Who audits the model that decides you have a gambling problem?
That question sits underneath every conversation about responsible AI in gambling, and the industry does not yet have a confident answer. At the Global Gaming Expo, a panel of researchers and operator executives argued that the answer should come from the industry itself rather than arriving later as a regulatory mandate. Kasra Ghaharian, research director at the UNLV International Gaming Institute, put it plainly: the sector spent decades building trust through anti-money-laundering work and consumer-protection guidelines, and AI is the next place that reputation gets tested.
“It’s a really good opportunity for the gaming industry to demonstrate, ‘This is how you do it,'” Ghaharian said during the session, titled “State of AI in Gaming 2026: Research Results on Industry Maturity, Regulatory Readiness, and the Road Ahead.”
What the G2E panel actually recommended
The panel was built around the inaugural State of AI in Gaming 2026 study, the first annual edition, produced by UNLV’s International Gaming Institute in collaboration with KPMG LLP. Two findings framed the whole discussion.
First, adoption is still early. Most gaming-industry AI deployments sit in back-of-house and security functions rather than customer-facing ones, which the study classifies as a “developing” stage of maturity. Second, there is a gap between operators and regulators: regulators want to write rules for AI, but they don’t have a clear picture of how operators are using it.
That gap is the practical call to action. Rules written without visibility tend to be blunt. The recommendations that came out of the session were less about lofty principles and more about closing that information gap before it hardens into bad policy:
- Treat responsible AI the way the industry treated AML compliance: as a standard the sector sets and documents, not one it waits to receive.
- Be able to explain, use case by use case, what models are doing and what data they touch, so regulator conversations start from facts.
- Involve staff in deployment decisions. Lori Kobashigawa, senior vice president of marketing and innovation at Fontainebleau Las Vegas, described the approach as “technology in service of the business” and stressed empowering employees rather than displacing judgment.
- Keep customer-facing ambitions tied to governance. The most-discussed ideas on the panel were customer-facing, which is precisely where the oversight is thinnest.
Follow one system end to end: the AI “host” scenario
The clearest way to see where ethics decisions actually live is to trace a single use case from the panel. Eric Bowers, vice president of innovation and architecture at Boyd Gaming, described his “dream scenario”: AI providing an individual host for every player in the database, delivering what he called “a holistic personalized journey” across in-person and online play. Simo Dragicevic, co-founder of the IGI’s AI Research Hub, pushed the idea further, envisioning a static player database turning into a “living database” that simulates human behaviour and opens up new innovation over the next five to ten years.
Now walk that system from signup to intervention.
Stage one: the data comes in. Deposits, session length, time of day, bet sizing, game switching, cancelled withdrawals, support chats. Nothing here is exotic; operators have collected it for years. The ethical question appears the moment it is repurposed. A player consented to KYC checks and account servicing. Did they consent to behavioural modelling? Under India’s Digital Personal Data Protection Act, 2023, consent has to be specific and tied to a stated purpose, which means “we already had the data” is not a defence for a new use.
Stage two: the model forms a view. The same machine learning model that predicts which player will respond to a free-spins offer can predict which player is escalating toward harm. It is close to the same feature set. That is the uncomfortable symmetry at the centre of responsible AI in gambling: one output drives marketing, the other drives player safety, and the operator chooses which one gets acted on first.
Stage three: the system acts. This is where governance either exists or doesn’t. A personalised “host” that notices a player chasing losses at 3am can surface a deposit limit, a reality check or a cool-off prompt. The same signal, pointed the other way, becomes a perfectly timed reload offer. Nothing in the technology decides which. A documented policy does.
AI player protection: what the safeguards actually do
AI player protection works by spotting patterns that a human reviewing accounts one at a time would miss, then triggering a defined response. Three layers matter.
Automated risk detection systems
These score accounts against markers of harm: rapidly increasing deposits, repeated failed payment attempts, multiple deposits inside a single session, play that runs far outside a player’s own historical pattern. The output should be a flag for review and a graduated response, not a silent internal label. Detection without a mandated action is theatre.
Behavioural pattern analysis
Harm rarely announces itself in one metric. Behavioural models look at sequences, for example a player who shifts from low volatility slots to high volatility games while shortening session gaps, or who moves from steady stakes to doubling after losses. These are correlations, not diagnoses. A flag means “look at this account”, not “this person is addicted”.
Real time intervention tools
The intervention is the product. In practice that means in-session messaging, forced pauses, prompts to set deposit or loss limits, restricted marketing for flagged accounts, and a clear route to self-exclusion. The useful test: how long between a flag being raised and the player experiencing something different? If the answer is measured in weeks, the model isn’t protecting anyone.
Ethics guidelines operators can write down this quarter
Gaming industry ethics only becomes real when it is written, dated and owned by a named person. Four commitments carry most of the weight.
Algorithmic transparency. Maintain an internal register of every model in production: purpose, inputs, owner, review date, and what decisions it influences. Players affected by an automated decision should be told a system was involved and be able to reach a human.
Human accountability. No account closure, no harm classification and no promotional suppression should be fully automated without a review path. AI recommends; a person decides.
Bias testing and mitigation. Models trained on historical play can misfire across groups, flagging some players aggressively and missing others entirely. Test detection performance across segments, log false positives and false negatives, and re-test after retraining. Bias detection is a scheduled task, not a launch-day checkbox.
Purpose separation. Harm signals should not feed marketing systems. That firewall is simple to state and easy to audit.
Where AI fair play and game integrity intersect
A point worth being precise about: AI does not change the math of the games. Slot outcomes come from certified RNGs, and RTP and house edge are fixed properties of a game’s design. A 96% RTP game carries a 4% house edge whatever the personalisation layer around it does. AI fair play concerns sit in the layer above the game, not inside it.
The real integrity risks are in targeting and pricing. Using a behavioural model to serve the highest-volatility content to the most loss-sensitive players, or to shape bonus terms around who is least likely to read wagering requirements, is manipulation even when every game in the lobby is certified. Any model that touches game surfacing or bonus eligibility belongs in the same audit scope as the RNG certificates, and regulators in several markets already require operators to explain automated marketing decisions.
Data privacy in casino AI systems
Behavioural models are only as defensible as the data governance under them. Player behaviour data is unusually sensitive: it can reveal financial distress, sleep patterns and mental health signals. Treat it accordingly.
| AI use case | What can go wrong | Practical safeguard |
|---|---|---|
| Harm detection scoring | Players labelled without recourse; false positives | Human review, appeal route, bias testing by segment |
| Personalised offers | Targeting distressed players | Suppress marketing for flagged accounts by policy |
| Behavioural modelling | Data used beyond stated consent | Purpose-specific consent, documented data register |
| Third party AI vendors | Player data leaving the operator’s control | Contractual limits, no training on raw player data |
| Chat and support bots | Missed disclosure of harm by a player | Escalation triggers to trained human staff |
The baseline duties are already familiar to Indian operators and suppliers working under the DPDP Act: lawful consent, purpose limitation, data minimisation, security safeguards, and breach notification. Add retention limits for behavioural data, access controls so marketing teams cannot query harm scores, and vendor terms that stop player data being absorbed into a third party’s training set.
The case for moving before the rules land
The commercial argument is straightforward. Regulators are writing AI rules now, and the study’s finding of an operator-regulator visibility gap means the operators who can already produce a model register, a bias testing log and an intervention audit trail will shape those rules rather than scramble to meet them. Documentation built voluntarily costs far less than documentation built under a compliance deadline.
There is a trust dividend too. Rick Arpin, KPMG’s U.S. gaming leader and the panel’s moderator, noted that AI can help suppliers know which game mechanics will land instead of guessing, and can strip cost out of back-office work like procurement price checks. Those gains depend on players and regulators accepting that operators handle data responsibly. One badly governed model that targets vulnerable customers undoes that goodwill across the sector, not just at one brand.
The honest summary of where the industry stands: the technology is ahead of the governance, and everybody on that stage knew it. Closing the gap is unglamorous work, a register, a policy, a test schedule, a named owner. It is also the difference between AI that protects players and AI that simply finds them faster.
If your own play has stopped feeling like entertainment, use the deposit limits, loss limits, cool-off and self-exclusion tools your operator is required to provide, and seek support from a recognised problem gambling helpline. Read more in our responsible gambling guide and our player protection resources.
Frequently asked questions
What is responsible AI in gambling?
It is the use of AI systems by gambling operators under documented rules covering transparency, human accountability, bias testing, data privacy and player protection. In practice it means knowing what every model does, who owns it, what data it uses, and what happens when it gets something wrong.
How can AI protect players?
By detecting behavioural markers of harm across large numbers of accounts and triggering defined interventions: limit prompts, session reminders, marketing suppression and escalation to trained staff. AI performs the monitoring at scale; people make the decisions that follow.
Why do casinos need AI ethics guidelines?
Because the same model that predicts marketing response can predict vulnerability. Without written rules, nothing in the technology prevents a harm signal from being used commercially. Guidelines also give operators something concrete to show regulators who are actively drafting AI rules.
What are the risks of unregulated AI use in gambling?
Targeting distressed players with offers, biased detection that misses whole groups of at-risk customers, opaque automated account decisions with no appeal, player behaviour data reused beyond consent, and over-reliance on models with no human review. Each is a reputational and regulatory exposure as much as an ethical one.
