Tech Policy
The Season of the Sandbox
The concept of a regulatory sandbox is becoming a familiar one. When a recent White House executive order laid out a comprehensive legislative framework for artificial intelligence, it included a call for Congress to establish federal regulatory sandboxes, without any further explanation. Just a few years ago, such a request might have been met with a confused stare. Now, the idea of a regulatory sandbox is a recognized policy making tool. I serve on the advisory committee for Utah's General Regulatory Sandbox and am excited about the potential for sandboxes, both at the state and federal levels. Given recent developments and momentum, I decided to put together a quick post on the innovative policymaking approach, to be followed hopefully soon with a more fulsome guide for businesses. What is a Regulatory Sandbox? While you've heard the term and likely have a general sense for what is involved, here is a quick explanation. The term itself (sandbox) is borrowed from the world of software engineering, where new code is sometimes tested in an isolated environment for safety reasons before being released. Extending that concept to the policy world, a regulatory sandbox generally refers to a program run by a regulatory body where new products and solutions are allowed to be tested in the marketplace under temporary waivers or "no action letter" interpretations of regulatory restrictions. This is typically done over a limited period of time (1-2 years is typical) and in a controlled fashion, including regular check-ins with the regulator. If the test yields positive results, long-term regulatory changes might then be proposed and rolled out. How Long have Regulatory Sandboxes been a Thing? The sandbox approach originated in the heavily regulated fintech space. The first one was an initiative in the U.K. in 2015 to support fintech startups. The approach has steadily gained traction since then, with sandboxes proliferating across the U.S., Europe and Asia. Arizona gets credit for adopting the first one in the U.S., a fintech sandbox launched in 2018, followed shortly by Utah. Utah took the concept a step further in 2021 by offering a comprehensive regulatory sandbox that is not limited to financial technologies. The state also offers legal and AI sandbox programs. At the federal level, the history is more start and stop. The Consumer Financial Protection Bureau launched a fintech sandbox in 2019, which had a short life when it was shuttered under the Biden Administration. A few months ago, the SEC and CFTC launched Project Crypto, which includes as a feature a sandbox-styled initiative where companies can trial tokenized products, particularly those with DeFi applications. As mentioned, there is momentum in DC around the concept of an integrated AI sandbox across agencies. Last year, Senator Cruz proposed a bill (S.2750 - SANDBOX Act) providing for just this approach. What Sandbox Opportunities Exist Right Now? While the AI sandbox vision contemplated by Senator Cruz’s bill and the White House executive order remain policy proposals for now, regulatory sandbox opportunities already exist in various forms across the United States, both at the federal and state levels. States with sandboxes of one kind or another include Arizona, Utah, Texas, Florida, Nevada, Kansas, North Carolina, Ohio, Kentucky, Vermont, South Dakota and West Virginia. Most of these sandboxes target highly regulated sectors, such as fintech, AI or even insurtech. However, some, such as Utah's, are technology-and-sector-agnostic and are potentially open to any business. This list changes regularly. What does it Take to Participate in a Sandbox? Requirements vary, but the spirit of the sandbox concept is to promote both innovation and regulatory reform where it makes sense to do so. As such, typically a proposal needs to bring a new solution to the market. Simply saying you want to do the same thing you've always done but with less regulatory restriction generally is not a winning proposal. That said, such an approach is not necessarily out of the question if a good case can be made that a public benefit could be achieved (such as addressing housing affordability). Is participating in a Sandbox a Good Idea for My Company? Maybe! It is certainly wise to look at a sandbox approach if you have a new business product or service that would be restricted by existing rules. Otherwise, to roll out your innovation you would need to challenge the law in some fashion or await formal policy change. However, given that sandbox options at the federal level are limited and state regulatory sandboxes only provide relief from state rules, the current sandbox opportunities are likely to be helpful only if the restrictions you are focused on are state level ones. For example, state sandboxes are particularly useful for navigating licensing requirements and consumer protection statutes--but they won't help when it comes to federal permitting requirements. Another limitation of a state sandbox is that you would need to operate within the geographic limitations of the state(s) where you are granted the regulatory relief. Despite these limitations, a sandbox approach can be powerful in pioneering new products and showcasing their efficacy in the real world, providing compelling evidence both of the utility of the innovation and the appropriateness of a specific policy change. Looking Ahead Sandboxes have the potential to address significant policymaking challenges. As use of frontier technologies like artificial intelligence proliferates, we will need new regulatory frameworks that are fit for purpose to both empower customers and promote competition. Also, affordability and global competitiveness concerns have raised questions around the benefit of some legacy regulatory systems. Process-based approaches like sandboxes are appealing in both cases because they provide flexibility to move with the pace of technology, and they allow efficient ways to test existing rules. However, until we have more sandbox options at the federal level, their utility will be limited. Follow us for more law and policy updates.
March 30, 2026
by Troy M. Keller
Tech Policy
More Quantum Policy
This article was written in collaboration with Dolly Chitta Ph.D. Dolly is founder of Curie Quantum and is Science and Innovation Advisor to the Nucleus Institute. In January, we made our first post on Quantum related policy. In a relatively short article, we summarized the totality of U.S. policy relating to Quantum initiatives and support over the last several years. Now, just two months later there is significantly more in the way of updates to share, reflecting momentum and increasing attention to the technology. What's Happening in Congress? Continued funding for the National Quantum Initiative (NQI) was included as part of the appropriations contained in the Commerce, Justice, Science; Energy and Water Development; and Interior and Environment Appropriations Act, 2026, signed into law on January 23. Quantum was just one in a long list of priorities supported by the bill, but it received special attention, including a hearing in the House Science, Space and Technology Committee titled "Assessing U.S. Leadership in Quantum Science and Technology". Committee Chairman Brian Babin (R-TX) commented: "We are no longer just funding science experiments. We are building the infrastructure for the next century’s economy. If we don’t own the quantum supply chain today, we will be importing our security tomorrow." Congress appears interested in going beyond maintenance funding for existing Quantum projects. In our earlier post, we had noted the introduction of The National Quantum Initiative Reauthorization Act of 2026, which would meaningfully expand the scope and resources of the NQI. On March 6, Representatives Haley Stevens (D-MI) and Randy Feenstra (R-IA) also introduced the Quantum in Practice Act that would include applied science in areas such as agriculture, healthcare, energy and materials as a focus of the NQI. These initiatives may not be game changers, but they are more than incremental steps. What's Happening in the White House? Arguably, the White House is even more focused on ways to promote Quantum development. In February, it was reported that a draft executive order called "Ushering In The Next Frontier Of Quantum Innovation" was close to being released. The executive order is expected to chart the next stage of the White House's strategy surrounding quantum by directing the Office of Science and Technology Policy to take actions such as lowering commercial barriers, partnering with foreign markets, scaling infrastructure and strengthening supply chains. It is expected to be a sweeping order, prioritizing an all-hands-on-deck approach to promoting the technology and protecting national security from the risks it presents. A Quantum-specific executive order will fit nicely within prior announcements around AI--as AI and Quantum have the potential to work hand in hand to bring viability to Quantum computing. For example, the Genesis Mission is a White House and Department of Energy initiative that seeks to develop "an integrated AI platform to harness Federal scientific datasets — the world’s largest collection of such datasets, developed over decades of Federal investments." The mission explicitly identifies Quantum information science among the national technology domains that could benefit from this platform-based approach to scientific discovery. Efforts like these reflect a view that technological leadership will require a coordination of resources across the governmental, academic and private sectors. For heavy resource technologies like Quantum this type of integrated research environment could play an important role in accelerating progress toward practical applications. Public-Private Initiatives On March 6, the formation of a national "Commission on U.S. Quantum Primacy" (CUSP) was announced. It was reported that: "CUSP will be led by co-chairs Ylli Bajraktari, U.S. Sen. Todd Young (R-IN) and U.S. Sen. Ben Ray Luján (D-NM). They are joined by a distinguished group of experts and policymakers at the intersection of technology and security." CUSP will "evaluate the current state of the U.S. quantum ecosystem and deliver a final report featuring actionable policy recommendations to ensure that the United States does not merely participate in the quantum age, but defines it." This particular effort feels less like tactics and more like strategy, a review of where we are. It is an interesting collaboration of legislative policymakers and private sector experts. We also note the ongoing DARPA Quantum Benchmarking Initiative (QBI) as important to monitor. QBI is exploring (through grants and academic and industry proposals) whether it is possible to build an industrially useful quantum computer by 2033, which it defines as "any quantum computing approach [that] can achieve utility-scale operation — meaning its computational value exceeds its cost." Unlike many earlier research initiatives, the QBI is structured around specific technical milestones intended to assess whether quantum systems can achieve the levels of reliability and scalability required for practical use. Similar to the White House initiatives discussed above, public private Initiatives such as CUSP and QBI reflect an understanding that the Quantum conversation requires an all-hands-on-deck approach. Where do These Steps Leave Us? Individually and spaced over time, any of the above developments might not appear material. But taken together, over the course of less than three months, the initiatives demonstrate momentum and growing awareness of the incoming importance of Quantum. We should expect to see more policy steps, especially as the rapid pace of AI reminds policymakers of the importance of staying ahead of transformational technologies. Follow us for more law and policy updates.
March 15, 2026
by Troy M. Keller
Tech Policy
Fintech's Fat Moment in Time
The legal world has always played fast and loose with the concept of time. Judges of course regularly rewrite history when rendering opinions about what a law means and then applying the consequences retroactively, sometimes unwinding acts that already occurred. (Many businesses are hopeful this very thing happens when SCOTUS delivers its opinion on IEEPA and tariffs.) Another example is the legal principle of ratification, which allows for post hoc authorization of actions in a corporate setting. So with the swipe of a pen we make the present reality become the past reality. And yes, we have a Latin phrase for it. Nunc pro tunc, or "now for then." But the legal world has nothing on the financial one. Eight hundred years ago the knights templar built possibly the world's first complex banking system, allowing travelers to spend wealth on one side of the continent that physically sat thousands of miles away. These transactions could take months or years to settle. With a little bit of paper and a lot of trust, time and space were imagined away. The modern banking system is not a whole lot different; it's just that settlements happens within days rather than months. But we are still playing with time and fudging the difference to make modern life work. Last week I attended the fintechXchange conference in Salt Lake City, and challenges associated with time, and fintech’s hopeful solutions, were a key theme. Crypto technology has for a while offered the potential to shrink to virtually nothing the space between transactions and settlement, as distributed ledgers are instantly updated, no need for an intermediary. A crippling obstacle has been the lack of a clear regulatory framework. Last year, the Genius Act was passed, providing a legal structure for stablecoins that could bring them into the mainstream, particularly useful when it comes to payments. There is plenty of spadework to be done before we see consumer take-up, but at least there’s a pathway. But tokenization and the broader crypto space still needs additional regulatory clarity before these tools can reach their potential. More on this later. I had a mentor who would use the expression “fat moment in time” when referring to the practice of closing a complex deal with a series of related transactions occurring in a particular order yet at the same time. If a "moment" is really a 1:1 transaction between time and space, it shouldn't physically for multiple, related and causal things to happen together. But we make it happen anyway in these projects, particularly when a deal needs to close at the end of a fiscal year, in that moment where a full fiscal year has passed but the next one has not yet started. We can do it because these steps, while reflecting real world consequences, are legal ones, and so assuming all the formalities are ready to go, and the money is sitting safely in escrow, we can deem it so. Right now, to build a fat moment like this takes teams of lawyers, bankers and accountants and weeks of planning. The promise of fintech, powered by the blockchain and AI, could enable complicated steps like these to take place in ordinary consumer transactions, opening up the possibility of bringing significant flexibility for consumers. For example, decentralized finance is are already offering ways for consumers to both invest and spend the same dollars by using assets as collateral for micro loans. If DeFi reaches its potential, imagine how consumers (with a little compute help from AI) could look at their phones and pay for their coffee using the most optimal financial choice in that moment, whether cash, earned wage access, third-party-credit, asset-backed micro-loans or even hedges, with the necessary transactional steps all happening on crypto ledgers in the right order, right then. The technology is on its way, but this future requires another dose of legal structure. Many are hopeful something like the Digital Asset Market Clarity Act will provide the framework that will enable fintechs to innovate in this direction. At the moment, a tussle in the financial industry over the ability for crypto providers to offer rewards that banks aren't in a position to do is likely to keep it from progressing in Congress. If resolved, maybe we will see the long promise of crypto realized. Follow us for more law and policy updates.
February 7, 2026
by Troy M. Keller
Tech Policy
The Unexpected AI Regulators
The axiom that legislators legislate and regulators regulate is typically applied to centers of government, like Washington D.C. or Brussels, where there can be a default instinct to create guardrails and restrictions whenever a new societal challenge is identified. But in a perceived accountability vacuum around artificial intelligence, states are seriously considering policies to get ahead of potential risks. California, Texas and New York have already passed legislation that would provide regulatory frameworks applicable to large AI developers. Now, legislators in Utah are swiftly progressing a bill that would provide a comparable level of oversight. H.B. 286 Artificial Intelligence Transparency Amendments Stepping carefully in light of White House directives for states not to impede AI progress and Utah's own pro-business reputation, the sponsors of H.B. 286 (Representative Doug Fiefia and Senator Mike McKell) are proposing a framework intended to mitigate child safety and large-scale, catastrophic risks through registration and reporting requirements. Specifically, the bill creates a new AI Transparency Act, which would apply to a category of "large frontier developers,” defined as AI companies that have foundation level computational power of 10²⁶ FLOPs (a threshold used in other contexts that captures the largest AI companies) and over $500 million in revenues. For companies falling into this category, the bill has the following key features: Mandatory Safety & Child Protection Plans: Developers must write, implement, and host public safety plans (to address catastrophic risks like cyberattacks or chemical weapons assistance) and child protection plans (detailing how they mitigate harms to minors and incorporate national safety standards). Risk Assessment & Incident Reporting: Companies are required to publish summaries of their internal risk assessments and must report "critical safety incidents"—such as the unauthorized release of model weights or AI-driven bodily harm—to Utah's new Office of Artificial Intelligence Policy. Whistleblower Protections: The bill establishes legal safeguards for employees of AI companies who report safety concerns or violations, prohibiting retaliatory "adverse actions" by the developer. Truth in Safety Labeling: It explicitly prohibits developers from making "materially false or misleading statements" regarding their safety plans or the risks posed by their models, allowing for civil penalties if a company claims to have safety measures that don't actually exist. Enforcement Mechanisms: Violations are subject to civil penalties, and the bill creates an enforcement fund to ensure the state has the resources to oversee these large entities. Disclosure Framework It's worth emphasizing that the bill would only regulate the largest of AI companies (i.e., not start-ups or companies in other spaces building out AI applications). And even at that level, it doesn’t restrict development but rather requires a level of “check in” and reporting with the state. Presumably, much would need to be worked out over time through rulemaking by the Office of AI Policy to provide specifics regarding the details of both what an adequate safety plan would entail and what results should they report to the state their model’s ability to cause harm. How the Bill fits into Utah’s Approach to AI In December, Utah held an AI summit, hosted by Governor Cox. State leaders were vocal about their desire to get ahead of emerging technologies that pose threats to mental health and to minors. As an alternative, they proposed a Pro Human AI initiative that would incentivize development that promotes human flourishing while being watchful. Last year, the State implemented an AI sandbox which has already authorized novel applications like an AI tool empowered to issue prescriptions for chronic illnesses. H.B. 286 would fit into the protective side of the equation. Follow us for more law and policy updates.
January 31, 2026
by Troy M. Keller
Tech Policy
The AI Moratorium
During 2025, lawmakers across the 50 states opened over 1,000 AI-related bills. Congress became justifiably worried that local lawmakers would go overboard, and came very close to passing an AI regulatory moratorium that would preclude states from weighing in. Many states pushed back firmly on this. On Dec. 11, the White House took matters into its own hands with an executive order laying out a plan for discouraging state laws that regulate AI in ways that are imprudent. The order does several things, such as instructing the DOJ to create a litigation task force to challenge state laws under preemption and/or interstate commerce clause principles wherever possible. It also threatens to withhold federal money (broadband and other federal grants) to states that enforce onerous AI laws. The Department of Commerce will publish its evaluation of such state laws within 90 days. It also directs the FTC to issue a policy statement on how laws that force AI to change its outputs (bias mitigation rules) could qualify as deceptive practices under federal law, allowing the FTC to override them. The FCC is given a job too. It is directed to work through whether its existing authority to regulate telecommunications systems (on which the internet and AI models run) would give it the ability to preempt certain state laws on AI. The EO explicitly does not target state laws regarding child safety, infrastructure (e.g., data center zoning) or state government procurement of AI technologies. The real test will come over the course of the year as states move ahead to roll out AI related laws or regulations anyway. The EO is not directly binding on the states. Rather, it is a framework of action the agencies might take, so expect there to be some test cases if federal agencies take action under the new policy.
January 17, 2026
by Troy M. Keller
Tech Policy
Quantum Policy (yes it's a thing)
We think of AI as the most exciting and transformative technology of our time, and I wouldn't argue with that. However, one of the less talked about aspects is the potential it has to bring viability to Quantum computing by (as I've been told) quickly finding and controlling for the random calculation errors that are inherent in the powerful technology. As a Quantum future becomes more and more possible, governmental policy is also developing around it. The first meaningful Quantum policy initiative in the U.S. actually came in 2018 in the form of the National Quantum Initiative (NQI) Act. This provided funding for Department of Energy (DOE) and National Science Foundation (NSF) research centers at national labs and universities across the country. It also directed NIST (National Institute of Standards & Technology) to forge industry connections through economic consortia. These were investments and grants that promoted the deep tech R&D that needed to happen if the U.S. wanted to be in a competitive position for this frontier technology. Late last year, a White House memo called out the need to prioritize Quantum development, noting the growing commercial viability of the technology: "As quantum technologies mature and become increasingly available on the commercial market, bolstering U.S. leadership will require advancing fundamental science while also tackling emerging engineering challenges and strengthening the critical technologies enabling the quantum ecosystem." It goes on to calls on federal agencies to prioritize practical R&D that looks at end user applications. Pre-competitive consortia are to be promoted. Then, earlier this month, Senators Todd Young (R-IN) and Maria Cantwell (D-WA) introduced the National Quantum Initiative Reauthorization Act of 2026. The bill would extend the National Quantum Initiative by five years to December 2034. That's of course good. But the bill also does something else that is noteworthy by expanding focus to commercial applications. It's an important shift in emphasis, reflecting the White House memo in part but going even further. Here are a few ways the bill proposes to do this: It would establish a number of new academic and private-public initiatives including three NIST Quantum Centers, five NSF Multi-disciplinary Centers for Quantum Research and Education, a quantum workforce coordination hub and quantum testbeds. This would significantly expand the touch points for the technology both to additional locations across the U.S. but also in some cases beyond the science centers and into the commercial arena. It would bring NASA to the table by authorizing it to pursue R&D in satellite communications and other areas. Again, real world applications. It also focuses on the Quantum supply chain, pushing for the creation of Quantum foundries that would make the technology more accessible. Funding for these initiatives may be squeezed between efforts by the House to find budgetary savings and pressure from the White House to dramatically increase defense spending. However, given the ample defense applications of Quantum tech, it is always possible the momentum takes Quantum funding the other way. It's worth keeping tabs on. The next Quantum Center, foundry or business consortium could be coming to your city soon! Follow us for more law and policy updates.
January 14, 2026
by Troy M. Keller