AI & Governance

AI Governance in Regulated Business: Beyond the Hype

AI tools are entering compliance workflows at pace. Regulated businesses face obligations they may not yet understand — and regulators are watching.

AI & Governance 9 min read

The adoption of AI tools in compliance, risk, and operational functions has accelerated significantly in the past two years. Automated document verification, transaction monitoring models, behavioural risk scoring, and responsible gambling signal engines are now common features of regulated gaming and financial services environments. What is less common is a governance framework that adequately addresses the specific obligations that attach to AI use in regulated contexts.

The EU AI Act entered into force in August 2024 and its requirements are now being phased into application. For regulated businesses operating in or serving EU markets, this is not a future planning exercise — it is a current compliance obligation. Many organisations have adopted AI tools faster than they have developed the frameworks to govern them, creating a gap that regulators are beginning to identify as a systemic risk.

The EU AI Act: What Regulated Businesses Actually Need to Know

The EU AI Act establishes a risk-based classification framework for AI systems. The classification determines the obligations that apply, and for businesses in regulated industries, the classification of their AI tools is the starting point for every governance question that follows.

🚫
Prohibited AI
Systems that manipulate behaviour, exploit vulnerabilities, or enable mass social scoring. Banned entirely. Some biometric categorisation systems fall here.
⚠️
High-Risk AI
Systems in critical infrastructure, employment, credit, essential services, or law enforcement adjacent functions. Extensive obligations including conformity assessment, logging, human oversight, and transparency.
📋
Limited-Risk AI
Systems interacting with humans (chatbots, deepfakes). Transparency obligations apply — users must know they are interacting with AI.
Minimal-Risk AI
Most AI applications. No specific obligations under the Act, though general GDPR and sector-specific rules still apply.

The practical question for most regulated gaming and financial services businesses is whether their AI tools fall into the high-risk category. The answer depends on the specific function — and several functions common in regulated business are either explicitly listed or plausibly within the high-risk perimeter.

High-Risk Classification Watch

AI systems used for creditworthiness assessment, risk scoring of individuals in essential services contexts, and employee monitoring may fall within Annex III high-risk classifications. For gaming operators using AI-powered responsible gambling scoring or AML risk models, legal review of classification is not optional — it is the starting point of the compliance exercise.

High-Risk AI System Obligations in Practice

Where an AI system is classified as high-risk, the obligations are substantial. They include requirements that many regulated businesses have not yet fully considered:

€35M maximum fine for prohibited AI system violations under the EU AI Act — or 7% of global annual turnover
€15M maximum fine for high-risk AI obligation breaches — or 3% of global annual turnover
Aug 2026 deadline for most high-risk AI system obligations to be in full application for new deployments

Explainability: The Compliance Challenge Nobody Is Ready For

Explainability — the ability to describe how an AI system reached a specific output — is required for high-risk AI systems and is also directly relevant under GDPR Article 22, which governs automated decision-making with significant effects on individuals. For regulated businesses using AI in customer-facing risk decisions, the intersection of these two obligations creates a specific compliance challenge that most have not adequately addressed.

"If you cannot explain in plain terms why your AI model flagged a specific customer, you cannot satisfy a data subject access request, a regulatory inquiry, or a legal challenge. Explainability is not a technical nice-to-have — it is a compliance requirement."

The explainability obligation applies at two levels. At the system level, the developer or deployer must be able to describe the model's general logic and the factors it weights in reaching outputs. At the individual decision level, they must be able to explain why the system produced a specific output for a specific input. The second requirement is significantly more demanding and is where many black-box machine learning models create legal exposure.

For compliance teams, the practical questions to address are:

Bias and Fairness in Player Profiling

AI-driven player profiling and responsible gambling scoring systems can exhibit bias if the training data reflects historical patterns that correlate with protected characteristics. A model trained predominantly on data from one demographic group may produce systematically different risk scores for individuals from other groups, even when their actual behaviour is equivalent.

In a regulated gaming environment, this creates intersecting obligations. The AI Act requires bias identification and mitigation for high-risk systems. GDPR prohibits automated decision-making based on protected characteristics. Equality legislation in most jurisdictions prohibits discriminatory treatment in service delivery. A player profiling system that produces systematically different responsible gambling flags or VIP access decisions for individuals of different protected characteristics is exposure across all three frameworks simultaneously.

The minimum governance standard for AI-driven player profiling includes regular bias audits against demographic variables, documentation of the audit methodology and findings, and a remediation process for identified bias. For operators using third-party AI tools, this obligation does not transfer to the vendor — the deployer remains responsible for bias in the outputs as applied to their customer base.

AML Model Validation: The Underrated Requirement

Transaction monitoring systems using machine learning or rule-based AI components require validation to demonstrate that they are performing as intended. Regulatory guidance across multiple jurisdictions now explicitly expects documentation of model validation — the process of testing whether the model actually detects the risks it is designed to detect, at the calibration levels applied.

Model validation for AML purposes covers:

GDPR and AI: The Overlap That Matters

The intersection of GDPR and AI use in regulated business is not a niche technical question — it is a central compliance obligation. The key provisions to integrate into AI governance frameworks are Article 5 (purpose limitation and data minimisation), Article 22 (automated decision-making), and Article 35 (data protection impact assessments for high-risk processing).

For most AI use in regulated business contexts, a Data Protection Impact Assessment is required before deployment. The DPIA must identify the specific risks arising from the AI processing, assess their likelihood and severity, and document the measures in place to mitigate them. A DPIA completed at the point of AI tool procurement that is never subsequently reviewed does not satisfy the requirement for an ongoing, risk-responsive process.

AI governance review for regulated businesses

Wise Key Solutions provides AI governance assessments covering EU AI Act classification, GDPR intersection, explainability obligations, and AML model validation requirements. Contact us to discuss a review for your AI tools.

Speak to our team →

This article reflects the operational perspective of the Wise Key Solutions founding team. It does not constitute legal or regulatory advice. Regulated businesses should obtain specialist legal advice on AI Act classification and obligations relevant to their specific deployment contexts.