The adoption of AI tools in compliance, risk, and operational functions has accelerated significantly in the past two years. Automated document verification, transaction monitoring models, behavioural risk scoring, and responsible gambling signal engines are now common features of regulated gaming and financial services environments. What is less common is a governance framework that adequately addresses the specific obligations that attach to AI use in regulated contexts.
The EU AI Act entered into force in August 2024 and its requirements are now being phased into application. For regulated businesses operating in or serving EU markets, this is not a future planning exercise — it is a current compliance obligation. Many organisations have adopted AI tools faster than they have developed the frameworks to govern them, creating a gap that regulators are beginning to identify as a systemic risk.
The EU AI Act: What Regulated Businesses Actually Need to Know
The EU AI Act establishes a risk-based classification framework for AI systems. The classification determines the obligations that apply, and for businesses in regulated industries, the classification of their AI tools is the starting point for every governance question that follows.
The practical question for most regulated gaming and financial services businesses is whether their AI tools fall into the high-risk category. The answer depends on the specific function — and several functions common in regulated business are either explicitly listed or plausibly within the high-risk perimeter.
AI systems used for creditworthiness assessment, risk scoring of individuals in essential services contexts, and employee monitoring may fall within Annex III high-risk classifications. For gaming operators using AI-powered responsible gambling scoring or AML risk models, legal review of classification is not optional — it is the starting point of the compliance exercise.
High-Risk AI System Obligations in Practice
Where an AI system is classified as high-risk, the obligations are substantial. They include requirements that many regulated businesses have not yet fully considered:
- Risk management system: A documented, ongoing risk management process for the AI system itself — separate from the business's broader risk framework, covering risks arising from the AI's outputs and limitations.
- Data governance: Training, validation, and test datasets must meet quality criteria. Biases must be identified and addressed. Data governance documentation must be maintained.
- Technical documentation: Detailed documentation of the system's design, development, testing, and performance — sufficient to demonstrate conformity to a regulatory authority.
- Automatic logging: High-risk systems must automatically log events during operation, enabling post-hoc audit of how the system performed in specific decisions.
- Transparency to users: The system must provide information enabling deployers to understand what it does and interpret its outputs.
- Human oversight: The system must be designed to allow human intervention, override, and monitoring. Fully autonomous decisions in high-risk contexts are not permitted.
- Accuracy, robustness, and cybersecurity: Performance standards must be maintained and tested. Adversarial robustness — resistance to manipulation of inputs to produce incorrect outputs — is specifically required.
Explainability: The Compliance Challenge Nobody Is Ready For
Explainability — the ability to describe how an AI system reached a specific output — is required for high-risk AI systems and is also directly relevant under GDPR Article 22, which governs automated decision-making with significant effects on individuals. For regulated businesses using AI in customer-facing risk decisions, the intersection of these two obligations creates a specific compliance challenge that most have not adequately addressed.
"If you cannot explain in plain terms why your AI model flagged a specific customer, you cannot satisfy a data subject access request, a regulatory inquiry, or a legal challenge. Explainability is not a technical nice-to-have — it is a compliance requirement."
The explainability obligation applies at two levels. At the system level, the developer or deployer must be able to describe the model's general logic and the factors it weights in reaching outputs. At the individual decision level, they must be able to explain why the system produced a specific output for a specific input. The second requirement is significantly more demanding and is where many black-box machine learning models create legal exposure.
For compliance teams, the practical questions to address are:
- Can we describe in plain terms what each AI tool does and what factors it considers?
- Can we explain, for any specific AI-influenced decision, what inputs drove the output?
- Do we have a process for responding to a data subject access request that includes AI-generated risk scores or classifications?
- Is there a documented human review process for AI outputs that affect customer access, credit, or services?
Bias and Fairness in Player Profiling
AI-driven player profiling and responsible gambling scoring systems can exhibit bias if the training data reflects historical patterns that correlate with protected characteristics. A model trained predominantly on data from one demographic group may produce systematically different risk scores for individuals from other groups, even when their actual behaviour is equivalent.
In a regulated gaming environment, this creates intersecting obligations. The AI Act requires bias identification and mitigation for high-risk systems. GDPR prohibits automated decision-making based on protected characteristics. Equality legislation in most jurisdictions prohibits discriminatory treatment in service delivery. A player profiling system that produces systematically different responsible gambling flags or VIP access decisions for individuals of different protected characteristics is exposure across all three frameworks simultaneously.
The minimum governance standard for AI-driven player profiling includes regular bias audits against demographic variables, documentation of the audit methodology and findings, and a remediation process for identified bias. For operators using third-party AI tools, this obligation does not transfer to the vendor — the deployer remains responsible for bias in the outputs as applied to their customer base.
AML Model Validation: The Underrated Requirement
Transaction monitoring systems using machine learning or rule-based AI components require validation to demonstrate that they are performing as intended. Regulatory guidance across multiple jurisdictions now explicitly expects documentation of model validation — the process of testing whether the model actually detects the risks it is designed to detect, at the calibration levels applied.
Model validation for AML purposes covers:
- Alert rate assessment: Is the true positive rate (genuine suspicious activity alerts) acceptable relative to the false positive rate (alerts that turn out to be benign)? An extremely high false positive rate indicates poor calibration; an extremely low rate may indicate under-detection.
- Scenario coverage: Does the model include scenarios that reflect current typologies for the business's specific risk profile? A model that does not include scenarios relevant to the business's actual exposure is not adequate regardless of its technical sophistication.
- Threshold justification: Are the thresholds at which alerts are triggered documented and justified by reference to the risk assessment? Arbitrary threshold selection is a common finding in regulatory inspections.
- Ongoing performance monitoring: Is there a documented process for monitoring model performance over time and updating configuration in response to changes in the customer base, transaction patterns, or typology landscape?
GDPR and AI: The Overlap That Matters
The intersection of GDPR and AI use in regulated business is not a niche technical question — it is a central compliance obligation. The key provisions to integrate into AI governance frameworks are Article 5 (purpose limitation and data minimisation), Article 22 (automated decision-making), and Article 35 (data protection impact assessments for high-risk processing).
For most AI use in regulated business contexts, a Data Protection Impact Assessment is required before deployment. The DPIA must identify the specific risks arising from the AI processing, assess their likelihood and severity, and document the measures in place to mitigate them. A DPIA completed at the point of AI tool procurement that is never subsequently reviewed does not satisfy the requirement for an ongoing, risk-responsive process.
AI governance review for regulated businesses
Wise Key Solutions provides AI governance assessments covering EU AI Act classification, GDPR intersection, explainability obligations, and AML model validation requirements. Contact us to discuss a review for your AI tools.
Speak to our team →This article reflects the operational perspective of the Wise Key Solutions founding team. It does not constitute legal or regulatory advice. Regulated businesses should obtain specialist legal advice on AI Act classification and obligations relevant to their specific deployment contexts.