• Updated:
  • Published:

AI in iGaming: chatbots went live first, KYC models are still rare

Denis Bolshakov
Denis Bolshakov

Editor-in-chief

Malta asked its licensees which AI systems they actually run, and the answer looks little like a vendor pitch deck.

On 18 September 2026 the Malta Gaming Authority published the AI Gaming Charter, written with the Malta Digital Innovation Authority (MDIA). Before setting out any principle, the 48-page document reports a study: a survey sent to every MGA licensee and in-depth interviews with a selected group.

The MGA itself calls the responses “a limited subset of the sector”, so the results are indicative. Even so, they give a rare regulator-level view of AI in iGaming, sorted by use case and by how far each one has moved past the pilot stage.

The picture is lopsided. AI runs mostly in analytics, operations and customer support, while player-facing decisions such as onboarding, payments and odds remain largely outside it. Governance trails even the adoption that exists, and the Charter now scores every system by how close it sits to the player.

Where iGaming uses AI today

The Charter groups use cases by how often respondents reported fully deployed systems or work beyond proof of concept, which produces three tiers of adoption.

Analytics, operations and support chatbots

Operational optimisation, data analytics and customer support chatbots are the most mature use cases in the Charter. In the interviews licensees described automated help desks, dynamic pricing, predictive maintenance and the automation of repetitive tasks. None of these systems decides anything about a player’s account.

Chatbots are also the most mature use case that faces the player directly. Section 3.2.1.1 expects players to know they are dealing with an AI system “at latest from the point of first interaction”. Section 3.6.1 lists when a conversation should pass to a person: repeated low-confidence answers, queries that escalate or stay unresolved, distress signals, signs of vulnerability or gambling harm, and direct requests for human support.

Coding assistants and creative tools

Part of the sector’s AI sits outside gaming functions altogether. Respondents named Claude Code and GitHub Copilot for software development, image and video generators for creative work, and compliance tools that track regulatory change and automate workflows. The Charter uses coding assistants as its standard example of a lower-impact tool that needs lighter governance.

Personalisation and marketing

Recommendation engines and player profiling reached deployment “to a lesser extent”, and several licensees still run them as minimum viable products. Interviewees described AI for tailored offers, segmentation and campaign analytics. The sharpest gap in the whole survey sits here: only a small number of respondents said they assess whether AI-driven personalisation increases risky or vulnerable behaviour, while others answered “partially” or were unsure.

Fraud, AML and responsible gambling

Fraud detection, AML and responsible gambling behavioural modelling share the middle tier. Machine learning flags suspicious activity and potential problem gambling in real time, and specialist vendors such as Mindway AI sell player-protection models to operators. Some B2C licensees told the MGA they never let AI decide account restrictions or responsible gambling flags, and some B2B suppliers have their own staff review alerts before they reach the client.

Odds, KYC, payments and live casino

Adoption is “far more limited” in dynamic odds setting and risk management, player onboarding and KYC, payments, player acquisition, regulatory reporting, HR and AI-powered live casino. For most of these areas respondents answered “not in use” or “not applicable”, although a few licensees test KYC, payments and acquisition models at MVP stage. The MGA reads the pattern as AI moving faster into “support, monitoring, and efficiency functions” than into “commercially sensitive or player-facing decision areas”.

Why governance lags adoption

Infrastructure is the easy part. Most respondents rated their technical setup as mature or adequate, citing cloud environments, low technical debt and AI already built into QA and security. The survey finds its gaps in the documentation and controls around the models.

Only a minority of licensees reported a formal AI strategy or roadmap, and a larger group is still drafting one. A majority have rules for data ownership, quality, access and retention, but fewer can document data lineage — the record of where a model’s data came from. Regular bias testing, impact measurement, AI literacy training and AI-specific incident processes are less developed still, and only a small number of respondents have a fully established AI risk assessment or incident-response plan.

Disclosure is thinner towards players than inside the company. Only a small number of organisations tell customers they use AI and ask for explicit consent to automated processing, while disclosure to employees is more common. Most respondents said a human always reviews AI-based decisions, which keeps AI in a support role in sensitive areas.

The B2B finding matters most for operators that buy AI in. Only one supplier respondent said it gives clients documentation on how its AI systems work. An operator running a third-party fraud or responsible gambling engine may be unable to explain that engine to its own regulator, because the explanation never left the supplier.

What Malta’s AI Gaming Charter changes

The Charter (document G-SPG-025-01) is voluntary and principles-based. It describes itself as one of the first initiatives in Europe to set AI principles for the gambling sector, adds no legal duties on top of the EU AI Act, GDPR or the EU Data Act, and uses wording such as “in accordance with applicable law” to separate existing obligations from good practice. Annex A maps each principle to the relevant provisions of the AI Act and GDPR.

The scope is wide. Internal and back-office AI is covered, while rules-based workflows and robotic process automation fall outside because they do not meet the AI Act’s definition of an AI system. Generative and agentic AI are in: Section 3.7.3 treats a system’s ability to take multi-step actions or use external tools as a risk factor in its own right.

Risk follows proximity to the player

Section 3.1 splits AI into two tiers. Lower-impact systems do internal, operational or administrative work and are unlikely to affect players, gaming integrity or regulated outcomes. Higher-impact systems are used in, or materially influence, player-facing, responsible gambling, fraud, AML, KYC, account restriction, eligibility or intervention decisions.

The scoring rule is the most quotable line in the document. Impact “should be based on the AI System’s proximity to the player and its potential effect on regulated outcomes, rather than solely on whether a human makes the final decision”. Human oversight “should not automatically reduce the applicable level of scrutiny where the AI System materially influences the outcome”.

Read against the survey, the rule targets the industry’s main reassurance. Most licensees rely on a person reviewing each model decision, yet under Section 3.1 a KYC model that flags an account for a freeze stays higher-impact even when a compliance officer clicks “approve”. A coding assistant that drafts test cases stays lower-impact however lightly anyone checks it. The tiers leave a system’s classification under the EU AI Act untouched, and safeguards must at least meet whatever that classification requires.

Six principles in Section 3

Section 3 sets out six principle areas, each with sub-sections on documentation, testing and oversight. Mapped against the survey, each one lands on a different part of the AI stack.

PrincipleWhat the Charter asksWhere it lands in iGaming
Transparency, accountability and explainability (3.2)Human-readable information on the role, purpose, limits and effects of each system; disclosure from first interactionSupport chatbots, synthetic content, supplier documentation for B2B clients
Fairness and non-discrimination (3.3)For higher-impact systems, a documented fairness objective, the reason for choosing it and how it is testedPlayer profiling, marketing and responsible gambling models
Environmental sustainability (3.4)Sustainable procurement, energy efficiency and a lower carbon footprint across training and deploymentChoice of hosted models, in-house training
Data protection, security and governance (3.5)GDPR compliance plus a data governance frameworkData lineage, the weakest point in the survey
Human oversight and responsibility (3.6)Staff who can monitor, understand and override the system, with training to matchChat escalation, account restrictions, responsible gambling flags
Reliability, safety and robustness (3.7)Testing before go-live; for higher-impact systems red-teaming, drift monitoring and tested rollback and kill-switch mechanismsFraud, AML, KYC and responsible gambling models

Transparency has a limit that matters to fraud and AML teams. The Charter does not require disclosure of source code, model architecture, trade secrets or sensitive fraud, AML or security logic where that would weaken the controls themselves.

AI washing, named in the text

The Charter defines AI washing as companies misrepresenting or exaggerating their AI capabilities “to enhance marketing appeal and gain a competitive advantage”. Section 3.2.1.1 lists three forms: presenting conventional software as AI, overstating how autonomous or sophisticated a system is, and marketing AI as a guarantee of fairness, accuracy or safety. Licensees “should communicate factually and proportionately” about what their systems do.

The clause reaches marketing teams as much as compliance. The scope rules make the first form easy to test: a rules-based alert engine falls outside the Charter’s definition of AI, so selling it as AI-powered is the textbook case. Some B2B suppliers in the survey already draw that line where humans programme the alerts. Claims such as “AI-driven KYC” or “fully automated player protection” now sit next to a public document that a supervisor can hold them against.

AI in market intelligence: how Blask builds its data

Market intelligence sits at the far end of the Charter’s scale from a KYC model, and Blask is a working example. It applies the Share of Search method, developed by Les Binet and James Hankins, to iGaming: billions of geo-tagged search queries from Google Keyword Planner and Google Trends become brand and market demand. Before a query counts, it passes an intent filter (“brand betting” stays in, “brand scam” drops out), a merge of spelling variants into one brand, a repeat collection of past periods because Google revises its data, and a seasonal adjustment.

Modelled layers sit on top. Blask Index measures demand, BAP (Brand Accumulated Power) gives a brand’s share of it, and APS (Acquisition Power Score) translates that share into an expected range of new customers using market-specific factors. CEB (Competitive Earning Baseline) converts the same inputs into a revenue baseline, anchored to regulator GGR in licensed markets and to ARPU benchmarks where no filings exist. A separate layer scans operator lobbies daily and recognises tens of thousands of games.

The market moves fast enough to make manual tracking impractical. Between January and September 2026 Blask added 811 brands to its tracking across 91 countries, and 369 of them went live in 2026.

For users the main gain is comparability. Licensed and offshore brands run through one framework, so a market without regulator data can be read next to one with full disclosures. Demand signals update hourly or daily, while regulator reports cover completed transactions with a lag. APS and CEB come as min / avg / max ranges, which keeps the uncertainty visible in the number itself.

Under Section 3.1 a system like this sits far from the player: it works on aggregated search and lobby data and makes no decision about any account, which places it in the lower-impact tier. The transparency asks in Section 3.2 still apply, and the methodology answers them by stating what each metric leaves out — Blask Index is neither GGR nor traffic, APS is no FTD count, and CEB is a baseline rather than reported revenue.

Where AI regulation in gambling goes next

Malta now has a finished framework, while the UK is at an earlier stage. The Gambling Commission set out its approach as an appendix to its corporate strategy: principles for its own use of AI, a low risk appetite, and an aim to understand and, where appropriate, regulate how the industry uses it. Its listed next step is policies, use-case templates and governance structures. In May 2025 KPMG argued that Malta could set standards for trustworthy AI in gaming and urged operators to build AI governance frameworks, and the Charter now puts that idea into the regulator’s own text.

The EU AI Act keeps classifying systems on its own track, which is why the Charter repeats that its two tiers change nothing in that Regulation. For other gambling authorities, Malta’s 48 pages are now a template to adopt, adapt or argue with.

Bottom line

AI in iGaming is today a back-office technology with a chatbot at the front door. The systems the Charter treats as higher-impact, such as KYC, account restrictions and eligibility, are still rare in production, and Malta has written its rules before most of them go live. The open question is whether the first licensees to adopt the Charter will be the ones with AI to govern or the ones with AI to market.

FAQ

How is AI used in iGaming?

According to the MGA’s licensee survey, mostly in operational optimisation, data analytics and customer support chatbots. Recommendation engines, player profiling, fraud, AML and responsible gambling models follow, while KYC, payments, dynamic odds and live casino remain rare.

Can AI be used in casinos?

Yes. Online operators use it for support, personalisation, fraud detection and player protection. In Malta the AI Gaming Charter expects stronger safeguards whenever a system influences player-facing or compliance decisions.

What is the MGA AI Gaming Charter?

A voluntary framework published by the MGA and MDIA on 18 September 2026. It sets six principle areas for AI use by licensees and maps them to the EU AI Act and GDPR.

What is AI washing?

Overstating the use, role or capabilities of AI in a product. The Charter names three forms: presenting conventional software as AI, overstating autonomy, and marketing AI as a guarantee of fairness, accuracy or safety.