The obligations attach to the operator
Every model described in this course makes or shapes decisions about people: who receives an offer, whose account is restricted, who is flagged for harm, whose identity is accepted. Law and regulation now attach obligations to those decisions, and the obligations sit with the operator that makes them, not with the supplier whose model it used. This lesson sets out the three legal frameworks that apply (data protection, the EU's AI Act, and gambling regulators' own expectations), the governance an operator needs to meet them, and the practical programme for running models responsibly.
Data protection and automated decisions
The GDPR and its British and other equivalents govern every model that processes personal data, which in gambling is all of them. Three provisions bite hardest. Profiling and automated decision-making: a decision based solely on automated processing that produces legal or similarly significant effects (restricting an account, refusing a withdrawal, denying verification, imposing a limit) is restricted, requires a lawful basis (contract, legal obligation, or explicit consent), and gives the individual the right to human intervention, to express their view and to contest. Transparency: privacy notices must explain the profiling, and individuals have a right to meaningful information about the logic involved and the significance and envisaged consequences. Impact assessment: high-risk processing, which profiling for harm, fraud or value plainly is, requires a documented data-protection impact assessment before it starts.
The practical consequence is the layered design the earlier lessons describe: models score and prioritise, humans decide the significant cases, the logic is documented in terms a customer can be given, and the assessments exist before deployment. Regulators have fined gambling companies for data-protection failures, and the data-protection authority, not the gambling regulator, enforces this layer.
The EU AI Act
The Artificial Intelligence Act, in force since August 2024 with obligations phased in, is the first comprehensive AI law and it applies to any operator or supplier placing AI systems on the EU market or affecting people in the EU. Its structure is risk-based. Prohibited practices (in force since February 2025) include manipulative or deceptive techniques that distort behaviour causing significant harm, and exploitation of vulnerabilities due to age, disability or social or economic situation; a personalisation system that targeted customers showing signs of gambling harm with inducements would be examined against exactly these provisions. High-risk systems (obligations now deferred to December 2027 for stand-alone systems under the 2026 amending regulation) carry requirements for risk management, data governance, documentation, human oversight, accuracy and robustness; the listed high-risk categories do not name gambling, but include creditworthiness assessment and, arguably, systems evaluating access to essential services, and the classification of harm-monitoring or affordability models is a live question the operator must document a view on. Transparency obligations (in force from August 2026) require that people be told when they interact with an AI system, that generated content be labelled, and that deepfakes be disclosed, which reaches customer-service assistants and generated marketing directly. General-purpose model obligations (since August 2025) sit with the model providers.
For a gambling operator the AI Act's practical demands in 2026 are the prohibited-practices analysis of every customer-facing model, the transparency labelling of assistants and generated content, and a documented classification of each system with the high-risk programme prepared for December 2027.
Gambling regulators
Gambling regulators have added their own layer, mostly through existing licence conditions rather than new rules. Britain's Commission has published its approach to artificial intelligence, expects licensees to understand and control the algorithms they use for customer interaction and marketing, and has named AI-driven identity fraud in its 2026 risk assessment; its customer-interaction guidance requires explainable, evaluated, evidenced monitoring, which is a model-governance standard in all but name. The Dutch authority has examined operators' duty-of-care systems and their personalised marketing. Ontario's standards require that algorithms used for marketing not target at-risk players and that operators be able to explain them. The American states' regulations on advertising and responsible gaming reach the models behind them, and the proposed federal SAFE Bet Act would restrict AI in marketing and in tracking bettors explicitly. Sports integrity bodies and the betting industry's own codes address automated trading and market surveillance. The direction across all of them is the same: an operator must know what its models do, be able to explain them, evaluate them, and show that protection takes precedence over commerce.
The governance programme
What an operator needs, in practice, is a model-governance function that mirrors the compliance functions it already runs.
Inventory. A register of every model and AI system in use, including suppliers' models embedded in platforms and vendors' services: purpose, owner, data used, decisions affected, classification under the AI Act and data-protection law, and validation status.
Ownership and accountability. A named owner for each model, a senior executive accountable for the programme, and board reporting; in Britain the personal-licence framework makes the accountability personal.
Documentation. For each model: the problem, the target definition, the data and features, the training and validation method, performance by segment, the decision logic, the human-oversight design, the monitoring plan and the review schedule. This is the file the regulator, the auditor and the data-protection authority will ask for.
Validation and bias testing. Independent review of performance and of differential impact across groups (age, gender, geography, product) before deployment and on a cycle, with documented remediation.
Monitoring and drift. Continuous measurement of model inputs and outputs against baselines, with alerts and retraining triggers; adversarial models drift fastest.
Human oversight. Defined points where a person reviews or decides, with the authority to override, and records of overrides.
Supplier management. Contracts that oblige vendors to disclose model use, performance, bias testing and changes, and that allocate responsibility; the operator remains accountable to regulators regardless.
Transparency. Privacy notices, customer explanations, AI-interaction and generated-content labelling, and a process for individuals to contest decisions.
Incident management. Model failures (a harm model that stopped scoring, a fraud model that blocked a market, an assistant that gave wrong terms) treated as incidents with root-cause analysis and, where the effect is significant, regulatory reporting.
Running generative tools responsibly
Generative models add specific controls: grounding in the operator's own approved content rather than general knowledge; hard rules on topics the model must escalate (harm, complaints, disputes, legal questions) and must not touch (encouraging deposits, discussing odds of winning); logging of every interaction for review; testing against adversarial prompts; disclosure to the customer; and a review process for generated marketing that treats it exactly as human-written copy under the advertising code. The principle is that the model is a drafting and routing tool inside a compliance process, not a substitute for it.
What to take from this lesson
Obligations attach to the operator's decisions, not the supplier's models. Data-protection law restricts solely automated significant decisions, requires transparency about profiling logic and impact assessments, and is enforced by data-protection authorities. The EU AI Act prohibits manipulative and vulnerability-exploiting practices (since February 2025), requires transparency and labelling for assistants and generated content (from August 2026), and applies high-risk obligations from December 2027, with operators needing a documented classification now. Gambling regulators require explainable, evaluated, evidenced models with protection ahead of commerce. The governance programme is an inventory, ownership, documentation, validation and bias testing, drift monitoring, human oversight, supplier management, transparency and incident management, with generative tools grounded, escalated, logged and reviewed like any other regulated content.