IGAMING REGULATION • 2026

EU AI Act and iGaming: AI Regulation, UKGC & KSA Compliance

How the EU AI Act affects AI systems used in online gambling, what operators need to understand about risk classification, and how UKGC and KSA oversight is approaching AI, behavioural monitoring, AML and player protection in 2026.

Updated September 2026 AI Act UKGC KSA iGaming Compliance
Quick answer

The EU AI Act does matter to iGaming, but not in the way many articles suggest. It does not create a universal requirement for online casinos to submit their complete source code to independent testing laboratories. Instead, operators and technology providers need to determine whether particular AI systems fall within the Act, understand the relevant obligations and maintain appropriate governance. Separately, gambling regulators such as the UK Gambling Commission and the Dutch KSA are increasingly examining how operators use algorithms, AI and behavioural monitoring in areas such as AML and player protection.

Why AI Compliance Has Become an iGaming Issue

Artificial intelligence is increasingly used across online gambling operations. It can appear in customer support, fraud detection, AML controls, identity verification, marketing personalisation, risk scoring, recommendation systems and customer-interaction tools.

That creates two related but different regulatory questions. The first is whether an AI system falls within the European Union’s AI Act and, if so, which obligations apply. The second is whether the way an operator uses algorithms complies with gambling-specific rules covering areas such as AML, customer protection and responsible gambling.

These questions should not be collapsed into one idea of “AI-regulated casinos”. The EU AI Act and national gambling regulation operate through different legal frameworks.

Important distinction

A casino’s AI-based recommendation engine, an AML risk model and the mathematics of a game such as JetX are three different technical and regulatory subjects. They should not be treated as one system simply because all three involve software.

Does the EU AI Act Apply to Online Gambling?

Potentially, yes. The AI Act applies according to the role and location of providers, deployers and affected parties, as well as the nature and intended use of the AI system.

The regulation uses a risk-based framework rather than applying the same requirements to every AI application. The framework includes prohibited AI practices, high-risk systems, transparency obligations and systems presenting minimal or no risk.

Risk category

Prohibited practices

Certain AI practices are prohibited because of the risks they create for people and fundamental rights.

Risk category

High-risk AI

Specific high-risk use cases are subject to requirements such as risk management, documentation, testing and human oversight.

Transparency

AI interaction disclosure

Certain AI systems have transparency obligations, including situations where people need to know they are interacting with AI.

Minimal risk

Many ordinary AI applications

A large number of AI systems fall outside the high-risk categories and do not receive the same regulatory burden.

For iGaming businesses, the first practical task is therefore not “audit everything”. It is to create an inventory of AI systems and determine what each system actually does.

Are Casino Recommendation Algorithms Automatically High Risk?

No. A recommendation or personalisation system is not automatically classified as high-risk simply because it uses customer data, behavioural information or machine learning.

Article 6 of the AI Act defines specific routes into the high-risk category. For systems covered by Annex III, the regulation also provides exceptions where the system does not pose a significant risk of harm, subject to the conditions in the regulation. However, an Annex III system is always considered high-risk when it performs profiling of natural persons.

That distinction matters for iGaming because operators can use several different types of algorithmic systems. A recommendation engine suggesting games is not automatically equivalent to an AI system making a regulated high-risk decision.

System What needs to be assessed? Key question
Game recommendation Purpose, data, impact and applicable AI Act category Does the system fall within a regulated use case?
Player risk model Profiling, decision-making and affected rights What decisions does the model influence?
AML model Gambling regulation, AML requirements and AI obligations Can the operator explain and govern the control?
Customer-support chatbot Transparency obligations and general AI governance Does the user know they are interacting with AI where required?

KSA and AI in Dutch Online Gambling

The Dutch Gambling Authority (Kansspelautoriteit, KSA) is taking a particularly relevant approach to AI through its broader supervision of player protection and duty of care.

In its 2026 supervisory agenda, the KSA identified duty of care as a key priority and said it would examine not only what operators monitor but also how quickly they intervene. The regulator also stated that it planned to issue guidance on the use of AI and automated monitoring tools.

This is important for operators using behavioural models. The regulatory question is not simply whether a company has an AI system. It is whether its monitoring and intervention processes work appropriately within the operator’s legal duties.

Player protection

Behavioural monitoring

Operators need to understand which indicators they monitor and how those indicators feed into intervention decisions.

AI governance

Automated monitoring tools

AI and automated monitoring are becoming part of the KSA’s supervisory conversation rather than an isolated technology issue.

UKGC and Artificial Intelligence in Gambling

The UK Gambling Commission has published a specific approach to artificial intelligence and states that it expects to encounter AI both in the gambling industry and in its own regulatory work.

The Commission’s principles include lawful use, appropriate transparency and responsibility, consistency with licensing objectives, human intervention and governance, and the use of AI by people with appropriate skills and expertise.

AI is also directly relevant to current AML and customer due diligence risks. The UKGC’s 2026 risk assessment highlights the increasing sophistication of AI-assisted attempts to bypass CDD, including false documentation, deepfakes and face swaps.

Does the UKGC Require Online Casinos to Submit Their Source Code?

There is no general UKGC rule requiring every licensed online casino to submit its entire source code to an independent certified laboratory simply because it uses AI.

The distinction is important. In published AML casework, the UKGC says it may ask for information about an algorithm’s methodology during compliance assessments to determine whether an AML control is appropriate and effectively implemented.

That is a much narrower and more practical requirement than a universal source-code audit.

What this means in practice

Operators should be able to explain what an algorithm is intended to do, what risks it addresses, how it is governed and whether it works as intended. The exact technical evidence required will depend on the regulatory context and the control being examined.

AI, Player Protection and Personalisation

Personalisation is one of the most obvious uses of AI in online gambling. Systems can analyse previous activity and use that information to recommend content, identify unusual behaviour or support customer-interaction processes.

The compliance question becomes more significant when an automated system materially influences decisions affecting a player.

Questions operators should document

1
Purpose: What exactly is the model designed to achieve?
2
Inputs: What categories of player or transaction data are used?
3
Output: Does the model merely recommend something, or does it influence a decision about an account or player?
4
Human oversight: When is a person expected to review or override the system?
5
Testing: How does the operator verify that the system continues to work as intended?
6
Records: What evidence exists to demonstrate how the system is governed?

AI, AML, KYC and Fraud Detection

AML is currently one of the clearest areas where gambling regulators are openly discussing AI and algorithmic controls.

The UKGC has reported increased use of AI, algorithms and behavioural models for AML purposes. These systems can identify potential money-laundering or terrorist-financing red flags within customer profiles or behaviour and may contribute to a customer risk rating.

The regulator’s concern is not simply whether an operator bought an AI product. Operators remain responsible for understanding their controls and ensuring that they are appropriate and effectively implemented.

Why this matters

A model that produces a risk score is still part of a regulated business process. The operator needs to understand the role that score plays, what happens after it is generated and whether the overall control addresses the risks identified by the operator.

AI Monitoring, Personal Data and GDPR

AI compliance does not replace data-protection compliance. Gambling operators using behavioural data must consider the applicable GDPR requirements alongside gambling and AI regulation.

It is also important not to describe all telemetry as automatically anonymous. Data can remain personal data even when direct identifiers are removed if individuals can still be identified or singled out.

For AI systems using player information, operators should therefore document the data involved, the purpose of processing, access controls, retention practices and the relevant legal basis and safeguards.

AI Act and GDPR are different frameworks

The AI Act governs certain AI systems and practices. GDPR governs the processing of personal data. An operator may need to comply with both, depending on what its system does and what data it processes.

AI Personalisation and Casino Bonuses

Bonus personalisation deserves separate attention because an algorithm can potentially influence which commercial offers are presented to different customers.

That does not mean that the EU AI Act automatically imposes a universal wagering cap, mandatory cooling-off period or specific bonus structure on online casinos.

Any commercial personalisation system should instead be assessed according to its actual function, the data it uses and the gambling, consumer-protection, privacy and AI rules applicable to the operator’s market.

What should be transparent?

Operators should be able to explain the commercial logic of personalised offers sufficiently for internal governance and applicable regulatory requirements. They should also avoid presenting invented technical limits as though they were requirements imposed by the EU AI Act.

Does the EU AI Act Regulate the JetX Game Algorithm?

This is where two different technical subjects are often mixed together.

JetX is a game developed by SmartSoft Gaming. SmartSoft describes JetX as an RNG-based crash game in which the multiplier is generated randomly. The game provides manual and automatic betting, two independent bets per round and manual or automatic cashout.

That game mechanic should not automatically be described as an “AI system”. AI regulation of an operator’s recommendation, customer-risk or monitoring system is a separate question from the mathematical and technical implementation of the game itself.

Do not confuse the layers

Game mathematics, RNG technology, AI-based player profiling and casino compliance systems can interact with the same website, but they are not automatically the same technology or subject to the same regulation.

For a separate explanation of JetX mechanics, see how JetX works and our crash-game RTP and mathematics guide.

EU AI Act Timeline for iGaming in 2026–2028

One of the easiest ways to misunderstand the AI Act is to treat all obligations as though they started on one date. The implementation is staged.

2 Aug 2026
Selected AI Act rules start applying Enforcement of prohibited AI practices, certain transparency requirements and other provisions begins according to the Act’s implementation timetable.
2 Dec 2026
Additional transparency-related provisions Further provisions enter application under the staged implementation schedule.
2 Dec 2027
High-risk AI obligations The main high-risk framework is scheduled to apply, including requirements around risk management, documentation, logging, human oversight, robustness and related controls.
2 Aug 2028
High-risk AI in regulated products A later stage applies to certain high-risk AI systems embedded in products covered by the relevant EU product legislation.

What Should an iGaming Operator Actually Document?

Instead of starting with a generic “AI audit”, an operator can build an inventory of every material AI or algorithmic control used across the business.

1
AI system inventory: list systems used for support, AML, KYC, fraud detection, personalisation and other material processes.
2
Purpose and ownership: identify what each system does and which business function is responsible for it.
3
Risk classification: assess whether the AI Act applies and which category is relevant.
4
Data map: record what information enters the system and how outputs are used.
5
Human oversight: document where human review, intervention or escalation occurs.
6
Testing and monitoring: establish how performance, errors and changes are identified.
7
Supplier governance: understand what third-party AI providers actually supply and what responsibility remains with the operator.
8
Regulatory evidence: keep documentation showing how the relevant controls are implemented and reviewed.

What Does AI Regulation Mean for Casino Players?

For players, the practical effect is less about seeing an “AI-compliant casino” badge and more about how an operator handles automated systems behind the account.

AI may be used for identity checks, fraud prevention, AML monitoring, customer support, marketing personalisation or responsible-gambling processes. The exact technologies differ between operators and jurisdictions.

Players should therefore avoid assuming that every automated decision is an AI Act issue, or that an operator using AI is automatically non-compliant. Regulatory compliance depends on the actual system, its purpose, the data involved and the legal framework applicable to that operator.

Common AI Compliance Claims That Need Context

Claim More accurate interpretation
“Every casino AI system is high-risk.” No. The AI Act uses specific risk categories and use cases.
“The EU now audits every casino source codebase.” There is no general AI Act rule requiring every casino to submit its complete source code for independent audit.
“AI bonuses are capped at 10x under EU law.” This is not a general EU AI Act requirement.
“AI telemetry automatically becomes anonymous.” Removing obvious identifiers does not automatically make data anonymous under GDPR.
“The AI Act regulates JetX’s crash algorithm.” AI regulation and game technology are separate issues unless the relevant software actually falls within the AI Act.
“UKGC demands full source code from every AI casino.” UKGC casework shows that the regulator may request information about algorithm methodology for relevant compliance controls.

EU AI Act and iGaming: The Practical Picture in 2026

AI is becoming a genuine compliance issue for the online gambling industry, but the regulatory picture is more nuanced than the idea of a universal casino source-code audit.

The EU AI Act introduces a risk-based framework for AI systems, while gambling regulators continue to focus on their own areas: player protection, AML, customer due diligence, responsible gambling, governance and effective controls.

For operators, the practical response is to understand what AI systems are actually being used, document their purpose and data, assess applicable obligations, maintain appropriate governance and retain evidence that controls work as intended.

For players, the important distinction is between an operator’s AI and compliance infrastructure and the underlying mechanics of a particular gambling game. Those are separate technical layers and should be evaluated separately.

EU AI Act and iGaming FAQ

It can apply to AI systems used by gambling businesses where the relevant conditions of the AI Act are met. It does not automatically impose the same obligations on every software system used by an online casino.

Not automatically. Classification depends on the relevant AI Act provisions, intended use and risk category. Systems covered by certain Annex III use cases can be high-risk, with specific rules also applying to profiling in the circumstances defined by Article 6.

There is no general rule requiring every online casino to submit its complete source code to an independent laboratory simply because it uses AI.

The UK Gambling Commission has published an AI approach covering lawful and responsible use, transparency, human intervention, governance and appropriate expertise. It is also examining AI and algorithms used in areas such as AML.

Yes. UKGC AML casework states that during compliance assessments it may ask for information about an algorithm’s methodology to assess whether the relevant control is appropriate and effectively implemented.

The Dutch KSA has identified AI and automated monitoring tools as part of its 2026 supervisory agenda, particularly in the context of duty of care and monitoring player behaviour.

JetX’s game mechanics should not automatically be classified as AI simply because the game is software-based. SmartSoft describes JetX as an RNG-based crash game. AI used elsewhere by a casino operator is a separate regulatory question.

No. A universal 10x wagering cap or mandatory one-hour cooling-off period should not be presented as a general requirement of the EU AI Act.

No. GDPR and the EU AI Act are separate legal frameworks. Depending on the system and data involved, an operator may need to comply with both.

Under the current staged timetable, the main high-risk AI obligations are scheduled to apply from 2 December 2027, subject to the specific provisions and implementation rules relevant to the system.

Regulatory Sources

European Union — AI Act

Regulation (EU) 2024/1689 and current European Commission implementation guidance should be used for the definitive interpretation of AI Act obligations and timelines.

UK Gambling Commission

The UKGC publishes its approach to AI and specific casework covering AI, algorithms and behavioural models used for AML controls.

Dutch Gambling Authority (KSA)

The KSA’s 2026 supervisory agenda places significant emphasis on duty of care, behavioural monitoring and the future use of AI and automated monitoring tools.

Editorial disclosure: JetX.Casino is an independent informational website. We are not the operator of JetX, SmartSoft Gaming or any casino discussed on this website. Regulatory requirements can differ by jurisdiction and may change as legislation and regulator guidance develop. This article is intended as general information and is not legal advice.

Leave a Comment