Most firms in financial services have heard of the FCA’s sandbox. Far fewer can describe what it offers, who it is open to, or what it costs. The misconceptions are costing firms opportunity.
Firms use the FCA Regulatory Sandbox when they wants to test an innovative FCA regulated product, service, or business model, or technology with real customers, and have identified a need for close regulatory engagement and a controlled testing environment before a full market launch.
As part of the Sandbox, the FCA may give firms temporary permissions, if appropriate, to carry out certain activities. Firms that are not FCA regulated, for example, RegTech or SupTech providers of technology solutions, use the sandbox that best suits them.
This article draws on the AI Capability Building working session, convened by FinTech-Tables with Keeper Solutions and Higgs LLP. The full report sets out the keynotes, the three working group findings, the five key challenges and the ten takeaways in full.
Sandboxes: A decade of controlled testing
The regulatory sandbox model in the UK is now around ten years old. Its founding logic was simple. Where a firm had an innovative proposition and genuine uncertainty about how the rules applied to it, the regulator would help that firm test the proposition in a controlled live environment with real consumers, rather than waiting for a full market launch to discover the answer.
That model has held up. What changed was the technology it had to accommodate. The earlier digital environments were built for machine learning models, regressions and data analysis, and they provided access to synthetic datasets on that basis. The FCA have three sandbox channels, Regulatory Digital and Supercharged for AU innovation supported by NVIDIA.
Generative AI introduced categorically different requirements: GPU access, proper development environments, model tooling, secure data management, probabilistic test systems. Environments designed for the previous generation of models were not built for any of that.
The current generation of AI-specific sandbox provision reflects those requirements. A participating firm receives its own secure environment, effectively a dedicated cloud account, in which to experiment with AI use cases. That typically includes GPU access, hyperscaler tooling, synthetic datasets covering consumer behaviour, banking transactions and fraud typologies, and access to policy expertise alongside the wider innovation network.
FCA Sandbox misconceptions about sandboxes worth clearing up
The first is eligibility. Sandbox participation is widely assumed to be for start-ups that may require authorisation in future. In practice, it is open to firms that are already authorised, firms currently seeking authorisation, and firms at any stage of an application, including those mid-application.
The second is cost. Compute is generally covered by the regulator up to defined limits. Firms bring their own engineering resource, which is the real investment, and they can bring their own data, subject to conditions around personally identifiable information.
The third is intellectual property. Environments of this kind are isolated: each participant works in a locked account, retains ownership of what it builds, and the regulator does not retain or share the output.
The fourth, and the most consequential, is what participation signifies. A sandbox is not a regulatory shield. Regulators running these programmes are not creating AI-specific rules, not picking winners and not endorsing products. Existing principles on consumer protection, governance, accountability and resilience apply in full. A firm that treats participation as a form of pre-approval has misunderstood the exercise, and will be told so.
What firms get out of s FCA sandboxes
The practical value is speed of evidence. Consider a firm wanting to test a large language model as a quality assurance judge. Internally, getting a single model through a model risk management committee can take months and may fail outright. In a sandbox environment, the same team can stand up several models in parallel, fine-tune, identify which performs, and return to internal governance with evidence of what to pursue and why. Months of governance delay compress into weeks of productive experimentation.
There is a governance lesson in how these programmes are run, too. Early cohorts of tightly restricted environments tend to generate a flood of permission requests rather than a flood of usage. Programmes that progressively opened access, in some cases to near-administrative permissions, found that firms behaved responsibly: they used what they needed, shut down what they didn’t, and got on with building. If people spend more time asking for permission than learning, the guardrails have become friction.
The question to ask yourself about using FCA sandboxes
Sandbox access solves a specific problem: it gives a firm somewhere to generate evidence without exposing customers or production systems. It does not solve the prior problem of knowing what you are trying to prove. Firms that arrive with a defined use case, an established baseline and a clear measure of success get disproportionate value. Firms that arrive with a demo do not.
Pitches of innovative products and services, based on a compelling demonstration is not evidence for your prospects. The firms that will thrive are the ones that can evidence what their systems do, because those are the ones consumers and institutional buyers will trust.
This information is for guidance purposes only and does not constitute legal advice. We recommend you seek legal advice before acting on any information given.