The machine - AI and player protection

There is an uncomfortable question sitting behind the use of artificial intelligence in gambling. What happens when the same machine that can tell an operator a player is getting into trouble can also tell it that this is the moment when the player is easiest to persuade to continue?

Consider a player who normally deposits once or twice a week. He starts depositing several times in one evening, putting more money in after losing and playing for much longer than usual. These changes may indicate that something is going wrong. AI can spot them as they happen and alert the operator much earlier than someone periodically reviewing the account. Used that way, the technology can help protect the player.

The difficulty is that the machine can read the same signals for another purpose. It can recognise that the player is susceptible and use that knowledge to decide when an inducement is most likely to work. Nothing fundamental has changed in the technology. It is the purpose given to it that has changed.

This is where the regulatory debate becomes more interesting than the familiar argument about whether AI is good or bad for gambling. It can plainly be both. The real issue is who decides which way the capability is turned, and when that decision is made.

European law is already approaching the problem from several directions. Gambling rules require player protection. The AI Act places limits on manipulative uses of AI and on the exploitation of certain vulnerabilities where the legal conditions are met. Consumer law continues to govern how products are marketed and sold, including its longstanding protection of vulnerable groups. These rules were written for different purposes, but they can now meet inside the same system.

The difficulty is that the three regimes can meet on the same conduct. Gambling regulation may require the operator to identify a player at risk. The AI Act and consumer law then have something to say about what happens to that information. Detecting vulnerability for the purpose of protecting a player is one thing. Detecting it and using it to make an inducement more effective is quite another.

There is also a more subtle consequence which I think will become increasingly important. AI gives businesses a much better ability to know their customers. In gambling that can include knowing when a player is vulnerable. Once the operator's own system has identified a relevant vulnerability, it becomes considerably harder to maintain that its effect could not reasonably have been foreseen.

In other words, better technology does not merely increase what an operator can do. It can increase what the operator can be shown to have known. This changes the practical meaning of consumer protection. For years the law has recognised that certain consumers require a different level of protection where vulnerability can reasonably be foreseen. AI can make that vulnerability visible at an individual level and in real time. The commercial attraction of personalisation and the regulatory responsibility created by that knowledge are therefore two sides of the same capability.

The temptation is to treat this as a compliance problem to be solved once the system has been built. That is too late. By deployment, somebody has already decided what information the system will use, what behaviour matters and, crucially, what it should do when it detects a player in difficulty. Those decisions may be taken in a product or engineering meeting, but some of them carry legal consequences from the moment they are made.

The choice is made much earlier than any regulatory investigation. When the system identifies a player in difficulty, someone has already decided what follows from that finding. If one part of the operation treats it as a reason to intervene while another uses it to sharpen an inducement, the contradiction was there from the start.

Regulators face a timing problem too. Supervision usually comes afterwards. By the time somebody examines why an AI system behaved as it did, the message has been sent, the inducement offered and the bet may have been placed. There are some things which cannot meaningfully be repaired after the event.

Operators will also need to show what choices were made. Good intentions are difficult to audit. Records of purpose, testing, responsibility, oversight and controls are not glamorous, but they provide the evidence of how the system was meant to behave and whether that intention survived contact with the real world.

None of this is an argument against using AI in gambling. Its capacity to identify harm earlier and more accurately could materially improve player protection. The concern lies in assuming that a useful capability is necessarily a benign one. The same insight can protect a player or be used against him.

The important regulatory decision may therefore be taken long before a regulator or court becomes involved. It is taken when somebody decides what the machine should do when it knows that a player should probably stop.

Article by Dr Ian Gauci

This article was first published in The Times of Malta of the 4 October 2026.

Photo credits: Times of Malta

 

Disclaimer This article is not intended to impart legal advice and readers are asked to seek verification of statements made before acting on them.
Skip to content