Info Gov

The Information Commissioner's Office (ICO) has published research concluding that a statutory regulatory sandbox for innovative products and services is feasible, but would require changes to data protection legislation and careful safeguards to protect the regulator's independence and individuals' rights.

A regulatory sandbox is a supervised environment in which organisations can develop and test innovative products and services with support and advice from a regulator, working through compliance questions before deployment rather than after.

The ICO's own Regulatory Sandbox has operated for more than eight years as a place for organisations to test new ideas, explore data protection risks and build privacy into new products and services by design. Projects have ranged from tools helping students manage their information when applying for further education to AI and sensor-based technologies designed to improve social care and prevent falls.

Participation in a conventional Regulatory Sandbox must still comply with the UK GDPR and the Data Protection Act 2018 throughout. A statutory sandbox goes further, however, using legislation to permit limited, supervised departures from specific legal requirements during testing.

The research, carried out with the Regulatory Innovation Office's AI Capability Fund, examined the viability of a data protection Statutory Regulatory Sandbox (SRS). The ICO's findings report, published on 30 July alongside supporting research, reached three headline conclusions:

1. A data protection SRS is feasible, but government and the ICO would need to address important challenges, including protecting the ICO's independence and ensuring individual rights are transparently protected through alternative but equivalent accountability and governance mechanisms.
2. Public trust must be at the heart of any SRS, with innovations delivering clear public benefit - people are willing to see new and novel data use where it delivers better services and outcomes for everyone.
3. Demand for an SRS is niche, but the potential impact is significant if key economic opportunities and societal benefits can be unlocked faster.

Any SRS would operate within ICO oversight and safeguards. It would require changes to data protection legislation and the ICO says it will be for government to decide next steps. The regulator positions the report as a contribution to policy development as government advances its thinking on the Regulating for Growth Bill and the AI Growth Lab.

The ICO said that existing sandboxes have limits, including the ability to use live personal information in cases that push the boundaries of the data protection principles, and creating space for issues requiring multiple regulators to balance risks across different domains, such as privacy and competition. These constraints, it argued, can slow the pace at which regulators deliver certainty on the rules of the road for emerging technologies, slow innovation, and leave users of new technologies confused or unprotected.

The regulator said it is drawing on international and domestic models, citing the Singaporean PDPC and the FCA, and its work through the Digital Regulation Cooperation Forum, which piloted an AI and digital hub offering multi-agency advice from the CMA, FCA, Ofcom and the ICO. It is also one of four regulators supporting the government's Advisory AI Growth Lab for legal services and is working with firms through the FCA's AI Lab.

Alongside the SRS work, the ICO committed to improving its existing sandbox to run faster and produce clearer outputs and conclusions for participants, while cautioning that organisations must be willing to bring the hard problems and accept that co-creation also means accepting limits on tech deployment where privacy, safety and individual rights are at play.

The findings report and supporting research are available at: https://ico.org.uk/about-the-ico/research-reports-impact-and-evaluation/research-and-reports/technology-and-innovation/statutory-regulatory-sandbox/

Also in this section

Sep 14, 2026

Human rights committee calls for AI Bill, single AI regulator and tougher UK GDPR rules on automated decisions

The UK Parliament's Joint Committee on Human Rights has called on the government to introduce a dedicated AI Bill, create a single statutory AI regulator and strengthen the UK GDPR's safeguards on automated decision-making, saying that the current legal framework is fragmented, applies mainly at the point of deployment and leaves people unable to find out when AI has been used in decisions that…
Sep 11, 2026

Government rejects Lords "last-resort" power to shut down AI systems and data centres

The government has rejected a cross-party amendment to the Cyber Security and Resilience (Network and Information Systems) Bill that would have given the Secretary of State statutory "last-resort" powers to direct the shutdown of data centres and AI systems deployed at scale in the UK in the event of an AI security or operational emergency.
Sep 03, 2026

What is AI Governance – and Why Does it Matter?

[data-gutter="2%"][data-nb="2"]:not(.ckadvancedlayout) [data-width="50"] [data-gutter="2%"][data-nb="2"].ckadvancedlayout [data-width="50"] [data-gutter="2%"][data-nb="2"]:not(.ckadvancedlayout) [data-width="50"] [data-gutter="2%"][data-nb="2"].ckadvancedlayout [data-width="50"] #block_ID1788458782633 { } #block_ID1788458782633 a.pbck-link-wrap { } #block_ID1788458782633…

InfoGov Masthead Newsletter 800