Skip to content
Market Trends & Consumer Behaviour

Prediction markets: the questions to ask before rivals decide for you

Question Pack

AI in affordability decisioning: the governance questions to ask first

1. Issue

A growing number of operators are moving, or are being asked by regulators to consider moving, from fixed rule-based affordability and risk thresholds toward machine learning models that predict which customers are heading toward harm before a simple deposit or loss figure would ever flag them, and the board-level challenge is that this shift is happening faster than the governance frameworks needed to run it safely. The UK Gambling Commission’s own current financial vulnerability regime is still rules and data matching rather than predictive modelling, which matters because it shows even the most scrutinised regulator in this space has not yet mandated AI decisioning, leaving operators who move first to set their own standard for explainability, bias testing and human oversight without a regulator template to follow.

The stakes of getting that standard wrong are real and already documented. Peer reviewed research testing machine learning models against real account data from 945 European online casino players found the best performing model, a Random Forest classifier, reached an accuracy score of only 0.729, meaningfully short of the reliability a board would want before letting a model decide who gets contacted about their gambling and who does not, and the Gambling Commission’s own October 2025 review of casino casework found operators deploying algorithmic controls they did not fully understand, with models that had been misconfigured, that failed to escalate genuine risk indicators, and that left compliance staff unable to explain why a customer had been flagged at all when challenged.

2. Global Context

Regulators are approaching this from different starting points, and a board should read the direction of travel rather than assume today’s light touch position holds. The Malta Gaming Authority opened a consultation in May 2026 on a proposed AI Gaming Charter, voluntary and principles-based for now, with chief executive Charles Mizzi stating plainly that where AI informs an intervention or player protection measure, documented human review is essential to prevent unintended harm, which puts human oversight at the centre of Malta’s thinking even before any binding rule exists.

The UK Gambling Commission has published its own four principles for AI use, requiring systems to be lawful and transparent, aligned to the licensing objectives, subject to human oversight, and used only by staff with the necessary expertise, and separately its Director of Enforcement and Intelligence told an industry conference in June that operators need to be sure their AI compliance tools are actually doing what is required, because the evidence the Commission has seen so far is too often that they simply are not delivering, a warning aimed squarely at operators who have already gone further than the regulator has.

The European Union’s AI Act treats AI systems used to assess creditworthiness as high risk, requiring documented risk assessment, non discriminatory training data, activity logging and human oversight, obligations that begin to bite from December 2027, and while gambling affordability tools are not explicitly named in that high risk category, a specialist gaming law firm has advised operators to assess their own systems against the same standard now rather than wait to be told they must, noting that the most significant AI related fines issued anywhere so far have come from data protection regulators, not gambling ones, which is exactly the kind of accountability gap a board should not assume will stay open.

3. Boardroom Questions

1. Are we currently using, piloting, or actively considering any AI or machine learning model in affordability, risk, or player protection decisioning, and does the board have visibility of all three?

2. If challenged by a regulator, can our compliance staff explain in plain terms why a specific customer was flagged by our system, or does that explanation only exist inside the model itself?

3. Has our model been tested for bias across different customer groups, and who outside the team that built it reviewed those results?

4. What is our model’s documented accuracy rate, and would we be comfortable disclosing that figure to a regulator if asked?

5. Do we have a genuine human review step before any AI-generated flag leads to a customer-facing intervention, or does human review only happen after the fact if a customer complains?

6. If we rely on a third-party vendor for any part of this decisioning, do we understand their model well enough to defend it ourselves, or are we simply trusting their assurances?

7. Have we built a way for a customer to contest an automated decision and request meaningful human review, in line with the standard UK data protection law already requires?

8. Does giving customers or regulators a more detailed explanation of how our model works actually improve their ability to spot when it has got something wrong, or could more detail create false confidence instead?

9. Who owns AI governance in our organisation, and is that a cross-functional responsibility spanning compliance, legal, data and cybersecurity, or has it been left inside a single technical team?

10. What would a regulator find if they reviewed our AI system’s training data and configuration today, and have we run that review ourselves before they do?

Sources

1. Malta Gaming Authority, MGA launches targeted consultation on proposed AI Gaming Charter, May 2026, https://www.mga.org.mt/mga-launches-targeted-consultation-on-proposed-ai-gaming-charter/

2. UK Gambling Commission, The Commission’s approach to Artificial Intelligence, accessed July 2026, https://www.gamblingcommission.gov.uk/about-us/guide/page/the-commissions-approach-to-artificial-intelligence

3. NEXT.io, UKGC enforcement chief: AI compliance systems “not delivering”, 11 June 2026, https://next.io/news/regulation/ukgc-ai-compliance-systems-not-delivering/

4. UK Gambling Commission, Anti-money laundering and counter-terrorist financing casino casework trends: October 2025, https://www.gamblingcommission.gov.uk/licensees-and-businesses/guide/page/casino-casework-trends-october-2025

5. Information Commissioner’s Office, What is the impact of Article 22 of the UK GDPR on fairness, accessed July 2026, https://ico.org.uk/for-organisations/uk-gdpr-guidance-and-resources/artificial-intelligence/guidance-on-ai-and-data-protection/how-do-we-ensure-fairness-in-ai/what-is-the-impact-of-article-22-of-the-uk-gdpr-on-fairness/

6. Financial Conduct Authority, Research Note: Credit where credit is due, 24 February 2025, https://www.fca.org.uk/publication/research-notes/how-ai-role-credit-decisions-explained.pdf

7. European Commission, AI Act, Shaping Europe’s digital future, accessed July 2026, https://digital-strategy.ec.europa.eu/en/policies/regulatory-framework-ai

8. DLA Piper, Legal Obligations for Online Gambling Operators in the Use of Artificial Intelligence, 13 April 2025, https://www.dlapiper.com/en/insights/blogs/mse-today/2025/legal-obligations-for-online-gambling-operators-in-the-use-of-artificial-intelligence-ai

9. Auer, M. and Griffiths, M.D., Development and validation of a prediction model for online gambling problems based on players’ account data, Journal of Gambling Studies, published online 19 July 2022, https://link.springer.com/article/10.1007/s10899-022-10139-1