The Test Becomes the Argument: How Regulatory Sandboxes Are Changing Lobbying

A regulatory sandbox is not a quiet compliance service. It is a scarce, supervised setting in which companies and authorities learn together—and where operational evidence can shape future rules. That makes the sandbox a consequential new arena for responsible lobbying, with unusual opportunities and equally unusual integrity risks.

Executive summary

Traditional lobbying tries to persuade a public institution with analysis, testimony, coalitions, and political judgment. A regulatory sandbox adds another instrument: a controlled real-world test. Instead of asserting that a new product can be governed safely, a participant may be able to demonstrate how it behaves, which safeguards work, where an existing rule blocks a socially useful outcome, and what a revised rule might require.

This matters because regulators are now using sandboxes well beyond their fintech origins. In July 2026, the European Union’s AI Omnibus expanded access to AI regulatory sandboxes and created a route for an EU-level sandbox.[2] The United Kingdom’s Financial Conduct Authority is testing stablecoin propositions expressly to inform its future regime.[6] Ofgem has published a completed energy case in which a supervised trial helped produce a permanent industry-code change.[9] Singapore’s financial regulator reported in October 2025 that 15 of the 19 firms accepted into its sandbox had graduated and obtained relevant licenses.[10]

The opportunity is real, but so are the distortions. Participants receive repeated access to officials, regulatory interpretation, and a chance to frame the evidence. Nonparticipants may never receive comparable attention. A small test can be mistaken for proof at market scale. Acceptance can be misrepresented as official endorsement. Confidential commercial data can make public scrutiny difficult. And a program intended to reduce barriers for innovators can favor firms with the staff, capital, legal sophistication, and risk tolerance to enter it. Legal scholarship on sandbox governance identifies this proximity, uneven transparency, and the possibility of regulatory capture as central design risks.[11]

The practical conclusion is not that public affairs teams should take over sandboxes. They should not. Product, legal, risk, compliance, engineering, and customer-protection teams must own the test. Public affairs should ensure that the organization understands the institutional purpose, separates commercial validation from policy claims, discloses advocacy as required, brings affected voices into the evidence base, and does not ask a limited experiment to carry more weight than it can bear.

Key evidence

  • The EU AI Omnibus entered into force on July 27, 2026, expanding access to AI regulatory sandboxes and introducing an EU-level sandbox.[2]
  • The FCA’s 2026 stablecoin cohort accepted 4 firms from 20 applications; testing began in the first quarter of 2026.[6]
  • A study of the UK fintech sandbox associated entry with about a 15% increase in average capital raised and a 50% increase in the probability of raising capital; the dataset covered 2014–2019 and the authors cautioned that their views were not those of the BIS.[7]
  • Ofgem’s Emergent trial covered approximately 165 customers; the resulting code modification became permanent in September 2024, although the end-to-end process took about four years.[9]
  • Singapore’s Ministry of Finance reported on October 14, 2025 that 15 of 19 firms accepted into Monetary Authority of Singapore sandboxes had graduated and obtained relevant licenses.[10]

The room where a hypothesis meets a rule

The phrase regulatory sandbox is used loosely. At its most credible, it means a time-limited and supervised environment in which an innovation is tested against defined objectives, guardrails, evidence requirements, and an exit plan. The OECD describes it as a controlled setting used to understand an innovation’s opportunities and risks and to develop an appropriate regulatory environment.[3]

That definition excludes several neighboring activities. An innovation hub may offer informal guidance without a live test. A digital sandbox may provide datasets and technical tools. A pilot may test delivery without adjusting a regulatory condition. A consultation asks stakeholders for views. A genuine regulatory sandbox normally combines supervised experimentation with some form of regulatory engagement and, in some systems, a temporary waiver, restricted authorization, derogation, or enforcement assurance.

The FCA makes these boundaries particularly clear. Its sandbox allows tests with real consumers on a limited scale and for a limited duration. Yet participation is not regulatory exemption. A firm conducting regulated activity still needs the appropriate authorization or registration. The FCA may offer restricted authorization, guidance, a temporary modification of its own rules, or a no-enforcement-action letter; it cannot waive national or international law, and consumer liabilities remain.[5]

Why should this concern lobbying professionals? Because a sandbox changes the medium of influence. The company is no longer only sending a position paper to an institution. It may be helping to define the test question, selecting metrics, generating data, interpreting anomalies, and presenting lessons that officials may use when they clarify or revise policy. This is lobbying by demonstration: influence exercised through an operational claim that can be observed, not merely asserted.

Whether a specific interaction is legally reportable as lobbying depends on the jurisdiction, the applicable register, the identity of the participants, and the purpose of the communication. “Sandbox” is not a universal exemption from transparency law. A company should classify contacts by their substance—not by the program’s friendly name—and obtain jurisdiction-specific legal advice.

A framework for understanding sandbox influence

A sandbox can affect policy through four connected mechanisms: access, translation, evidence, and diffusion. Together they explain why participation can matter far beyond the test itself.

1. Access: repeated contact changes the information environment

Sandbox participants often work with a dedicated case manager or specialist team. That relationship can improve mutual understanding. Regulators see the product architecture, risk controls, customer journey, and constraints in greater detail than a conventional consultation normally permits. The company learns how the authority interprets uncertain requirements and which public-interest concerns carry the greatest weight.

Access is not the same as improper influence. Regulators need information that only operators may possess. The integrity question is comparative: who else can contest the participant’s account, and how will the authority avoid treating a selected firm’s experience as representative of an entire market?

2. Translation: technical choices become regulatory categories

Emerging technologies rarely arrive in the categories used by existing law. A sandbox translates engineering and commercial facts into regulatory concepts: custody, control, explainability, settlement, consumer consent, resilience, switching, or accountability. That translation can be more consequential than a broad argument for or against regulation. Once a regulator accepts a particular framing of the problem, some policy options become natural and others become difficult to defend.

Public affairs teams add value here when they make the translation legible across institutions. They create risk when they turn a contested business preference into an apparently neutral technical necessity.

3. Evidence: the test produces a policy asset

A well-designed sandbox can move a debate from prediction to observation. It can show whether consumers understand a disclosure, whether settlement data remain accurate, whether a safety control works under defined conditions, or whether a rule designed for an older market structure produces an unintended barrier.

Evidence, however, is bounded. A six-month trial involving a limited customer group does not automatically establish effects at national scale, under competitive stress, or over several years. Participants and authorities must preserve the distinction between the test worked as specified and the policy should therefore be generalized.

4. Diffusion: a private test can become a public rule

The strongest sandboxes have a path from experiment to wider learning. That may involve a published evaluation, a consultation, a code modification, generalized guidance, or a formal rulemaking. Diffusion is where the exercise becomes most clearly relevant to lobbying: the participant’s evidence enters a process that affects competitors, consumers, and future entrants who were not part of the original test.

Influence channelLegitimate public valuePrincipal integrity riskEvidence leaders should require
AccessRegulator gains detailed operational knowledgeSelected participants receive privileged attentionPublished eligibility criteria, contact records where required, and routes for outside input
TranslationNovel technology is mapped to workable legal conceptsA commercial preference is framed as technical inevitabilityAlternative architectures and affected-party perspectives
EvidencePolicy is tested against observed behaviorSmall or favorable samples are overgeneralizedPredefined metrics, baseline, adverse outcomes, limitations, and reproducibility
DiffusionSuccessful learning informs clearer rulesA temporary advantage becomes a durable market privilegePublic evaluation, formal decision route, review date, and equal-access plan

Case one: the EU is turning AI sandboxes into infrastructure

The EU AI Act made regulatory sandboxes part of the Union’s governance architecture. The European Parliament’s research service described them in March 2026 as controlled environments for testing compliance while warning of design, fragmentation, and timing challenges across member states.[4]

The AI Omnibus, which entered into force on July 27, 2026, materially widened that architecture. According to the European Commission, the amended regime expands testing opportunities and introduces an EU-level sandbox. It also extends certain benefits to small mid-cap companies and gives the AI Office broader oversight in defined areas.[2] The legislative text strengthens coordination among sandboxes and clarifies the involvement of data-protection authorities when personal data are processed.[1]

Verified fact. These provisions create supervised routes for experimentation; they do not suspend the AI Act or other applicable law. The Commission’s public summary also places the sandbox changes within a broader package that postponed the application of certain high-risk AI rules to December 2, 2027 and August 2, 2028, depending on the category.[2]

Analysis. The political significance lies in institutionalization. A sandbox is no longer an optional innovation service at the edge of EU digital policy. It is becoming part of the system through which authorities understand applications, coordinate interpretations, and accumulate implementation knowledge.

That creates an opportunity for companies with genuinely testable questions: for example, how a conformity requirement applies to a novel system, how real-world testing can be conducted with adequate safeguards, or how multiple regulators should coordinate around the same use case. But the influence claim must remain disciplined. Participation may reveal that a compliance pathway is workable for one architecture and one dataset. It does not prove that an entire class of systems is safe or that statutory safeguards are excessive.

For multinational businesses, fragmentation is the immediate strategic risk. If national sandboxes differ in capacity, admission standards, sector expertise, transparency, or regulatory relief, companies may seek the most accommodating venue. Cross-border coordination can reduce that risk, but it also raises the stakes of early cases: a solution tested in one setting may travel across the Union.

Case two: the FCA’s stablecoin cohort makes scarcity visible

The FCA’s 2026 stablecoin cohort offers an unusually explicit example of a sandbox used before final rules are settled. The authority received 20 applications and selected four firms—Monee Financial Technologies, ReStabilise, Revolut, and VVTX—to test use cases that include payments, wholesale settlement, and crypto trading. The FCA states that the resulting insights may help shape its future regime, while emphasizing that acceptance is not endorsement.[6]

Verified fact. The cohort began testing in the first quarter of 2026. Firms operate under existing permissions and registrations, and the regulator has said that findings will inform final stablecoin rules.[6] Separately, the FCA’s general sandbox remains open to firms throughout the year and applies published eligibility criteria including genuine innovation, consumer benefit, readiness, and a need for regulatory support.[5]

Analysis. The selection ratio—four out of 20—shows why sandbox governance is also access governance. The selected firms will generate the live evidence, receive specialist feedback, and participate in the regulator’s learning process. Sixteen applicants will not have the same position. Meanwhile, organizations that lacked the resources or confidence to apply are absent even from the denominator.

This does not make the cohort illegitimate. Scarcity is unavoidable when supervisory capacity is finite and live consumer testing carries risk. It does mean that selection criteria, safeguards, and the route by which lessons are generalized deserve as much attention as the technical tests. A cohort can help a regulator see what is possible; it can also narrow the field of vision to the business models of those admitted.

The wider evidence is encouraging but incomplete. Research by Cornelli, Doerr, Gambacorta, and Merrouche used UK fintech data from 2014 to 2019 and found that sandbox entry was associated with a higher probability of fundraising and approximately 15% more capital raised on average. The authors also identified positive associations with survival and patenting.[7] That suggests a sandbox can reduce regulatory uncertainty and information asymmetry for investors. It also means admission may confer a valuable market signal—even when a regulator says it is not an endorsement.

Boards should therefore prohibit promotional language that turns “accepted for a limited test” into “approved by the regulator.” The difference is not semantic. It protects consumers, the authority, and the credibility of the program.

Case three: an energy test travels into permanent rules

Ofgem’s Emergent Energy Systems case shows the complete path from controlled experiment to regulatory change. Emergent operates residential microgrids and sought a practical method enabling residents on private networks to switch electricity supplier. Existing settlement arrangements made that right difficult to exercise. Ofgem granted a temporary derogation from the Balancing and Settlement Code in March 2022 so the company could test an on-site aggregation method.[8]

The trial took place across four sites in Gateshead and Nottingham, covering approximately 165 customers—well below the permitted ceiling. According to the evaluation published in May 2026, the test demonstrated settlement accuracy, reduced operational complexity, and supported Modification P455. Ofgem approved that modification on September 17, 2024; it was implemented a week later and made the method available beyond the original trial.[9]

Why the approach worked. The advocacy claim was narrow and falsifiable. Emergent did not merely argue that the old code was outdated. It identified a specific barrier, proposed a testable alternative, operated under a time-limited derogation, generated settlement data, and moved the evidence through a formal code-modification process. The test was connected to a public value—making an existing consumer switching right practical—rather than only to the company’s market entry.

What did not work cleanly. The evaluation also records an onerous proving requirement, a lengthy end-to-end process of about four years, cross-code coordination problems, and objections from incumbents that the company regarded as commercially motivated. These are claims in a participant-authored evaluation hosted by Ofgem; they should not be treated as an independent finding about another party’s motives. The documented timeline and test design nevertheless show that “agile” regulation can impose substantial cost and delay on a small innovator.[9]

Analysis. This case is lobbying by proof in its clearest form. The company’s evidence supported a change with market-wide effect. Yet the pathway retained institutional gates: consultation, code-panel review, Ofgem assessment, and a formal modification. The sandbox generated evidence; it did not replace the decision process.

Case four: Singapore’s graduation figure—and what it cannot tell us

In an October 14, 2025 parliamentary reply, Singapore’s Ministry of Finance stated that the Monetary Authority of Singapore had accepted 19 firms across its sandbox arrangements and that 15 had graduated and obtained the relevant licenses. It also explained that unsuccessful applicants are directed toward other innovation-support channels where appropriate.[10]

The figure indicates that many accepted firms progressed to authorization. It does not establish that the sandboxes caused their commercial success, improved consumer welfare, or produced better regulation at system level. Nor does it tell us whether the four other accepted firms failed, withdrew, remained in testing, or followed another route. Those distinctions matter.

Hilary Allen’s 2025 review of the first decade of sandboxes makes this evidence problem explicit: available studies say more about benefits to participating firms than about effects on the broader regulatory system or society.[12] Graduation is an output. Sound policy analysis still needs outcomes: consumer harm avoided, competition improved, compliance costs reduced without weakening protection, or rules made more accurate.

The five integrity tests

A responsible organization should apply five tests before describing a sandbox as a public-affairs success.

Public-purpose test

What public problem does the experiment examine? Faster market entry may be legitimate, but it is not by itself a public outcome. The case should identify the consumer, competition, resilience, inclusion, environmental, safety, or administrative benefit being tested.

Counterfactual test

Compared with what? A pilot needs a baseline: the existing rule, process, cost, error rate, or consumer experience. Without one, the participant may demonstrate that its product operates, not that a regulatory change is justified.

Representativeness test

Who and what are missing? Small tests may exclude vulnerable users, unusual failure conditions, less sophisticated competitors, or cross-border complications. Limitations should be reported as prominently as favorable results.

Transparency test

Which contacts, waivers, methods, results, and conflicts can be disclosed? Commercial confidentiality is sometimes necessary, but it should not make the policy pathway invisible. Where lobbying rules apply, contacts should be recorded according to their real purpose.

Exit-and-diffusion test

What happens after the test? A sandbox without an exit condition risks becoming a private corridor around ordinary rules. A successful experiment should lead to one of several explicit outcomes: no change, further testing, generalized guidance, a formal consultation, a rule or code amendment, or standard authorization. The path should be available to others on equivalent terms.

What leaders should do now

Begin with a regulatory question, not a showcase. A sandbox is not a product launch. Define the uncertainty that requires live evidence and why normal authorization, consultation, or laboratory testing cannot resolve it.

Put operations in charge of the evidence. The test plan should be owned by people accountable for product performance, risk, legal compliance, data protection, customer outcomes, and technical assurance. Public affairs should connect the evidence to the institution’s policy process, not manufacture the evidence.

Write the limitations before the results arrive. Agree the sample, duration, baseline, success metrics, failure indicators, adverse-event process, and claims that the design cannot support. This reduces the temptation to convert a promising signal into a sweeping policy conclusion.

Build a transparent contact protocol. Maintain a record of regulator interactions, distinguish supervisory assistance from advocacy, apply the relevant lobbying and conflicts rules, and review public statements for implied endorsement. If a contact seeks to influence general policy, calling it “technical” does not change its substance.

Invite the absent stakeholder into the design. Depending on the test, that may mean consumer representatives, civil society, labor, smaller competitors, technical standard-setters, data-protection specialists, or local authorities. The objective is not ceremonial consultation. It is to expose the experiment to risks the applicant may not see.

Protect against the endorsement effect. Investor and customer materials should state precisely what acceptance means, which permissions apply, how long the test lasts, and what the regulator has not approved. Senior management should sign off on any use of the authority’s name.

Plan for generalization. If the test succeeds, specify how results could be scrutinized and made usable by others. Separate proprietary engineering from policy-relevant findings. Support a formal, contestable decision route rather than seeking to preserve a bespoke advantage indefinitely.

Give the board the whole picture. The board dashboard should show the public purpose, legal basis, safeguards, resources, regulator contacts, test metrics, affected stakeholders, disclosure obligations, commercial signaling risk, and possible exits. A sandbox can affect authorization, reputation, capital, market structure, and future regulation at the same time.

Conclusion

Regulatory sandboxes are changing the craft of lobbying because they change what counts as an argument. A company can bring a regulator not only a forecast or a position, but a supervised experience: customers moved through a process, safeguards activated, settlement data reconciled, or a compliance pathway tested.

That is potentially better policymaking. It can expose obsolete rules, reduce uncertainty, and give public institutions evidence before they generalize a decision. The Ofgem case shows that a narrowly designed experiment can help convert a legal right into a workable market mechanism. The FCA’s stablecoin cohort shows how live testing can inform rules before a new regime is finalized. The EU’s revised AI framework shows that sandboxes are becoming regulatory infrastructure rather than isolated innovation programs.

That is potentially better policymaking. It can expose obsolete rules, reduce uncertainty, and give public institutions evidence before they generalize a decision. The Ofgem case shows that a narrowly designed experiment can help convert a legal right into a workable market mechanism. The FCA’s stablecoin cohort shows how live testing can inform rules before a new regime is finalized. The EU’s revised AI framework shows that sandboxes are becoming regulatory infrastructure rather than isolated innovation programs.

But evidence does not eliminate power. Someone selects the participants, frames the question, chooses the metrics, interprets the result, and decides whether the lesson travels. Responsible lobbying in a sandbox therefore demands more than technical competence. It requires candor about access, limits, conflicts, and who is absent from the test.

The winning position is not “our pilot succeeded, therefore change the rule.” It is more disciplined: “under these conditions, this evidence supports this conclusion, these uncertainties remain, and this is the public process through which others should be allowed to challenge it.” When companies can say that—and mean it—the test becomes an argument worthy of institutional trust.

Glossary

Regulatory sandboxA controlled, time-limited environment in which an innovation is tested under regulatory supervision and defined safeguards.DerogationTemporary, legally authorized relief from a specific rule or code requirement; its scope depends on the authority’s powers.No-enforcement-action letterA regulator’s limited statement that it does not expect to take specified enforcement action during an agreed test; it does not erase other liabilities.Real-world testingTesting in actual operational conditions, potentially involving real users, rather than only simulated or laboratory environments.Regulatory captureA condition in which regulation or supervision becomes unduly shaped by the interests of regulated actors rather than the public mandate.DiffusionThe process by which learning from a limited experiment influences broader guidance, standards, codes, or rules.

References and further reading

Official and primary sources

  1. European Union, Regulation (EU) 2026/1744 amending Regulation (EU) 2024/1689, Official Journal of the European Union, July 24, 2026.
  2. European Commission, AI Omnibus Enters into Force, July 27, 2026.
  3. OECD, Regulatory Sandbox Toolkit: A Comprehensive Guide for Regulators to Establish and Manage Regulatory Sandboxes Effectively, OECD Publishing, July 24, 2025.
  4. Tristan Jacques Marcel Marcelin, European Parliamentary Research Service, AI Regulatory Sandboxes: State of Play and Implementation Challenges, European Parliament, March 17, 2026.
  5. Financial Conduct Authority, Regulatory Sandbox, first published March 27, 2022; updated July 24, 2026.
  6. Financial Conduct Authority, Regulatory Sandbox: Stablecoins Cohort, November 26, 2025; updated February 25, 2026.
  7. Ofgem, Regulatory Sandbox: Emergent Energy Systems Ltd—2022, March 14, 2022; evaluation added May 28, 2026.
  8. Emergent Energy Systems Ltd, hosted by Ofgem, BSC Sandbox Evaluation Report, February 18, 2026; published May 2026.
  9. Singapore Ministry of Finance / Monetary Authority of Singapore, Written Reply to Parliamentary Question on Statistics on MAS Regulatory Sandboxes, October 14, 2025.

Academic and analytical works

  1. Giulio Cornelli, Sebastian Doerr, Leonardo Gambacorta, and Ouarda Merrouche, Regulatory Sandboxes and Fintech Funding: Evidence from the UK, BIS Working Papers No. 901, Bank for International Settlements, November 2020.
  2. Sofia Ranchordás and Valeria Vinci, Regulatory Sandboxes and Innovation-Friendly Regulation: Between Collaboration and Capture, Italian Journal of Public Law, Vol. 16, Issue 1, 2024, pp. 107–139.
  3. Hilary J. Allen, Regulatory Sandboxes: One Decade On, Georgetown Journal of International Law, Vol. 56, 2025, p. 667.

Source and methodology note

Research was completed on August 24, 2026. The article prioritizes legislation, regulators’ program pages, official decisions, a regulator-hosted evaluation, parliamentary material, OECD guidance, and peer-reviewed or scholarly analysis. The Ofgem evaluation was prepared by the participant, Emergent Energy Systems, and is therefore used for documented test details and the participant’s stated experience; its characterizations of incumbent motives are not treated as independently verified. The MAS source was temporarily unavailable at the time of access; the official indexed text and publication metadata were cross-checked, and no details beyond the Ministry’s reported aggregate figures are inferred. The BIS study examines UK fintech data from 2014–2019 and should not be generalized automatically to AI, energy, or every sandbox design. The article distinguishes official facts from the author’s analysis and makes no causal claim about a particular private intervention changing policy unless the formal record establishes the pathway.

Suggested internal links


Discover more from Responsible Public Affairs

Subscribe to get the latest posts sent to your email.

Share This :
Facebook
X
LinkedIn
Print
Email
WhatsApp

Leave a Comment

Your email address will not be published. Required fields are marked *

This site uses Akismet to reduce spam. Learn how your comment data is processed.

Discover more from Responsible Public Affairs

Subscribe now to keep reading and get access to the full archive.

Continue reading