Open-source software for EU AI Act Article 57 sandboxes
Sandbox testing you can defend.
Test a high-risk AI system at your own HPC centre without anyone handing over the model or the data, and keep evidence a notified body can re-check offline.
Histor is for the authorities and agencies that must run a regulatory sandbox by 2 August 2027, for the engineers who have to stand behind its results, and for the HPC centres and AI Factories that host the tests. Open source, EUPL-1.2.
Every Member State must have at least one operational sandbox.
High-risk obligations apply; providers will want tested results before then.
Tells authorities to use AI Factories and supervise projects run there.
Why testing
Sandboxes so far gave advice. The next ones have to test.
The sandbox reports published to date describe regulatory dialogue and written guidance. Germany's pilot ran no technical tests, because no lawful test data was available. Providers will not hand over a model, and personal test data cannot move freely under the GDPR.
Histor is built for the test itself. It runs at the host the authority already has access to, so that neither the model nor the data has to leave its owner, and the authority ends up holding evidence it can defend to a notified body.
See for yourself
Four things you can check today
- The 3-minute film
- One supervised test run on a cluster, silent and captioned.
- The read-only console
- Click through a supervised run as the authority sees it.
- The offline verifier
- Run it on the sample bundle, on your own machine, with no network and no account.
- The Configurator plug-in
- Posts a verified result into the Luxembourg AI Factory's Sandbox Configurator.
How it works
One test run, in six steps
The provider brings a model, the authority brings a signed test plan, and the host runs the test.
Both sides sign the test plan.
The authority and the provider sign the model digest, the sealed test set, the tests, the thresholds and the number of runs before anything runs. A run that cites an unsigned plan is refused.
The model runs isolated, with no network, at the host.
On Kubernetes with default-deny networking, or as a Slurm job at an HPC centre, as an ordinary project user. Whatever the model tries to reach is dropped and logged.
The test data stays sealed.
It is decrypted only inside the test harness, never handed to the provider, the authority or the operator.
Results are signed where they are measured.
The harness signs each result as it produces it, so a number cannot be changed on its way to the report.
Every action goes into a hash-chained ledger, and the keys die at exit.
Each entry is linked to the one before it and timestamped by an external authority. When the run ends, the keys are destroyed and the data can no longer be decrypted on the platform.
The authority re-checks the evidence bundle offline.
The free verifier runs on your own machine, with no network and no account, against anchors you hold: the plan digest, the ledger head, the timestamp authority's root. One changed character fails it.
The film
One supervised test run on a cluster
Three minutes, silent and captioned. A biased age-estimation model is caught, a corrected one passes, a hostile model is contained, and the evidence is verified offline.
Who it is for
Each party keeps what is theirs
- Sandbox operators and innovation agencies
- Scope a testing component for 2027 that you can fund and defend, and learn what it needs before you buy it.
- Market-surveillance and data-protection authorities
- Sign the plan, watch the run, halt it if you must, and verify the result yourself, offline.
- HPC centres, AI Factories and TEFs
- Host confidential tests as ordinary project jobs: Slurm with Apptainer or Kubernetes, nothing installed as root, synthetic data only in a proof of concept.
- Notified bodies
- Verify the outcome offline with the free verifier, without an account.
- Providers
- Have a model tested without handing over its weights, and without receiving the test data.
- Users of the AI Sandbox Configurator
- A plug-in posts a verified result into the Luxembourg AI Factory's Configurator as measures. The model and the data never reach it.
Founding partner
One sandbox, first in, shapes the 2027 testing.
Histor is taking one regulatory sandbox as founding partner for its 2027 cohort.
- A free proof of concept at its own HPC partner
- Four to six weeks, one participation on synthetic data, the authority verifying the result itself. No fee, no obligation, and the outputs published.
- Its staff trained
- The host's operators and the authority's verifier seat, trained on the partner's own run.
- Its requirements in the public release
- What the partner needs for its 2027 testing component shapes the public release, so its later tender can ask for functions, not a product.
- Named first in the release notes
- The founding partner is named first, with its host, in the release notes and the documentation.