Are gambling operators ready for AI compliance?
Marek Plota, Founder of RM Legal and Gaming in Poland, returns for another Global Gaming Insider column. He asks: are we really ready for AI compliance?
Artificial intelligence is increasingly becoming embedded in the operational infrastructure of gambling businesses. In betting and online casino, AI-based tools are already used to predict player behaviour, personalise offers, detect fraud, support AML processes, identify responsible gambling risks, automate customer support and improve commercial performance.
Used properly, these tools may enhance the operator’s control environment. They can support earlier detection of harmful gambling patterns, improve fraud prevention, strengthen AML monitoring and allow customer support teams to handle routine cases more efficiently.
At the same time, the deployment of AI creates a distinct layer of legal and regulatory risk. AI systems may influence player behaviour, classify or profile users, determine the targeting of offers, support risk scoring or affect access to an account. In a highly regulated gambling sector, such systems cannot be treated as merely technical or operational tools.
For operators and B2B suppliers, the first step should be a structured assessment of each AI system. This should include its intended purpose, the categories of data processed, the decisions or recommendations it supports, the level of automation involved, the role of human oversight and the potential impact on the player.
Although the EU AI Act was not designed specifically for gambling, it is highly relevant to the sector. Gambling businesses rely extensively on behavioural data, personalisation, financial transactions, risk scoring and player monitoring. These are precisely the areas in which the use of AI may give rise to regulatory exposure.
AI systems in gambling
For the purposes of legal and regulatory assessment, AI should be understood broadly. It should not be limited to generative AI tools. Depending on its functionality, it may also include machine learning models, predictive scoring tools, recommendation systems, automated classification tools, anomaly detection systems, chatbots, personalisation engines and decision support systems.
In sports betting, AI may support odds optimisation, trading processes, suspicious betting detection, customer segmentation, AML alerts, fraud scoring, bonus abuse detection, risk-based KYC and personalised recommendations. In online casino, AI may be used for game recommendations, bonus targeting, responsible gambling monitoring, churn prediction, VIP segmentation, payment risk analysis, withdrawal risk scoring, customer support and behavioural profiling.
The legal qualification of such systems should be based primarily on their function, context of use and impact on the player. A tool used solely for internal analytics may present limited regulatory risk. The same tool may require a more detailed assessment where it affects a player’s account, funds, access to the service, risk classification or exposure to marketing.
Prohibited AI practices
The highest level of regulatory concern under the AI Act relates to prohibited AI practices. In the gambling sector, the principal risk arises where AI is used to manipulate player behaviour or exploit a player’s vulnerabilities.
This risk is particularly acute where an AI system identifies indicators of vulnerability and uses those indicators to increase engagement, play intensity or spending. Such indicators may include chasing losses, increased deposit frequency, repeated cancellation of withdrawals, late night play or other patterns suggesting impaired control. If these signals are used to trigger personalised bonuses, retention campaigns, targeted incentives or behavioural nudges, the operator may be exposed to significant regulatory risk.
Examples may include tailored promotions sent to players showing signs of harmful gambling, online casino recommendations directing such players towards faster or higher volatility games, or AI-driven near miss mechanics activated when the system identifies emotional fatigue, loss aversion or similar behavioural patterns. Where such features are calibrated around player psychology, previous losses or vulnerability indicators, they may be assessed as exploitative design.
Personalisation becomes legally sensitive when it relies on behavioural or socio-economic signals in a manner that takes advantage of a player’s vulnerability. Operators should treat such use cases as high-priority red flags requiring legal, compliance and product review before deployment.
Operators and suppliers should adopt clear internal restrictions. AI should not be used to identify vulnerability for commercial exploitation. Responsible gambling indicators should trigger protective measures rather than marketing escalation. Players identified as at risk should be excluded from promotional targeting. AI-driven product design should be assessed not only by reference to conversion or retention metrics, but also by reference to fairness, transparency and harm prevention.
High-risk AI
Gambling is not automatically classified as a high-risk sector under the AI Act. However, this does not remove the need for a detailed assessment of individual use cases. Certain AI systems may fall within the high-risk framework or, as a minimum, require comparable governance because of their potential impact on players.
Attention should be paid to systems that affect access to gambling services, financial decisions, risk classification, player monitoring or decisions that may have serious consequences for the individual. This may include automated systems used to freeze accounts, refuse withdrawals, close accounts, restrict access, adjust player limits, escalate AML cases, classify users as fraudulent or impose responsible gambling interventions.
Responsible gambling tools require careful legal and operational review. Their purpose is protective, but their outputs may still materially affect the player. A system that recommends a cooling off period, triggers a limit, escalates a player for safer gambling review or restricts account functionality should be subject to appropriate governance. The operator should understand how the model works, what data it uses, how reliable it is, how false positives are managed and whether human review is genuine.
Fraud and AML systems raise similar concerns. AI may be used to detect suspicious betting patterns, multi-accounting, bonus abuse, unusual payment behaviour or collusive play. Where automated alerts lead to account restrictions, payment delays or refusal of withdrawals, the operator should be able to explain the basis of the decision, document the process, provide appropriate review routes and ensure effective human oversight.
As a practical rule, any AI system that may affect player rights, funds, access to the service or regulatory status should be treated as enhanced risk, even where the formal legal classification requires further analysis.
AI transparency
Some AI systems may not be prohibited or high risk, but they may still require transparency. This is especially relevant for chatbots, generative AI and AI-generated content. If players interact with an AI chatbot, they should be informed that they are dealing with an AI system unless this is obvious from the context. This matters in customer support, complaints handling, KYC assistance, safer gambling interactions and retention communication.
Generative AI used to create marketing content, images, game assets, synthetic voices,
avatars, influencer style messages or automated player communications may also require transparency and governance. The more realistic or personalised the content, the greater the risk that users may be misled.
A player should not believe that a human safer gambling agent is speaking to them if the response is generated by AI. A customer should not receive personalised regulatory or financial information from a chatbot without proper controls. AI generated marketing should not hide its automated origin where disclosure is required.
GDPR remains central
Most AI use cases in gambling involve the processing of personal data. This may include registration data, payment data, gambling history, behavioural data, device data, location data, KYC information, responsible gambling records and customer support interactions.
For this reason, AI Act compliance should be aligned with GDPR requirements from the outset. Operators should identify the appropriate legal basis for processing, provide clear privacy notices, apply data minimisation, define retention periods, ensure appropriate security measures and respect data subject rights.
Many AI deployments in gambling are also likely to require a Data Protection Impact Assessment. This will be particularly relevant where AI is used for profiling, behavioural monitoring, risk scoring, fraud detection, responsible gambling assessments or other forms of systematic player evaluation.
Profiling and automated decision making require particular care. Where an automated decision produces legal effects or similarly significant effects for the player, GDPR Article 22 may become relevant. Examples may include automated account closure, refusal of withdrawal, severe account restrictions, automated risk classification or other decisions that materially affect access to gambling services.
Human oversight should be genuine and effective. A manual review will not be sufficient if the reviewer cannot understand the basis of the AI-generated result, challenge it in practice or change the outcome where appropriate.
Next steps for operators and suppliers
The first step is to map AI use. Many organisations do not have a complete list of AI systems because AI features are often embedded in CRM tools, payment systems, AML platforms, game recommendation engines, analytics tools and customer support software.
The second step is classification. Each system should be assessed as a prohibited use risk, potential high-risk use, transparency obligation use or lower risk internal use. This classification should be documented and reviewed when the system changes.
The third step is data review. Operators should know what data is processed, where it comes from, whether it includes sensitive or vulnerability related indicators, whether it is used for the original purpose and whether it may be lawfully used for AI training
or inference.
The fourth step is governance. Operators should adopt AI policies, human oversight rules, escalation procedures, incident response mechanisms, audit trails and model monitoring. AI compliance should involve legal, compliance, product, data, security, responsible gambling and commercial teams.
The fifth step is supplier control. Contracts with AI vendors should cover permitted use, prohibited use, documentation, audit rights, explainability, logging, testing, bias monitoring, cybersecurity, data processing, model updates, subcontractors, regulatory assistance, incident notification and liability.Operators should be careful with black box systems if they may later need to justify the output to a regulator, player or court.
The sixth step is marketing separation.AI systems detecting responsible gambling risk should not feed commercial targeting without strict controls. At risk players should be removed from promotional campaigns. Vulnerability signals should be used to protect the player, not to sell more.
Are we ready?
In most cases, probably not yet. The gambling sector is still at an early stage of formal AI governance. Many operators and suppliers already use AI based tools, often through existing platforms, CRM systems, AML tools, customer support solutions or marketing technology. In many organisations, however, these tools have not yet been formally mapped, classified or assigned to a clear internal owner.
This makes the current moment important. It is an opportunity to build the framework properly before regulatory expectations become more settled and before AI becomes even more deeply embedded in day-to-day operations.
Operators do not need to solve every issue at once. A sensible first step is to identify existing AI use cases, prioritise those that may affect players, and review the highest risk areas first. Suppliers should take the same approach from the product side. It is not too late. In fact, for many gambling businesses, this is probably the best time
to act.
The companies that start now will be better placed to use AI safely, explain their systems clearly and respond with confidence when regulators, partners or players begin to ask harder questions.