Adapte Dijital
Anasayfa
AINEO
Dijital Danışmanlık Dijital Denetim
Web & AI
Kurumsal
Paketler Blog

What Is a Regulatory Sandbox?

Yayın Tarihi: 31 Ağustos 2026 Yazar: Adapte Dijital Kategori: Tips
What Is a Regulatory Sandbox? — Adapte Dijital cover image
💡 Kısaca: Some work cannot be tried because of regulation.

Some work cannot be tried because of regulation. Sandboxes exist to get past that wall. Türkiye’s AI Action Plan foresees regulatory sandboxes in priority areas, starting with finance, health, energy, mobility and telecommunications. There will be a single digital application point, time-limited trials and a “graduation gate”.

The graduation gate is the most important part. Successful pilots move quickly to permanent regulation or public procurement. So the trial does not stay a trial. The door is open at both ends.

WHAT

What Is the Problem?

BU BÖLÜMÜN ÖZETİ

  • The solution exists; the permission does not
  • Nobody starts because the rule is unclear
  • Regulators cannot regulate what they cannot see

Three scenes recur in regulated sectors.

The solution exists; the permission does not

The idea works and the technology is ready. But regulation does not allow the job to be done that way. The venture stops here. It will either wait years or move to another country. Both are losses.

Nobody starts because the rule is unclear

Sometimes there is no ban, only ambiguity. Nobody knows whether it is allowed. Ambiguity halts investment. No business wants to carry the risk of a later penalty.

Regulators cannot regulate what they cannot see

There is a problem on the institutional side too. Writing rules for a technology never tested in the field is hard. The result is a standoff both sides are waiting out. Nobody takes the first step.

WHY

Why Does It Happen?

BU BÖLÜMÜN ÖZETİ

  • Regulation moves slower than technology
  • Risk sits on one side
  • There is no channel

Three root causes.

Regulation moves slower than technology

Rule-writing takes years; technology changes in months. That gap is not closing. The sandbox does not try to close it either. It opens a passage through.

Risk sits on one side

In the classic order, all risk binds whoever tries. That punishes trying. The sandbox shares risk by limiting it. Limited duration, limited scope, supervised trial.

There is no channel

A business wanting to say “I would like to try this” does not know whom to approach. The plan’s single-application-point promise fills exactly that gap. Having a known counterpart is itself a relief.

HOW

How Is It Done?

BU BÖLÜMÜN ÖZETİ

  • Step 1: describe the obstacle precisely
  • Step 2: write how you will limit the risk
  • Step 3: set a measurement and reporting plan

The application prepares in three steps.

Step 1: describe the obstacle precisely

Which regulatory provision blocks which part of your work? You should be able to write that in one sentence. A general complaint achieves nothing; you need a specific provision. “Regulation makes things hard for us” is not grounds for an application. Showing which article makes which practice impossible is. That precision separates your application from the rest.

Step 2: write how you will limit the risk

The sandbox’s logic is limited risk. So propose the limit yourself. How many users, for how long, at what value, with what rollback mechanism? Where does human oversight step in? Who stops the system if something goes wrong? An application that has designed its approval flow upfront inspires confidence.

Step 3: set a measurement and reporting plan

The regulator wants to know what it will see during the trial. Which indicators will you report, how often? What is your incident notification process? When this plan is built well, the graduation gate opens easily. Because the evidence is already collected.

HOW

How Long, Where to Start?

BU BÖLÜMÜN ÖZETİ

  • Application prep takes a few weeks
  • The return has two layers
  • First step: write down your obstacle

Duration varies by programme; preparation is standard.

Application prep takes a few weeks

The obstacle description, the risk-limiting proposal and the measurement plan are a few weeks of work. You may need legal advice. The trial period is usually limited and set upfront. Ask for a duration based on your evidence needs, not your own calendar.

Duration varies by programme; preparation is standard.

The return has two layers

The first layer is the trial itself: a real-environment test under legal protection. The second is graduation: the plan targets at least a quarter of graduating projects scaling within 12 months, through licensing or public procurement. So the door is open on the way out too.

First step: write down your obstacle

Is there work you cannot do today because of regulation? If yes, write it in one sentence. If not, this programme is not for you; spend your energy at another door. Most businesses without a clear answer have simply never researched the obstacle. Sometimes what looks like a rule is only a habit.

THE

The Common Mistake

BU BÖLÜMÜN ÖZETİ

  • Mistaking the sandbox for an exemption
  • Applying before you are ready
  • Treating the regulator as an opponent and skipping the exit

Three traps.

Mistaking the sandbox for an exemption

A sandbox does not exempt you from rules; it bends them under supervision. An application going outside the scope loses its protection. Limits get written into the agreement and taken seriously. Crossing the limit ends the protection.

Applying before you are ready

A sandbox is not a place to build prototypes. It is a place to test in a real environment. An application without a working solution wastes time. Pilot in your own environment first. The sandbox is for proving in real conditions what you already know works.

Treating the regulator as an opponent and skipping the exit

A business that frames the relationship as conflict loses. The regulator also wants to learn. An application that takes their questions seriously and shares data transparently moves faster. The second omission happens at the exit. The trial succeeds but nobody thought about what comes next. Preparation for permanent authorisation, licensing or public procurement starts during the trial. Collect your evidence file with that in mind.

FREQUENTLY

Frequently Asked Questions

Sık Sorulan Sorular

Can a small software firm enter this programme?

Yes; the programme is based on sector and risk, not size. In fact small firms benefit most. A large institution has a legal team and lobbying power; a small firm has neither. The sandbox opens a door for the smaller player facing rule ambiguity. Two conditions: a working solution and a clear description of the obstacle. Both cost effort, not money.

If something goes wrong during the trial, who is responsible?

Responsibility is not removed; it is limited. That is why scope, duration and user numbers get written upfront. An incident notification process is also mandatory. What is expected of you is not hiding the problem but reporting it fast. A business that reports transparently keeps its protection and gains trust for the next application.

Our sector is not on the priority list. What should we do?

The programme starts with five priority areas, but the scope is expected to widen over time. Meanwhile, put your obstacle in writing. The plan also says that regulatory obstacles will be collected through direct applications and brought to the agenda by the Programme Office. So reporting your obstacle is itself a channel. An unreported obstacle enters nobody’s agenda.

Bu Konuyla İlgili Diğer İçerikler

TREN