EU AI Act Art. 60: testing in real-world conditions outside sandboxes
Testing of high-risk (Annex III) AI systems in real-world conditions outside AI regulatory sandboxes
AIGE-OBL-EUAIA-ART60. Drawn from chapter 08.
Text alternative
- Clause: EU AI Act, Art. 60.
- Duty holder: Provider / prospective provider.
- Applies from: 2026-08-02, In force.
- Artefact: Real-world testing plan.
- Layers: Layer 03, Layer 04.
- Evidence record: Test plan.
- Record schemas: Test plan .
- The same topic in 19 other frameworks; the crosswalk section below links each clause.
- Id
AIGE-OBL-EUAIA-ART60- Instrument
- EU AI Act (post-Omnibus) law
- Compared side by side
- ISO 42001 vs EU AI Act · NIST AI RMF vs EU AI Act
- Clause
- Art. 60
- Duty holder
- Provider / prospective provider
- Authority
- National MSA
- Applies from
- In force
- System class
- High-risk (Annex III)
The artefact that evidences it
Real-world testing plan; Art. 61 informed-consent records; test monitoring, logging and incident hooks.
Patterns that build it
- Staged Rollout with Rollback Criteria (layer 4)
The same topic in other frameworks
From the topic crosswalk: the clauses filed under the same topics as this one. Mappings are illustrative, not a claim of conformity.
Robustness, security and evaluations
- EU AI Act Art. 15 Accuracy, robustness and cybersecurity (core)
- EU AI Act Art. 55 Obligations for providers of general-purpose AI models with systemic risk (core)
- ISO 42001 A.6 AI system life cycle (core)
- NIST AI RMF MEASURE 2 MEASURE 2: AI systems are evaluated for trustworthy characteristics (core)
- TC260 Framework 3.0 TC260 3 Technological countermeasures (core)
- TC260 Framework 3.0 TC260 App. 2 II.6 Sandbox validation and red teaming (core)
- China Deep Synthesis DeepSyn Art. 15 Technology management and algorithm verification (core)
- China Deep Synthesis DeepSyn Art. 20 Security assessment of new products (core)
- GB/T 45654 GB/T 45654 Security assessment Security-assessment requirements for generative AI services (core) (clause not verified)
- GPAI Code Safety 3.2 Measure 3.2: Model evaluations (core)
- NIST AI RMF MEASURE 2.7 MEASURE 2.7: AI system security and resilience as identified in the MAP function are evaluated and documented (core)
- CSA AICM MDS-06 Adversarial Attack Analysis (core)
- CSA AICM MDS-07 Robustness against Adversarial Attack / Model Hardening (core)
- Singapore GenAI GenAI 5 Testing and Assurance (core)
- Singapore GenAI GenAI 6 Security (core)
- Singapore Agentic Agentic 2.3.2 Before deploying, test agents (core)
- CoE Convention CoE Art. 16(2)(g) Testing before first use and when significantly modified (core)
- OECD AI Principles OECD 1.4 Robustness, security and safety (core)
- G7 Code G7 Action 1 Identify, evaluate and mitigate risks across the lifecycle, including testing (core)
- GAO AI Accountability 3.7 Assessment: assess performance against defined metrics to ensure the AI system functions as intended and is sufficiently robust (core)
- ISO 42001 9.1 Monitoring, measurement, analysis and evaluation
- TC260 Framework 3.0 TC260 5.3.14 Resilience
- China GenAI Measures GenAI Art. 17 Security assessment
- EU AI Act Art. 15(3) Declared accuracy levels and metrics
- EU AI Act Art. 9 Risk management system
- EU AI Act Art. 42(3) Presumption of conformity for cybersecurity (Cyber Resilience Act)
- GPAI Code Safety C6 Commitment 6: Security mitigations
- GDPR Art. 32 Security of processing
- NIST AI RMF MEASURE 2.1 MEASURE 2.1: Test sets, metrics, and details about the tools used during TEVV are documented
- NIST AI RMF MEASURE 1 MEASURE 1: Appropriate methods and metrics are identified and applied
- CSA AICM AIS-05 Application Security Testing
- OWASP LLM LLM01:2026 Prompt Injection
- OWASP Agentic ASI05 Unexpected Code Execution (RCE)
- Korea AI Act Art. 32(1) Safety duties for AI above the compute threshold
- GAO AI Accountability 3.2 Metrics: define performance metrics that are precise, consistent, and reproducible
Sandboxes and real-world testing
- EU AI Act Art. 57 AI regulatory sandboxes (core)
- CoE Convention CoE Art. 13 Safe innovation (controlled testing environments) (core)
- EU AI Act Art. 58 Detailed arrangements for, and functioning of, AI regulatory sandboxes
- EU AI Act Art. 59 Further processing of personal data in the AI regulatory sandbox
- EU AI Act Art. 61 Informed consent to participate in testing in real world conditions
- ISO 42001 A.6.2.4 AI system verification and validation (clause not verified)
- NIST AI RMF MEASURE 2.3 MEASURE 2.3: AI system performance or assurance criteria are measured qualitatively or quantitatively and demonstrated for conditions similar to deployment setting(s)
- CSA AICM AIS-13 AI Sandboxing
- Singapore Agentic Agentic 2.3.2 Before deploying, test agents
- TC260 Framework 3.0 TC260 App. 2 II.6 Sandbox validation and red teaming
Source
Chapter 08, section EU AI Act, post-Omnibus, checked against its sources on the review date above.
Machine-readable
- This obligation:
/api/v1/obligations/aige-obl-euaia-art60.json - The register:
/api/v1/obligations.json· CSV - Schema and stability promise: open data and API
Cite this obligation
García Aibar, J. (2026). EU AI Act Art. 60: testing in real-world conditions outside sandboxes (AIGE-OBL-EUAIA-ART60). In AI Governance Engineering: The Thesis & Body of Knowledge (v0.5.0). https://doi.org/10.5281/zenodo.22956197. https://aigovernanceengineer.com/obligations/aige-obl-euaia-art60. CC BY 4.0
BibTeX
@misc{aige2026obligation,
author = {Jorge García Aibar},
title = {{EU AI Act Art. 60: testing in real-world conditions outside sandboxes (AIGE-OBL-EUAIA-ART60)}},
howpublished = {In AI Governance Engineering: The Thesis \& Body of Knowledge},
year = {2026},
version = {0.5.0},
doi = {10.5281/zenodo.22956197},
url = {https://aigovernanceengineer.com/obligations/aige-obl-euaia-art60},
note = {Version 0.5.0}
}