On 29 September 2026, Euronews published an interview with Ukraine's Digital Minister Oksana Ferchuk in which she said Ukraine wants Europe to "use Ukraine as an AI sandbox: a place where it can observe the experiments we are conducting," learn from what works and what fails, and only then apply the lessons across the EU. The pitch rests on a platform with real scale. Diia, the state's app, portal and offline service network, serves more than 24 million Ukrainians, holds more than 30 digital documents and offers roughly 250 online services, per the Euronews interview. It now includes an AI assistant.
The strongest case for caution
The sceptic's argument deserves a fair statement. A wartime state can move fast partly because its citizens have accepted trade-offs that peacetime democracies would contest. Concentrating identity documents, tax IDs, family records and service access in one app creates a high-value target and a single point of failure. Adding a generative AI agent that touches state registries raises the stakes on error, bias and accountability. Regulators who insist on conformity assessment and human oversight before deployment are answering real risks, not imagining them. A country under invasion also has fewer institutional brakes and less room for slow, adversarial review. On that view, "Ukraine as sandbox" could mean Europe imports lessons drawn from conditions it should not replicate.
Why the offer is still substantive
The answer is that Ukraine has a track record worth examining. The assistant, Diia.AI, launched in 2025 and was recognised by the Book of World Records on 4 November 2025 as the first national AI assistant providing public services, according to the Cabinet of Ministers of Ukraine. The record is a publicity milestone, not an audit. The more useful evidence sits in the European Commission's own Interoperable Europe portal. It describes Diia.AI as an agent that delivers services directly in chat, built on Google's Gemini 2.0 Flash through Vertex AI with LangGraph orchestration. The entry cites customer satisfaction above 80%, and projects service resolution under three minutes, over one million citizen-hours saved annually and a 30% cut in human support tickets. Note the wording: several of those figures are projections, and they are self-reported by the project. They are hypotheses for a European evaluator to test, which is exactly what a sandbox is for.
Europe has a live need for such evidence. Article 57 of the AI Act requires each Member State to have at least one national AI regulatory sandbox operational by 2 August 2026, and it shields good-faith participants from administrative fines while leaving them liable for third-party damage, as laid out in the text of Article 57. Sandboxes are only as useful as the cases that pass through them. Public-sector agentic AI, where the service, the data and the regulator are all state-run, is one of the least-tested categories in Europe.
What is actually being proposed
Details on the institutional vehicle are thin. Coverage of Ferchuk's remarks at a forum in Kharkiv describes a vision in which Ukraine "must not only adapt European rules" but "create solutions for Europe," with emphasis on defence technology, robotics, AI and dual-use engineering, according to dev.ua. That article gives no launch date, application process or named participants. The Euronews interview likewise offers a principle rather than a legal framework. There is no announced agreement with the Commission, no data-sharing arrangement and no evaluation protocol. Anyone treating this as an operating programme is ahead of the evidence.
Resilience is the real export
The interview's least glamorous material may matter most. Ferchuk said Russia has recently attacked data centres and telecom providers, and that the government is planning for blackouts of up to five days, using generators and batteries to keep mobile networks running and security operations centres with AI-assisted monitoring. She added that "in IT, you can never say that anything is 100% safe." That candour is more persuasive than a claim of invulnerability. A digital state that assumes outages, and designs offline fallbacks and distributed infrastructure around them, offers lessons on continuity that European governments planning for cyber and energy disruption can use immediately, without importing any of Ukraine's wartime legal trade-offs.
A proportionate way to use the offer
Europe should accept the invitation, with conditions that make the learning real rather than rhetorical.
- Define what is being tested. Separate service-delivery lessons (chat access to registries, resolution times, fallback design) from rights-sensitive ones (automated decisions, data retention). Only the first set transfers cleanly.
- Demand independent evaluation. Satisfaction and time-saved figures should be measured by a third party, not quoted from the operator. The Commission's portal already flags which numbers are projections.
- Keep the guardrails at home. Observing Ukraine does not replace running Member State sandboxes under Article 57, where fine protection is paired with regulator guidance and liability for harm.
- Avoid over-regulating the observer. If Brussels responds by layering new pre-approval requirements on public-sector AI pilots, it would slow the very learning it says it wants.
The pro-innovation reading is straightforward. Governments that ship useful digital services at scale, publish what happened and let outsiders check the numbers are doing the work that better regulation depends on. Ukraine's offer is credible because Diia exists and runs at scale. It becomes valuable only if the evidence is open to challenge, and only if Europe treats "sandbox" as a discipline of measurement, not a label for deregulation by another name.