AI.100-1.pdf accessed 30 July 2026.
  75. OECD (n 14); European Parliament (n 13).
  76. Constitution of India 1950, arts 14 and 21; Justice KS Puttaswamy (Retd) v Union of India (2017) 10 SCC 1.
Cookies help us deliver our services. By using our services, you agree to our use of cookies.