Straven Co

A Straven Institute article · 2 min read · 2026

Regulatory sandboxes for AI (US federal push, MHRA AI Airlock)

More from the Institute: The current body of work

Title: Regulatory Sandboxes for AI: A False Sense of Security for Buyers in Regulated Industries

Regulatory sandboxes, now a US federal push and part of the UK’s MHRA AI Airlock, are designed to facilitate innovation while maintaining safety and trust. This development may seem like a step forward for buyers of AI solutions in regulated industries such as healthcare, insurance, and financial services in Canada and the UK. However, it actually creates a false sense of security by lowering entry barriers for vendors, leading to an influx of under-validated tools reaching buyers.

The primary concern for these organisations is capability risk – does the technology do what was promised? The answer may seem straightforward, but it’s not when regulators start asking questions. AI solutions can make confident claims, which buyers must independently verify before committing resources and reputation to them. Unfortunately, many buyers lack the expertise or resources to perform such testing, making them vulnerable to buying technology that does not meet their needs.

A second concern is governance risk – can the decision be defended when boards or regulators ask? The regulatory sandbox may ease vendor entry, but it increases the complexity of AI adoption for buyers. This raises questions about the accountability of organisations for what their AI does and says, making it crucial to ensure that these solutions align with existing governance obligations.

The third concern is liability risk – what is an organisation accountable for when the AI errs? As AI becomes more integrated into decision-making processes, organisations must consider potential liabilities resulting from AI errors. A regulatory sandbox may not be enough to mitigate this risk; independent validation of AI capabilities is essential to ensure accountability.

To navigate these risks, prudent organisations should take several steps:

1. Conduct a thorough review of the vendor’s claims and ensure that their AI solution aligns with existing governance obligations.
2. Develop an internal team or external partner with expertise in AI to validate the technology before deployment.
3. Establish clear guidelines for AI use cases and decision-making processes.

Straven & Co, an independent AI validation firm, helps organisations like yours navigate these risks by examining AI decisions before they are acted upon. Through a thorough assessment of the proposed solution against your operations, people, governance obligations, and legal exposure, we deliver a plain verdict – proceed, proceed with conditions, or do not. Our independence ensures that our judgment can be trusted, as we have no product to sell and earn nothing by recommending more.

Straven & Co examines AI decisions before they are acted on: https://stravenandco.com