From a duty to a model
Regulators have required operators to identify customers at risk of harm for two decades, but until the 2020s the requirement was met with rules and human judgement: a deposit above a threshold, a support agent noticing distress. That has changed. Britain's customer-interaction rules, the Dutch duty of care, Ontario's standards, the Australian reforms and the American states' responsible-gaming plans now expect operators to monitor behaviour continuously across a defined set of indicators, to act in proportion to the risk, and to evaluate whether the action worked, at a volume no team can handle by hand. The answer is a model: a system that scores each account for markers of harm and prioritises the interactions. This lesson covers what such a model does, how it is built, what regulators expect of it, and where the hard questions are.
What the model predicts
The target is contested and matters. Three definitions are in use. Behavioural harm markers: the indicators regulators list (escalating deposits, chasing, session length, late-night play, cancelled withdrawals, declined payments, limit hits, customer statements), combined into a score. Future events that proxy harm: self-exclusion, a complaint of harm, a request for help, a chargeback citing gambling, account closure with a harm reason. Validated screens: scores on instruments such as the Problem Gambling Severity Index, obtained from a sample of customers who complete a survey and used to label the behaviour of everyone else. The first is transparent and directly maps to the rules; the second gives a model something concrete to predict but is rare and late; the third is closest to harm as clinicians define it but depends on a sample that may not represent the base. Operators use combinations, and the choice of target is the first thing a regulator or auditor will ask about.
Features and architecture
The features are the account's behaviour over time: deposits and their trend, withdrawals and cancellations, stakes and their escalation, session timing and duration, product mix and moves to higher-volatility products, limit changes, promotional response, payment declines, support contacts and their content, and, where the operator has it, affordability information. Real-time features (this session's stakes against the customer's norm) matter as much as historical ones, because the interaction that regulators expect is one that happens during the session in which harm is showing. The architecture is therefore a streaming one: events scored as they arrive, a risk score maintained per account, thresholds and rules that trigger interactions, and a record of every score, trigger, action and outcome for the audit trail.
Interactions and evaluation
A score is only useful if something happens. The interaction ladder runs from automated messages (a safer-gambling prompt, a reality check, a suggested limit) through personal contact (a call or email from a trained team), to imposed measures (a limit, a cooling-off, a suspension) and, where the market requires it, an affordability or source-of-funds check. The model prioritises which accounts get which rung, and the rules set the floor: certain markers must trigger certain actions regardless of the score, and certain customers (young adults, in Britain) trigger earlier.
Evaluation is the hard part and the part regulators now examine. Did the interaction reduce the behaviour? Operators measure the change in deposits, session length and markers after an interaction against a comparison group, and report the results in their regulatory returns and to their boards. The ethical constraint on evaluation is that randomised holdouts of at-risk customers, the cleanest method, mean deliberately not interacting with some people showing harm; the practice that has emerged is to randomise the form and timing of the interaction rather than whether it happens.
What regulators expect
The expectations have converged across markets and are specific enough to audit against.
Coverage. All customers, all products, all channels, in real time or near it, with the regulator's listed indicators as a minimum.
Proportionality. Action scaled to risk, with escalation for repeat or severe markers, and documented thresholds.
Evidence. A record of scores, triggers, actions and outcomes per customer that the regulator can inspect, and aggregate reporting in returns.
Evaluation. Measurement of whether interactions work, with adjustments where they do not.
Explainability. The ability to say why a customer was flagged, to the customer where appropriate and to the regulator always; opaque models are a compliance risk in themselves.
Primacy. Protection scores applied before commercial ones: no promotion, no reactivation, no VIP treatment for a customer the harm model has flagged, with the suppression audited.
Governance. A named owner, documented methodology, validation, monitoring for drift and bias, and board-level reporting. Britain's Commission, the Dutch authority and Ontario's regulator have each published guidance or expectations in these terms, and enforcement cases have turned on their absence.
The single customer view
A customer at risk may hold accounts with several operators, and no single operator sees the whole picture. Britain has piloted a cross-operator data-sharing scheme, the single customer view, under which participating operators share risk indicators for high-risk customers through a central system so that each can act on the combined picture; Germany's LUGAS enforces a cross-operator deposit limit centrally; and the Netherlands' mandatory limits are per operator with the KSA examining cross-operator effects. The single customer view is the logical end-point of harm modelling, and it raises the data-protection and competition questions that lesson six covers.
Hard questions
Several problems remain open and an honest course says so. False positives impose friction on customers who are not at risk, and friction moves customers to unlicensed sites; the trade-off is set by the regulator's tolerance and the operator's, and neither has a settled number. Bias: models trained on operator data reflect which customers were flagged before, and may under-detect harm in groups whose behaviour differs from the historical flagged population. Gaming: customers learn what triggers checks and adapt. Commercial conflict: the operator building the harm model also profits from the customers it flags, and the model's thresholds are set by that operator; independent validation and regulator inspection are the answer offered, and the debate about whether that is enough continues. And the most fundamental: behavioural markers are proxies for harm, not measurements of it, and a model that optimises the proxies may or may not reduce the harm.
What to take from this lesson
Player-protection models score accounts for markers of harm in real time and prioritise interactions, replacing threshold rules and manual judgement at volumes regulators now require. The prediction target (behavioural markers, proxy events or validated screens) is contested and matters. The architecture is streaming, the interactions run on a ladder from prompts to imposed measures, and evaluation measures behaviour change after interaction. Regulators expect coverage, proportionality, evidence, evaluation, explainability, primacy over commercial models and governance. Cross-operator systems (Britain's single customer view, Germany's LUGAS) are the end-point. False positives, bias, gaming, commercial conflict and the gap between proxies and harm remain open.