Artificial intelligence and algorithmic systems now run inside almost every layer of an iGaming platform, from harm detection to promotional targeting. Regulators have stopped treating that as a technical footnote. Between May 2025 and July 2026, supervisory bodies in Britain, the Netherlands and Malta each set out what an operator must be able to explain about the models deciding what happens on a player account.
Where Algorithmic Systems Already Sit in the Operator Stack
The debate about AI regulation reaching online gambling tends to open with speculative use cases. The supervisory record opens somewhere duller. When the Malta Gaming Authority launched its consultation on a proposed AI Gaming Charter in May 2026, its stated premise was that licensees already deploy automated systems across customer support, fraud detection, marketing and risk management. The regulatory question is not whether models are running. It is whether the operator can account for them.
Five clusters carry most of the exposure that falls under the requirements for player protection and under game integrity rules.
- Onboarding and identity, covering document authenticity checks, liveness detection and duplicate account matching.
- Financial crime controls, covering transaction monitoring scenarios, sanctions and PEP name matching, and network analysis.
- Harm detection, covering behavioural risk scoring, session pattern analysis and language screening of customer service contacts.
- Commercial personalisation, covering bonus targeting, recommendation engines, and churn or reactivation models.
- Player-facing conversation, covering chatbots that handle first-line contact, including limit change requests.
Only the first two carry a mature audit tradition. Algorithmic risk scoring in gambling, and the promotional models sitting alongside it, are where supervisory expectations have moved fastest since 2024.
How the Gambling Commission Treats Automated Harm Detection
Social Responsibility Code Provision 3.4.3 came into force for remote licensees on 12 September 2022, with the formal guidance taking effect on 31 October 2023. Paragraph 11 is the operative text on automation. It requires licensees to act on strong indicators of harm in a timely manner by implementing automated processes, to manually review the operation of those processes in each individual case, and to give the customer an opportunity to contest any automated decision affecting them.
The guidance is specific about what immediate action looks like. Where a significant level of harm is identified, an operator may block further gambling, block further deposits, or impose a deposit limit, holding that measure until a member of staff has considered the case and applied a final action. Where a decision is taken solely by automated means and produces legal effects or similarly significantly affects the customer, the licensee must contact them, inform them of the right to contest, and conduct a substantive manual review if the decision is challenged.
Britain is therefore not asking whether an operator uses machine learning applied to markers of harm. Supervisory attention has shifted to the speed of detection of markers of harm, and the absence of automated action is itself treated as the failure. On 30 June 2026 the Gambling Commission published a regulatory settlement of £900,000 with Petfre (Gibraltar) Limited, operator of betfred.com, following a licence review. The findings were about automation rather than intent.
- No sufficient processes to identify indicators such as spend, time spent gambling and patterns of spend by automated means.
- No process ensuring that immediate, automated action was taken where strong indicators of harm were identified.
- A safer gambling review flag that suppressed any further review of the same account for seven days.
One customer received an interaction after passing a deposit trigger and a decision was taken that no further action was needed. That account then deposited and lost a further £17,900 within 24 hours without further intervention. The licensee had not defined its strong indicators of harm within its own safer gambling policy, which is what paragraph 11 leaves to the operator to specify.
What the Ksa Expects Before a Model Goes Live
The Netherlands addressed the question directly. On 12 May 2025 the Kansspelautoriteit (Ksa), the Dutch gambling authority, wrote to every online licensee setting out conditions for the use of chatbots and artificial intelligence. The letter followed a technical meeting held in October 2024 on the Regeling speellimieten, the play limits regulation, and the Beleidsregel verantwoord spelen, the responsible play policy rule. The answer was permissive on deployment and strict on explanation, resting on three conditions.
| Condition | Dutch term | What the operator must be able to produce |
|---|---|---|
| Transparency | Transparantie | An account of why the system reached a given conclusion or recommendation, including what a red flag for excessive play rests on and how confident the system is in it. |
| Responsibility | Verantwoordelijkheid | Ownership of how the system behaves, including where it was bought in. Pointing at system output without explaining its workings is not sufficient. |
| Accountability | Rekenschap | An explanation of how the system operates, what data it was trained on, and which values and norms are embedded in it. |
Two limits are absolute. A chatbot may not replace conversations with staff trained in addiction prevention and can only supplement them, with a human always available to take the conversation over. Requests to raise deposit limits beyond the maxima in article 3.19d of the Regeling kansspelen op afstand require a trained member of staff to deal with the player personally. The Ksa added that referring to a black box is not acceptable when an operator is asked to explain how an analysis of play behaviour was produced.
The wider Dutch duty of care obligations set the tempo any model has to hit. Under the amended Beleidsregel verantwoord spelen, in force from 3 June 2024, a licensee must detect, analyse and intervene on a signal or reasonable suspicion of excessive participation or gambling addiction within one hour, and that requirement runs 24 hours a day. The Ksa supervision agenda published on 20 January 2026 confirmed that guidance on the use of AI and monitoring tools by licensees would follow.
Regulator Positions Compared Across Five Frameworks
These positions sit on top of the responsible gambling tool mandates each body already imposes. Compared side by side, the frameworks diverge less on outcome than on how far they have gone in writing the expectation down.
| Framework | Instrument and date | Expectation of algorithmic systems |
|---|---|---|
| Great Britain | SR Code 3.4.3, guidance in effect 31 October 2023 | Automated action on strong indicators, manual review of that action case by case, and a customer right to contest automated decisions. |
| Netherlands | Ksa letter to online licensees, 12 May 2025 | Transparency, responsibility and accountability. No black box explanations. Trained staff for prevention conversations and limit increases. |
| Malta | Proposed AI Gaming Charter, consultation opened May 2026 | Voluntary, principles-based guidance developed with the MDIA and aligned to the EU AI Act, addressing bias, transparency and consumer protection. |
| Ontario | Registrar’s Standards for Internet Gaming, standards 2.10 and 2.11 | Automated and manual monitoring in combination, technology used to scale interventions, and records of manual adjustments to risk scores. |
| European Union | Regulation (EU) 2024/1689, amended by Regulation (EU) 2026/1744 | Prohibited practices and AI literacy since 2 February 2025. High-risk duties for Annex III systems deferred to 2 December 2027. |
Ontario is the outlier in one respect. Expectations published under standard 2.11 ask operators to use technology to scale tailored interventions to more players rather than reserving personal contact for the highest-risk group, and to monitor new accounts closely from the outset instead of applying a graduated delay and observe approach. Records must also cover situations where a decision was made not to intervene, together with any manual adjustment to a player risk score. That is a documentation requirement aimed squarely at model overrides.
Does the EU AI Act Reach Player Risk Models
The EU AI Act for gambling operators reads more usefully as a calendar than as a classification exercise. Regulation (EU) 2024/1689 entered into force on 1 August 2024 and applies in stages. The Digital Omnibus on AI, Regulation (EU) 2026/1744, was published in the Official Journal on 24 July 2026 and entered into force on 27 July 2026, six days before the original high-risk deadline. The revised sequence is as follows.
- 2 February 2025: prohibited practices and AI literacy obligations apply.
- 2 August 2025: obligations for general purpose AI models apply.
- 2 August 2026: Article 50 transparency obligations apply, other than Article 50(2) for systems already on the market.
- 2 December 2026: Article 50(2) applies to legacy systems and the new prohibitions added by the Omnibus take effect.
- 2 December 2027: high-risk obligations apply to standalone Annex III systems.
- 2 August 2028: high-risk obligations apply to AI embedded in products covered by Annex I.
The deferral bought time on Annex III classification. It did not touch Article 5. Practices that exploit vulnerabilities arising from a person’s age, disability or specific social or economic situation have been prohibited since February 2025, and a model tuned to lift deposits from players it has identified as financially stressed is the case the gambling sector should be reading itself against. Nor does the AI Act displace data protection law. Automated decision making affecting player accounts engages Article 22 of the GDPR, which is where the British right to contest originates, and it sits inside the same GDPR obligations in iGaming that govern lawful basis and retention for verification records.
Personalised Promotions and the Boundary Regulators Are Drawing
Promotional models are where player protection and commercial incentive collide most directly. Paragraph 10 of SR Code 3.4.3, in force from 12 February 2023, requires that a customer showing strong indicators of harm no longer receives direct or targeted marketing and is prevented from taking up new bonus offers. That is a hard interlock between the risk model and the marketing stack. Where the two systems do not share state in near real time, the licensee is exposed every time the risk model fires.
Bonus suppression is not only a player protection control. It also sits inside the advertising and marketing standards that govern how offers are presented and to whom. The Ksa listed negative behavioural steering, meaning design that pushes players to deposit more or play for longer, among its 2026 supervisory themes and said it would draw on behavioural experts to assess it. At EU level the Digital Fairness Act is the instrument to watch. It has not yet been tabled, the Commission work programme places the proposal in the final quarter of 2026, and its announced scope covers dark patterns, addictive design and unfair personalisation that exploits consumer vulnerability. Four controls tend to survive scrutiny.
- Suppression lists that update within the same session as the risk score rather than on an overnight batch.
- A record of which model version selected a given player for a given campaign.
- Documented exclusion of harm indicators as features inside promotional targeting models.
- An approval trail demonstrating that marketing sign-off cannot override a protection flag.
Game Integrity Constraints on Adaptive Systems
Everything above concerns models that watch the player. A separate question is whether models may shape the game. In Great Britain the answer is settled. RTS requirement 7A states that random number generation and game results must be acceptably random and that adaptive behaviour, meaning a compensated game, is not permitted. The implementation guidance adds that random numbers must be used in the order received and may not be discarded because of adaptive behaviour. That rules out the most obvious application of machine learning at the game layer, and it does so without any drafting specific to artificial intelligence.
The softer end is constrained too. On 1 October 2025 the Gambling Commission imposed a penalty of £240,000 on Petfre (Gibraltar) Limited after finding that slot games on betfred.com and oddsking.com failed to display the customer’s net position and celebrated returns equal to or below the total stake as wins. The regulator held that such effects may damage a player’s ability to interpret gameplay accurately and make informed choices. The affected games were decommissioned.
Under GICNT-FP, certification attaches to the individual game rather than to the operator, which has a practical consequence for anything adaptive in the presentation layer. A model that changes what a player sees is a change to the certified build. It triggers recertification by an independent laboratory such as eCOGRA, BMM Testlabs, iTech Labs or an equivalent house recognised in the target market, on the same footing as any other release and inside the same RNG certification obligations that apply to the base game. Four constraints follow.
- Outcome determination stays outside the model boundary, with RNG output consumed in sequence.
- Published RTP figures reflect the configuration actually running, not an average across variants.
- Any personalised presentation is disclosed in the submission to the test house.
- Retraining or retuning of a model that touches the game client is treated as a version change.
What GICNT-PP and GICNT-FP Require of Model Governance
Certification under GICNT-PP runs on a bi-annual audit and GICNT-FP operates at game level, so the evidence an operator has to hold differs between the two. What they share is a refusal to accept output as proof of process. An assessor asking about AI monitoring tools for responsible gambling is asking for the file behind the tool, not a demonstration of the dashboard.
| Artefact | What it has to show | Domain |
|---|---|---|
| Model inventory | Every system touching player accounts, its owner, and whether it was built internally or procured. | GICNT-PP, GICNT-FP |
| Feature and training record | What the model was trained on, which features drive a risk flag, and when the data was last refreshed. | GICNT-PP |
| Threshold rationale | Why a given score triggers a given action, and who approved the threshold. | GICNT-PP |
| Human review log | Manual review of automated action case by case, including decisions taken not to intervene. | GICNT-PP |
| Contest and override trail | Player challenges to automated decisions, the outcome, and any manual change to a risk score. | GICNT-PP |
| Supplier assurance | A contractual right to explanation where the model is third-party, and evidence that it has been exercised. | GICNT-PP, GICNT-DS |
| Certification linkage | Which certified game build each presentation variant belongs to. | GICNT-FP |
Periodicity matters here. Because the domains run on different GICNT audit cycles, a model retrained in the gap between assessments can drift away from the state that was reviewed. Version control on models, tied to the assessment date, is the cheapest way to keep the two in step.
Frequently Asked Questions on Algorithmic Systems and Compliance
Do gambling regulators require operators to use AI for harm detection?
No regulator mandates artificial intelligence specifically. Several mandate outcomes that manual review cannot deliver at scale. Paragraph 11 of the British SR Code 3.4.3 requires automated processes where strong indicators of harm appear, and the Dutch responsible play policy rule requires detection, analysis and intervention within one hour, around the clock. Whether that is achieved with deterministic rules or with machine learning remains the operator’s choice.
Does the EU AI Act classify player risk scoring as a high-risk system?
Annex III does not list gambling harm detection by name, so classification turns on the facts of the deployment. The practical position is that high-risk obligations for standalone Annex III systems now apply from 2 December 2027 following the Digital Omnibus deferral, while the Article 5 prohibitions and the AI literacy duty have applied since 2 February 2025 regardless of classification.
Can a chatbot handle a request to raise a deposit limit?
Not on its own in the Netherlands. The Ksa position of 12 May 2025 is that chatbots and AI may supplement staff but not replace them in addiction prevention contexts, and that requests to exceed the maximum deposit limits under article 3.19d of the Regeling kansspelen op afstand require a trained member of staff to deal with the player personally.
What has to happen when an automated system blocks a player account?
Under the British formal guidance, where a decision is made solely by automated means and has legal effects or similarly significantly affects the customer, the licensee must contact that customer, inform them of their right to contest the decision, and carry out a substantive manual review if they do contest it. Separately, the licensee must review the operation of the automated process in each individual case.
Are operators allowed to adapt game outcomes to individual players?
No. RTS requirement 7A prohibits adaptive behaviour, meaning a compensated game, and requires random numbers to be used in the order they are received rather than discarded. Personalisation in gambling products is confined to the presentation, marketing and service layers, and any change to a certified game build triggers recertification through an approved test house.