Pith. sign in

REVIEW 2 major objections 4 minor 1 cited by

The paper argues that standardised AI technical sandboxes are the missing micro-foundation for regulatory learning under the EU AI Act.

Reviewed by Pith at T0; open to challenge. T0 means a machine referee read the full paper against a public rubric. the ladder, T0–T4 →

T0 review · deepseek-v4-flash

2026-08-03 12:04 UTC pith:WBVVXBB7

load-bearing objection A genuinely useful analytical mapping of the AI Act's learning space, but the central claim that technical sandboxes are the missing micro-foundation rests on an engineering assumption the paper itself concedes is open. the 2 major comments →

arxiv 2601.04094 v3 pith:WBVVXBB7 submitted 2026-01-07 cs.CY

Bathtubs, Boundaries, and Sandboxes: AI Regulatory Learning under Legal Uncertainty

classification cs.CY
keywords regulatory learningEU AI ActAI technical sandboxesColeman's bathtubmeso-level governancesemantic interoperabilitymachine-readable evidenceadaptive regulation
verification ladder T0 review T1 audit T2 compute T3 formal T4 reserved

The pith

A machine-rendered reading of the paper's core claim, the machinery that carries it, and where it could break.

The paper argues that the EU AI Act's ability to learn and adapt depends on reliable evidence flowing from individual AI developers up to the European Commission, and that the missing piece is a shared technical assessment infrastructure. It models the Act's governance as a three-level 'bathtub'—micro, meso, macro—and identifies AI Technical Sandboxes as the engine that generates comparable, machine-readable evidence at the micro level. The paper claims that if these sandboxes are built with a common specification language, a shared data model, standardised tool documentation, and a reference ontology of metrics, then scattered compliance testing can be aggregated into regulatory signals. This matters because, without that micro-foundation, legal uncertainty persists and the Act's adaptive mechanisms—reviews, standards, and codes of practice—cannot be fed with the evidence they need.

Core claim

The paper's central claim is that AI Technical Sandboxes (AITSes)—technical environments for assessing accuracy, robustness, and bias—are the missing micro-foundation of EU AI Act learning. Using Coleman's bathtub model of social learning, extended with a meso level, the paper maps how macro-level legal pressure reaches micro-level developers and how evidence should flow back up. It argues that this upward flow currently breaks: evidence is heterogeneous, manual, and non-comparable, so meso actors cannot aggregate it into signals the Commission could use to amend the Act, adopt delegated acts, or shape standards. AITSes are proposed as the standardised, reproducible environments that generat

What carries the argument

The argument runs through Coleman's bathtub—macro-to-micro enforcement and micro-to-macro evidence aggregation—extended with an explicit meso layer of intermediary actors such as national authorities, advisory bodies, and standardisation groups. Within that architecture, AI Technical Sandboxes act as boundary negotiating artifacts: the technical infrastructure that translates abstract legal requirements into operational assessment practice. Their load-bearing components are a domain-specific language for structuring assessment logic, an internal unified data model for storing heterogeneous results, standardised documentation of assessment tools, and a reference ontology of metrics to fix the

Load-bearing premise

The central mechanism assumes that micro-level assessment evidence, once encoded in a shared specification language and ontology, stays semantically faithful and comparable across different sandbox instances; the paper itself flags this as unresolved.

What would settle it

Run the same high-risk AI system through two independently built sandboxes that both use the proposed DSL, unified data model, and reference ontology, then compare outputs: if the resulting evidence requires substantial human re-interpretation or diverges on the same metric, the claim that AITSes provide a scalable micro-foundation is falsified. A simpler test is to collect real sandbox reports and check whether identical metric names map to identical mathematical definitions.

Watch this falsifier — get emailed when new claim-graph text bears on it.

If this is right

  • If AITSes adopt the proposed machine-readable formats, the three compliance pathways in the Act—self-assessment, AI regulatory sandboxes, and notified-body conformity assessment—produce comparable evidence rather than isolated reports.
  • Meso-level actors can aggregate this evidence into structured feedback, reducing the manual burden of interpreting text-based compliance documents.
  • The European Commission can use aggregated sandbox evidence to decide which standards deserve legal force, design codes of practice, and target amendments of the AI Act, closing the loop from micro-level experience to macro-level adaptation.
  • Because evidence is normalised at the source, smaller providers gain a lower-cost route to demonstrate compliance and contribute to standard-setting, partially countering the resource advantages of large firms.
  • The same assessment infrastructure can extend beyond the EU via the Brussels effect, potentially shaping how other jurisdictions collect regulatory evidence.

Where Pith is reading between the lines

These are editorial extensions of the paper, not claims the author makes directly.

  • If legal uncertainty is, as the paper says, partly productive as a space for negotiating socio-technical meaning, then the push for a reference ontology of metrics could backfire by freezing contested definitions too early; the paper's own caution about overly granular thresholds points in this direction.
  • A direct test of the framework would be to run the same AI system through two independent sandboxes using the proposed DSL and ontology and measure whether the resulting evidence is comparable without human re-interpretation.
  • The bathtub model, once articulated for the AI Act, applies naturally to other adaptive regulations; the same micro/meso/macro decomposition could expose missing evidence infrastructure in data protection or digital services law.
  • The argument implies that regulators should invest in standardising the semantic meaning of metrics now, in parallel with technical standardisation, rather than waiting for harmonised standards to settle first.

Editorial analysis

A structured set of objections, weighed in public.

Desk editor's note, referee report, simulated authors' rebuttal, and a circularity audit.

Referee Report

2 major / 4 minor

Summary. The paper proposes a theoretical model of the EU AI Act's regulatory learning space, using Coleman's bathtub with an added meso level. It maps actors (Commission, AI Office, AI Board, national authorities, notified bodies, providers/deployers) to micro, meso, and macro levels and distinguishes enforcement and evidence-aggregation flows. The central claim is that AI Technical Sandboxes (AITSes)—a technical layer distinct from AI Regulatory Sandboxes (AIRS)—are the 'missing micro-foundation' that generates the evidence needed for scalable regulatory learning. The paper identifies three assessment scenarios (self-assessment, AIRS engagement, notified-body conformity assessment) and proposes four infrastructural requirements: a domain-specific language (DSL), an internal unified data model, standardised assessment-tool documentation, and a reference ontology of metrics. It concludes with a discussion of socio-political limitations.

Significance. If the central claim is accepted, the paper would provide a useful framework for designing technical sandbox infrastructure and a systematic mapping of the AI Act's learning pathways. The actor-level decomposition (Table 1, Figure 1) is careful and well-grounded in the AI Act; the AIRS/AITS distinction is analytically helpful. The paper also candidly discusses political risks such as regulatory capture and incentives for data sharing. However, the necessity claim that AITSes are essential for regulatory learning is not empirically demonstrated; it is a conjecture that depends on the resolution of the semantic-interoperability problem the paper itself identifies in Section 4. The value is thus primarily conceptual, and the contribution would be strengthened by softening the claim or providing a proof-of-concept.

major comments (2)
  1. [Section 4, 'Reference Ontology of Metrics'] The central micro-macro evidence-aggregation mechanism requires that assessment data from different sandbox instances be semantically comparable. The paper concedes: 'Without this semantic layer, the DSL remains susceptible to interpretation errors across different sandbox instances; for example, if the same metric name is instantiated with divergent mathematical definitions, the resulting evidence becomes incomparable.' The proposed remedy—a reference ontology—is not developed: the paper states that 'the proposed ontologies remain high-level... with a closer link to operational technical requirements still missing,' and Section 6 defers implementation to future work. This is not a peripheral caveat; it is the load-bearing premise for the claim that AITSes are the 'missing micro-foundation.' Unless the ontology is specified or a feasibility argument is provided, the aggregation story rem
  2. [Section 3.2 and Conclusion] The paper asserts that AITSes are 'the essential engine' and 'the missing micro-foundation' for regulatory learning, but the necessity claim is not supported. In the self-assessment scenario, the paper allows that an SME may conduct conformity assessment without an AITS; the argument that a 'consistent, reproducible methodology' requires AITSes is asserted rather than derived from the AI Act or from empirical evidence. The paper also does not consider alternative mechanisms for achieving standardization, such as mandating common machine-readable reporting formats through implementing acts (which Article 43 and Annex VI could enable). To be persuasive, the paper should either demonstrate that existing instruments are insufficient or explicitly present AITSes as one possible (rather than the necessary) technical solution. As it stands, the central contribution overreaches its evidence.
minor comments (4)
  1. [Section 1, first paragraph] 'imposesex-ante' is missing a space; should be 'imposes ex-ante'.
  2. [Section 2.1, paragraph 2] 'themesolevel' should be 'the meso level'.
  3. [Section 4, 'Extensible Formal Configuration Language'] The DSL from [16] is not described in sufficient detail for readers unfamiliar with that prior work. A brief summary (e.g., its core and sector-specific extension layers) would improve accessibility and make the proposal more self-contained.
  4. [Figure 1] The figure is dense and the arrow types are not explained in the caption. A short legend or a sentence in the text describing the meaning of the arrows would help readers follow the flow.

Circularity Check

0 steps flagged

No significant circularity; only a minor non-load-bearing self-citation of the authors' own DSL proposal.

full rationale

The paper is a conceptual and architectural analysis rather than a fitted or predictive derivation. It maps the AI Act's actors onto Coleman's bathtub, identifies three assessment scenarios from Articles 43 and 57, and argues that AI Technical Sandboxes (AITSes) are the micro-level evidence generator needed for regulatory learning. That conclusion is analytic given the paper's own definitions (an AITS is 'a technical environment designed to evaluate system properties such as accuracy, robustness, cybersecurity, energy efficiency, transparency, and bias'); it does not arise from fitting parameters, from an equation that is equivalent to its own inputs, or from a uniqueness theorem. The only self-citation of note is in Section 4, where the Domain-Specific Language from the authors' prior work [16] is recommended as the syntactic core of AITSes. This is a design input, not evidence for the central claim, and the paper explicitly flags the unresolved semantic interoperability prerequisite: 'Without this semantic layer, the DSL remains susceptible to interpretation errors across different sandbox instances.' It also defers implementation to future work in Section 6. These limitations weaken the operational claim but do not make the argument circular. Score 2 reflects one minor self-citation that is not load-bearing.

Axiom & Free-Parameter Ledger

0 free parameters · 5 axioms · 1 invented entities

The argument rests on interpretive assumptions from policy-learning theory and on the premise that standardized technical infrastructure can solve the evidence-aggregation problem. No free parameters are fitted, but several domain assumptions are load-bearing and would need empirical validation.

axioms (5)
  • domain assumption Coleman's bathtub can be extended with an explicit meso level to model AI Act regulatory learning.
    Invoked in Section 2.1 via [29, 71] to justify the meso level; this is a modeling choice from policy learning theory, not an empirically validated property of the AI Act.
  • domain assumption The EU AI Act is intended as an adaptive, learning-oriented framework rather than a fixed command-and-control instrument.
    Section 1 and Section 2.1 characterize the Act as 'future-responsive, adaptive regulation'; this interpretive premise underlies the whole analysis.
  • domain assumption Harmonised standards for AI under the Act have not yet been approved, creating a gap in translating legal requirements.
    Section 2.1 relies on [3, 54] for the current absence of approved vertical standards; if standards were completed, the urgency and role of AITSes would change.
  • domain assumption Aggregated micro-level evidence from conformity assessments can drive macro-level regulatory learning.
    Sections 3.1 and 3.2 assume a causal chain from provider evidence through meso actors to Commission adaptation; no empirical support is provided.
  • domain assumption Machine-readable standardized reporting makes evidence comparable and enables scalable aggregation.
    Section 4 argues that DSLs, unified data models, and ontologies will resolve heterogeneity; the paper itself flags semantic interoperability as unresolved.
invented entities (1)
  • AI Technical Sandbox (AITS) as an analytically distinct technical layer separate from AI Regulatory Sandbox (AIRS) no independent evidence
    purpose: Serves as the micro-level evidence generator and technical backbone for regulatory learning under the AI Act.
    The paper defines AITS operationally and assigns it a causal role, but it is a conceptual construct with no direct falsifiable handle outside the paper; its effectiveness is not measured.

pith-pipeline@v1.3.0-alltime-deepseek · 17395 in / 8789 out tokens · 90126 ms · 2026-08-03T12:04:45.822863+00:00 · methodology

0 comments
read the original abstract

Effective regulation of AI is a defining policy challenge, driven by their integration into all aspects of society. To remain responsive to their rapid development and emergent properties, policymakers across the globe rely on high-level principles and abstract legal requirements. Yet, while this flexibility supports future-proofing human-centred regulations and aligning them with socio-ethical values, it also causes legal uncertainty downstream as developers, companies, and auditors struggle with translating these abstract requirements into verifiable technical requirements. Using the AI Act as an example, this paper draws on Coleman's bathtub to analyse the regulatory learning space in AI governance. It argues that legal uncertainty cannot be fully reduced ex ante and that, within reasonable bounds, it is also necessary for regulatory learning because it creates the space in which boundary negotiation over socio-technical meaning can occur. Building on this analysis, the paper shows how boundary objects and boundary negotiating artifacts help explain the translation of legal requirements into operational practice. By examining technical sandbox frameworks, it further identifies concrete properties that technical infrastructures must possess to function effectively as boundary negotiation artifacts in AI assessment. The paper concludes that legal certainty remains the long-term aim, but that premature closure of regulatory instruments risks undermining the learning processes needed for adaptive governance.

Figures

Figures reproduced from arXiv: 2601.04094 by Alessio Buscemi, Alfredo Capozucca, German Castignani, Marco Almada, Tom Deckenbrunnen.

Figure 1
Figure 1. Figure 1: The EU AI Act’s bathtub. the AI Act, delegated acts, or implementing acts. As the European Commission is the sole actor with the legal power to exert these adaptations, the Commission represents the macro level. In contrast to the micro and macro levels, the meso level consists of those actors who are tasked with translation of the macro-micro transition on the one hand and evidence aggregation of the micr… view at source ↗
Figure 2
Figure 2. Figure 2: The flow of information in the self-assessment by an SME. [PITH_FULL_IMAGE:figures/full_fig_p010_2.png] view at source ↗
Figure 3
Figure 3. Figure 3: Work and information flow in the AIRS scenario. [PITH_FULL_IMAGE:figures/full_fig_p010_3.png] view at source ↗

discussion (0)

Sign in with ORCID, Apple, or X to comment. Anyone can read and Pith papers without signing in.

Forward citations

Cited by 1 Pith paper

Reviewed papers in the Pith corpus that reference this work. Sorted by Pith novelty score.

  1. AI Sandboxes: A Threat Model, Taxonomy, and Measurement Framework

    cs.CR 2026-06 unverdicted novelty 5.0

    The paper presents a threat model, taxonomy, and six-dimension measurement framework for AI sandboxes to clarify valid testing claims for safety, security, and regulatory assurance.

Reference graph

Works this paper leans on

71 extracted references · 16 canonical work pages · cited by 1 Pith paper

  1. [1]

    d.].Better Regulation: Guidelines and Toolbox

    [n. d.].Better Regulation: Guidelines and Toolbox. https://commission.europa.eu/law/law-making-process/better-regulation/better-regulation- guidelines-and-toolbox_en

  2. [2]

    [n. d.]. RDF 1.1 Concepts and Abstract Syntax. https://www.w3.org/TR/rdf11-concepts/

  3. [3]

    CEN-CENELEC

    CEN-CENELEC 2025.Update on CEN and CENELEC’s Decision to Accelerate the Development of Standards for Artificial Intelligence. CEN-CENELEC. https://www.cencenelec.eu/news-events/news/2025/brief-news/2025-10-23-ai-standardization/

  4. [4]

    2024. Regulation (EU) 2024/1689 of the European Parliament and of the Council of 13 June 2024 laying down harmonised rules on artificial intelligence (Artificial Intelligence Act) and amending certain Union legislative acts. https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:32024R1689. OJ L 2024/1689, 12 July 2024

  5. [5]

    CEN-CENELEC

    CEN-CENELEC 2025.Small and Medium Enterprises (SMEs). CEN-CENELEC. https://www.cencenelec.eu/get-involved/small-and-medium- enterprises-smes/smes-and-standards/

  6. [6]

    Trump Administration. 2025. America’s AI Action Plan. https://www.whitehouse.gov/wp-content/uploads/2025/07/Americas-AI-Action-Plan.pdf AI regulatory framework emphasizing innovation, free speech, borderless open AI

  7. [7]

    Deirdre Ahern. 2021. Regulatory Lag, Regulatory Friction and Regulatory Transition as FinTech Disenablers: Calibrating an EU Response to the Regulatory Sandbox Phenomenon.European Business Organization Law Review22, 3 (2021), 395–432. doi:10.1007/s40804-021-00217-z

  8. [8]

    Deirdre Ahern. 2025. The New Anticipatory Governance Culture for Innovation: Regulatory Foresight, Regulatory Experimentation and Regulatory Learning.European Business Organization Law Review26, 2 (June 2025), 241–283. doi:10.1007/s40804-025-00348-7

  9. [9]

    Deirdre Ahern. 2025. Operationalising AI Regulatory Sandboxes under the EU AI Act: The Triple Challenge of Capacity, Coordination and Attractiveness to Providers | Cambridge Forum on AI: Law and Governance.Cambridge Core(2025), e35. doi:10.1017/cfl.2025.10023

  10. [10]

    Marco Almada and Nicolas Petit. 2025. The EU AI Act: Between the Rock of Product Safety and the Hard Place of Fundamental Rights.Common Market Law Review62, 1 (Feb. 2025), 85–120. doi:10.54648/COLA2025004

  11. [11]

    Mandepanda Sharmista Appaya, Helen Luskin Gradstein, and Mahjabeen Haji Kanz. 2020. Global experiences from regulatory sandboxes. (2020). https://documents.worldbank.org/en/publication/documentsreports/documentdetail/912001605241080935/Global-Experiences-from- Regulatory-Sandboxes

  12. [12]

    Julien Arnal. 2024. AI at Risk in the EU: It’s Not Regulation, It’s Implementation.European Journal of Risk Regulation (2024). https://www.cambridge.org/core/journals/european-journal-of-risk-regulation/article/ai-at-risk-in-the-eu-its-not-regulation-its- implementation/A9FD120F3EACE2C083048ABCBF96C0F6

  13. [13]

    2020.The Brussels Effect(1 ed.)

    Anu Bradford. 2020.The Brussels Effect(1 ed.). Oxford University PressNew York, 25–66. doi:10.1093/oso/9780190088583.003.0003

  14. [14]

    Serrano, and Eduardo Fernández-Medina

    Carlos Mario Braga, Manuel A. Serrano, and Eduardo Fernández-Medina. 2025. Towards a Methodology for Ethical Artificial Intelligence System Development: A Necessary Trustworthiness Taxonomy.Expert Systems with Applications286 (Aug. 2025), 128034. doi:10.1016/j.eswa.2025.128034 Manuscript submitted to ACM The Bathtub of European AI Governance: Identifying ...

  15. [15]

    Ullman, Fernando Martinez-Plumed, Joshua B

    Ryan Burnell, Wout Schellaert, John Burden, Tomer D. Ullman, Fernando Martinez-Plumed, Joshua B. Tenenbaum, Danaja Rutar, Lucy G. Cheke, Jascha Sohl-Dickstein, Melanie Mitchell, Douwe Kiela, Murray Shanahan, Ellen M. Voorhees, Anthony G. Cohn, Joel Z. Leibo, and Jose Hernandez-Orallo

  16. [16]

    Alessio Buscemi, Thibault Simonetto, Daniele Pagani, German Castignani, Maxime Cordy, and Jordi Cabot. 2025. The Sandbox Configurator: A Framework to Support Technical Assessment in AI Regulatory Sandboxes. arXiv:2509.25256 [cs.CY] https://arxiv.org/abs/2509.25256

  17. [17]

    Andrea Campagner, Riccardo Angius, and Federico Cabitza. 2023. A Question of Trust: Old and New Metrics for the Reliable Assessment of Trustworthy AI:. InProceedings of the 16th International Joint Conference on Biomedical Engineering Systems and Technologies. SCITEPRESS - Science and Technology Publications, Lisbon, Portugal, 132–143. doi:10.5220/0011679...

  18. [18]

    Celso Cancela-Outeda. 2024. The EU’s AI Act: A Framework for Collaborative Governance.Internet of Things27 (2024), 101291. doi:10.1016/j.iot. 2024.101291

  19. [19]

    Samuel Carey. 2025. Regulating Uncertainty: Governing General-Purpose AI Models and Systemic Risk.European Journal of Risk Regulation (2025). https://resolve.cambridge.org/core/journals/european-journal-of-risk-regulation/article/regulating-uncertainty-governing-generalpurpose- ai-models-and-systemic-risk/7EEFE1D8421A43A98CE91F7C697DE538

  20. [20]

    Albana Celepija, Alessio Palmero Aprosio, Bruno Lepri, and Raman Kazhamiakin. 2025. AI Product Cards: A Framework for Code-Bound Formal Documentation Cards in the Public Administration.Data & Policy7 (Jan. 2025), e1. doi:10.1017/dap.2024.55

  21. [21]

    Xuechen Chen and Lu Xu. 2025. State, Society, and Market: Interpreting the Norms and Dynamics of China’s AI Governance.Computer Law & Security Review59 (Nov. 2025), 106206. doi:10.1016/j.clsr.2025.106206

  22. [22]

    James S. Coleman. 1986. Social Theory, Social Research, and a Theory of Action.Amer. J. Sociology91, 6 (1986), 1309–1335. jstor:2779798

  23. [23]

    European Commission. 2025. Draft Commission Implementing Regulation Laying down Rules for the Application of Regulation (EU) 2024/1689 of the European Parliament and of the Council as Regards the Establishment, Development, Implementation, Operation and Supervision of AI Regulatory Sandboxes. https://digital-strategy.ec.europa.eu/en/consultations/commissi...

  24. [24]

    Ben Crum. 2025. Brussels Effect or Experimentalism? The EU AI Act and Global Standard-Setting.Internet Policy Review14, 3 (2025). doi:10.14763/ 2025.3.2032

  25. [25]

    de Carvalho, João Paulo A

    Victorio A. de Carvalho, João Paulo A. Almeida, and Giancarlo Guizzardi. 2014. Using Reference Domain Ontologies to Define the Real-World Semantics of Domain-Specific Languages. InAdvanced Information Systems Engineering, Matthias Jarke, John Mylopoulos, Christoph Quix, Colette Rolland, Yannis Manolopoulos, Haralambos Mouratidis, and Jennifer Horkoff (Eds...

  26. [26]

    Deloitte. 2024. EU AI Act Survey: Uncertainty in Implementation.Deloitte Legal Research(2024). https://www.deloitte.com/dl/en/services/legal/ research/umfrage-eu-ai-act-2024.html

  27. [27]

    Daan Di Scala, Sophie Lathouwers, and Michael van Bekkum. 2025. Bridging the AI Trustworthiness Gap between Functions and Norms. doi:10.48550/ARXIV.2512.20671

  28. [28]

    Mario Draghi. 2024. EU Competitiveness Report (Draghi Report). https://sciencebusiness.net/news/ai/eu-losing-narrative-battle-over-ai-act-says- un-adviser

  29. [30]

    Martin Ebers. 2025. Truly Risk-based Regulation of Artificial Intelligence How to Implement the EU’s AI Act.European Journal of Risk Regulation16, 2 (June 2025), 684–703. doi:10.1017/err.2024.78

  30. [31]

    European Commission. 2025. Guidelines on the definition of an artificial intelligence system established by Regulation (EU) 2024/1689 (AI Act). C(2025) 924 final. https://digital-strategy.ec.europa.eu/en/library/commission-publishes-guidelines-ai-system-definition-facilitate-first-ai-acts- rules-application Accessed: 2025-12-31

  31. [32]

    2025.Guidelines on the definition of an artificial intelligence system established by Regulation (EU) 2024/1689 (AI Act)

    European Commission. 2025.Guidelines on the definition of an artificial intelligence system established by Regulation (EU) 2024/1689 (AI Act). Technical Report C(2025) 924 final ANNEX. European Union. https://digital-strategy.ec.europa.eu/en/library/commission-publishes-guidelines-ai-system- definition-facilitate-first-ai-acts-rules-application

  32. [33]

    Directorate General for Parliamentary Research Services

    European Parliament. Directorate General for Parliamentary Research Services. 2018.EU Agencies, Common Approach and Parliamentary Scrutiny. Publications Office. https://data.europa.eu/doi/10.2861/656418

  33. [34]

    2025.EU Regulatory Sandboxes for AI (EUSAiR) Roadmap

    EUSAiR Consortium. 2025.EU Regulatory Sandboxes for AI (EUSAiR) Roadmap. Project Deliverable. EUSAiR Project. https://eusair-project.eu/app/ uploads/2025/04/EUSAIR_RoadMap_v1_final.pdf

  34. [35]

    Financial Conduct Authority. 2017. Regulatory sandbox lessons learned report. (2017). https://www.fca.org.uk/publication/research-and- data/regulatory-sandbox-lessons-learned-report.pdf

  35. [36]

    Financial Times. 2025. European CEOs urge Brussels to halt landmark AI Act.Financial Times(3 July 2025). https://www.ft.com/content/a825759e- aec8-4184-bc73-f604f169204c

  36. [37]

    Timnit Gebru, Jamie Morgenstern, Briana Vecchione, Jennifer Wortman Vaughan, Hanna Wallach, Hal Daumé, and Kate Crawford. 2021. Datasheets for Datasets. arXiv:1803.09010 [cs] doi:10.48550/arXiv.1803.09010

  37. [38]

    2024.From Blueprint to Reality: Implementing AI REgulatory Sandboxes under the AI Act

    Nathan Genicot. 2024.From Blueprint to Reality: Implementing AI REgulatory Sandboxes under the AI Act. Technical Report. FARI & LSTS Research Group (VUB), Brussels. Manuscript submitted to ACM The Bathtub of European AI Governance: Identifying Technical Sandboxes as the Micro-Foundation of Regulatory Learning 17

  38. [39]

    Nathan Genicot and Thiago Guimaraes Moraes. 2025. Exploring the Boundaries of AI Regulatory Sandboxes under the AI Act: Flexibility and Real-World Testing.Cambridge Forum on AI: Law and Governance1 (Jan. 2025), e36. doi:10.1017/cfl.2025.10013

  39. [40]

    Ahmad Ghazawneh and Ola Henfridsson. 2013. Balancing Platform Control and External Contribution in Third-Party Development: The Boundary Resources Model.Information Systems Journal23, 2 (2013), 173–192. doi:10.1111/j.1365-2575.2012.00406.x

  40. [41]

    Pandit, Sven Schade, Declan O’Sullivan, and Dave Lewis

    Delaram Golpayegani, Isabelle Hupont, Cecilia Panigutti, Harshvardhan J. Pandit, Sven Schade, Declan O’Sullivan, and Dave Lewis. 2024. AI Cards: Towards an Applied Framework for Machine-Readable AI and Risk Documentation Inspired by the EU AI Act. InPrivacy Technologies and Policy: 12th Annual Privacy Forum, APF 2024, Karlstad, Sweden, September 4–5, 2024...

  41. [42]

    Pandit, and Dave Lewis

    Delaram Golpayegani, Harshvardhan J. Pandit, and Dave Lewis. 2022. AIRO: An Ontology for Representing AI Risks Based on the Proposed EU AI Act and ISO Risk Management Standards. InTowards a Knowledge-A ware AI. IOS Press, 51–65. doi:10.3233/SSW220008

  42. [43]

    Mélanie Gornet and Winston Maxwell. 2024. The European Approach to Regulating AI through Technical Standards.Internet Policy Review13, 3 (July 2024). doi:10.14763/2024.3.1784

  43. [44]

    2025.Interplay between the AI Act and the EU Digital Legislative Framework

    Hans Graux, Krzysztof Garstka, and Nayana Murali. 2025.Interplay between the AI Act and the EU Digital Legislative Framework. Technical Report. Policy Department for Transformation, Innovation and Health Directorate-General for Economy, Transformation and Industry

  44. [45]

    Gstrein, Noman Haleem, and Andrej Zwitter

    Oskar J. Gstrein, Noman Haleem, and Andrej Zwitter. 2024. General-Purpose AI Regulation and the European Union AI Act.Internet Policy Review 13, 3 (Aug. 2024). doi:10.14763/2024.3.1790

  45. [46]

    Julio Hernandez, Delaram Golpayegani, and Dave Lewis. 2025. An Open Knowledge Graph-Based Approach for Mapping Concepts and Requirements between the EU AI Act and International Standards.AI and Ethics5, 5 (Oct. 2025), 4463–4474. doi:10.1007/s43681-025-00708-6

  46. [47]

    Ari Holtzman, Peter West, and Luke Zettlemoyer. 2025. Generative Models as a Complex Systems Science: How Can We Make Sense of Large Language Model Behavior?Journal of Social Computing6, 2 (June 2025), 75–94. doi:10.23919/JSC.2025.0009

  47. [48]

    Chawla, Jian Pei, Jianfeng Gao, Michael Backes, Philip S

    Yue Huang, Chujie Gao, Siyuan Wu, Haoran Wang, Xiangqi Wang, Yujun Zhou, Yanbo Wang, Jiayi Ye, Jiawen Shi, Qihui Zhang, Yuan Li, Han Bao, Zhaoyi Liu, Tianrui Guan, Dongping Chen, Ruoxi Chen, Kehan Guo, Andy Zou, Bryan Hooi Kuen-Yew, Caiming Xiong, Elias Stengel-Eskin, Hongyang Zhang, Hongzhi Yin, Huan Zhang, Huaxiu Yao, Jaehong Yoon, Jieyu Zhang, Kai Shu,...

  48. [49]

    Isabelle Hupont, David Fernández-Llorca, Sandra Baldassarri, and Emilia Gómez. 2024. Use Case Cards: A Use Case Reporting Framework Inspired by the European AI Act.Ethics and Information Technology26, 2 (March 2024), 19. doi:10.1007/s10676-024-09757-7

  49. [50]

    Ronald Jepperson and John W. Meyer. 2011. Multiple Levels of Analysis and the Limitations of Methodological Individualisms. 29, 1 (2011), 54–73. doi:10.1111/j.1467-9558.2010.01387.x

  50. [51]

    Robert Kilian, Linda Jäck, and Dominik Ebel. 2025. European AI Standards – Technical Standardisation and Implementation Challenges under the EU AI Act.European Journal of Risk Regulation16, 3 (Sept. 2025), 1038–1062. doi:10.1017/err.2025.10032

  51. [52]

    Noam Kolt, Michal Shur-Ofry, and Reuven Cohen. 2025. Lessons from Complex Systems Science for AI Governance.Patterns6, 8 (Aug. 2025), 101341. doi:10.1016/j.patter.2025.101341

  52. [53]

    Dave Lewis, Maria Lasek-Markey, Donya Golpayegani, and Harshvardhan J. Pandit. 2025. Mapping the Regulatory Learning Space for the EU AI Act. arXiv preprint arXiv:2503.05787. https://arxiv.org/abs/2503.05787

  53. [54]

    Andrew Leyden. 2025. Standards and the EU AI Act: Legitimacy, State of Play, and Future Challenges.Information & Communications Technology Law0, 0 (Oct. 2025), 1–31. doi:10.1080/13600834.2025.2570966

  54. [55]

    Marjan Mernik, Jan Heering, and Anthony M. Sloane. 2005. When and How to Develop Domain-Specific Languages.Comput. Surveys37, 4 (Dec. 2005), 316–344. doi:10.1145/1118890.1118892

  55. [56]

    Thomas Metcalf. 2025. AI Safety and Regulatory Capture.AI & SOCIETY(Aug. 2025). doi:10.1007/s00146-025-02534-0

  56. [57]

    Krzysztof Miksa, Pawel Sabina, and Marek Kasztelnik. 2010. Combining Ontologies with Domain Specific Languages: A Case Study from Network Configuration Software. InReasoning Web. Semantic Technologies for Software Engineering: 6th International Summer School 2010, Dresden, Germany, August 30 - September 3, 2010. Tutorial Lectures, Uwe Aßmann, Andreas Bart...

  57. [58]

    Margaret Mitchell, Simone Wu, Andrew Zaldivar, Parker Barnes, Lucy Vasserman, Ben Hutchinson, Elena Spitzer, Inioluwa Deborah Raji, and Timnit Gebru. 2019. Model Cards for Model Reporting. InProceedings of the Conference on Fairness, Accountability, and Transparency. ACM, Atlanta GA USA, 220–229. doi:10.1145/3287560.3287596

  58. [59]

    Stéphane Moyson, Peter Scholten, and Christopher M Weible. 2017. Policy Learning and Policy Change: Theorizing Their Relations from Different Perspectives.Policy and Society36, 2 (2017), 161–177. doi:10.1080/14494035.2017.1331879

  59. [60]

    Jessica Newman. [n. d.]. A Taxonomy of Trustworthiness for Artificial Intelligence. ([n. d.])

  60. [61]

    Claudio Novelli, Philipp Hacker, Jessica Morley, Jarle Trondal, and Luciano Floridi. 2025. A Robust Governance for the AI Act: AI Office, AI Board, Scientific Panel, and National Authorities.European Journal of Risk Regulation16, 2 (2025), 566–590. doi:10.1017/err.2024.57 Manuscript submitted to ACM The Bathtub of European AI Governance: Identifying Techn...

  61. [62]

    2025.Regulatory Sandbox Toolkit

    Organisation for Economic Co-operation and Development (OECD). 2025.Regulatory Sandbox Toolkit. Technical Report. https://www.oecd.org/ content/dam/oecd/en/publications/reports/2025/06/regulatory-sandbox-toolkit_cc8d3e50/de36fa62-en.pdf

  62. [63]

    Papazoglou

    M.P. Papazoglou. 2003. Service-Oriented Computing: Concepts, Characteristics and Directions. InProceedings of the Fourth International Conference on Web Information Systems Engineering, 2003. WISE 2003.3–12. doi:10.1109/WISE.2003.1254461

  63. [64]

    DLA Piper. 2025. The European Commission Considers Pause on AI Act’s Entry into Application.AI Outlook Report(2025). https://www.dlapiper. com/en/insights/publications/ai-outlook/2025/the-european-commission-considers-pause-on-ai-act-entry-into-application

  64. [65]

    Lavista Ferres

    Anthony Cintron Roman, Jennifer Wortman Vaughan, Valerie See, Steph Ballard, Jehu Torres, Caleb Robinson, and Juan M. Lavista Ferres. 2024. Open Datasheets: Machine-readable Documentation for Open Datasets and Responsible AI Assessments. arXiv:2312.06153 [cs] doi:10.48550/arXiv. 2312.06153

  65. [66]

    Hannah Ruschemeier. 2025. Experimental Regulation for AI Governance with Regulatory Sandboxes.Cambridge Forum on AI: Law and Governance 1 (Jan. 2025), e38. doi:10.1017/cfl.2025.10035

  66. [67]

    Thibault Schrepel. 2025. Adaptive Regulation. social science research network:5416454 doi:10.2139/ssrn.5416454

  67. [68]

    Michael Veale and Frederik Zuiderveen Borgesius. 2021. Demystifying the Draft EU Artificial Intelligence Act. social science research network:3896852

  68. [69]

    Koen Verhoest. 2018. Agencification in Europe. InThe Palgrave Handbook of Public Administration and Management in Europe, Edoardo Ongaro and Sandra Van Thiel (Eds.). Palgrave Macmillan UK, 327–346. doi:10.1057/978-1-137-55269-3_17

  69. [70]

    Welch, Hallie Eakin, Nadine Methner, Yamini Yogya, and Jinghuan Ma

    Eric W. Welch, Hallie Eakin, Nadine Methner, Yamini Yogya, and Jinghuan Ma. 2025. Conceptualizing Meso-Level Organizations and Their Relations to Catalyze Transformative Climate Adaptation.WIREs Climate Change16, 6 (2025), e70034. doi:10.1002/wcc.70034

  70. [71]

    Bishoy Zaki. 2025. Conceptualising Organisational Policy Learning: Triggers, Processes, Outcomes, and Implications for Policy and Governance Change.Australian Journal of Public Administration(Nov. 2025). doi:10.1111/1467-8500.70031 Manuscript submitted to ACM

  71. [2023]

    doi:10.1126/science.adf6369

    Rethink Reporting of Evaluation Results in AI.Science380, 6641 (April 2023), 136–138. doi:10.1126/science.adf6369