MGA and MDIA Launch Voluntary AI Gaming Charter: A Comprehensive Guide for Licensees
MGA and MDIA Launch Voluntary AI Gaming Charter: A Comprehensive Guide for Licensees
Overview: A New Framework for Ethical AI in Gaming
On 18 September 2026, the Malta Gaming Authority (MGA) and the Malta Digital Innovation Authority (MDIA) jointly published the AI Gaming Charter, a 48-page voluntary framework designed to guide licensees in the ethical and responsible use of artificial intelligence across gaming operations. The document was unveiled at an event attended by representatives from the gaming industry, the public sector, and the technology community.
Importantly, the Charter creates no new legal or regulatory obligations. It does not modify existing requirements under national or European Union law, including the EU AI Act, the General Data Protection Regulation (GDPR), and the Data Act. Instead, it sets out what the regulators expect licensees to document, oversee, and be able to explain when they deploy AI systems. The MGA describes this as one of the first initiatives in Europe to establish AI principles tailored specifically to the gambling sector.
What the Charter Covers: Scope and Applicability
Which AI Systems Are Included?
The Charter applies to any AI system used anywhere in a licensee’s operations—including internal, back-office, and player-facing functions—regardless of how the system is classified under the EU AI Act’s risk categories. This means that even low-risk or unclassified AI tools fall under the Charter’s expectations.
Notably, rules-based workflows and robotic process automation (RPA) that lack AI functionality are generally excluded from the Charter’s scope.
The Two-Tier Classification System
Licensees are encouraged to sort their AI systems into two tiers based on their potential impact:
| Tier | Description | Examples |
|---|---|---|
| Lower-Impact Systems | Internal, operational, or administrative systems unlikely to materially affect players | Internal reporting dashboards, employee scheduling tools, document automation |
| Higher-Impact Systems | Systems used in, or that materially influence, player-facing decisions or regulated outcomes | Responsible gambling interventions, fraud detection, AML screening, KYC verification, account restrictions, eligibility checks, player profiling |
The Charter advises that impact should be judged by how close the system sits to the player and its effect on regulated outcomes—not merely by whether a human makes the final decision.
Core Principles: What Licensees Are Expected to Do
The Charter outlines nine key areas of expectation. Below is a detailed breakdown of each, with context and practical guidance.
1. Risk-Based Application
Expectation: Apply the Charter proportionately, calibrating documentation, testing, and oversight to each system’s impact on players and regulated outcomes.
Why it matters: A one-size-fits-all approach would be impractical. A chatbot that answers FAQ questions poses far less risk than an AI system that automatically blocks player accounts. Licensees should allocate resources accordingly.
Practical steps:
- Create a risk assessment matrix for all AI systems.
- Assign higher documentation and testing requirements to higher-impact systems.
- Document the rationale for tier classification decisions.
2. Transparency, Accountability, and Explainability
Expectation: Let players know when they are engaging with AI, keep records of purpose, inputs, limitations, and logs, and avoid “AI washing” and “open-washing” (misleading claims about AI capabilities or openness).
Why it matters: Players have a right to understand how AI affects their experience. Regulators also need to verify that systems operate as claimed.
Practical steps:
- Add clear disclaimers when players interact with AI (e.g., “This chat is powered by AI”).
- Maintain an audit trail for each AI system’s purpose, training data, known limitations, and decision logs.
- Avoid marketing language that exaggerates AI capabilities.
3. Fairness and Non-Discrimination
Expectation: Test for bias, document the fairness objective chosen for higher-impact systems, and review proxy variables such as geolocation, device type, or deposit patterns.
Why it matters: AI systems can inadvertently discriminate against certain player groups. For example, a model that uses geolocation data might unfairly restrict access from specific regions.
Practical steps:
- Conduct bias audits on higher-impact systems before deployment.
- Define and document your chosen fairness metric (e.g., demographic parity, equal opportunity).
- Identify and mitigate proxy variables that could lead to indirect discrimination.
4. Environmental Sustainability
Expectation: Treat energy use and carbon impact as a factor when deciding whether to adopt, develop, or procure a system—not only afterwards.
Why it matters: AI can be computationally intensive. The Charter encourages licensees to think about sustainability from the start, rather than as an afterthought.
Practical steps:
- Include environmental impact assessments in procurement decisions.
- Choose energy-efficient hardware or cloud services.
- Monitor and report energy consumption for high-use AI systems.
5. Data Protection, Security, and Governance
Expectation: Keep AI processing within GDPR requirements and maintain a proportionate data governance framework covering data quality, retention periods, and transfers.
Why it matters: AI systems often process large volumes of personal data. Compliance with GDPR is non-negotiable, and the Charter reinforces this expectation.
Practical steps:
- Conduct Data Protection Impact Assessments (DPIAs) for AI systems handling personal data.
- Implement data retention schedules for AI training and inference data.
- Ensure lawful basis for processing (e.g., consent, legitimate interest).
6. Human Oversight and Responsibility
Expectation: Keep review, override, and reversal possible; set escalation triggers for player-facing conversational AI; and remain accountable for outcomes.
Why it matters: Human oversight ensures that AI errors or edge cases can be caught and corrected. It also maintains accountability for decisions that affect players.
Practical steps:
- Design systems with manual override capabilities.
- Establish clear escalation paths for player-facing chatbots (e.g., escalate to a human agent if a player expresses distress).
- Assign named individuals responsible for AI outcomes.
7. Reliability, Safety, and Robustness
Expectation: Test before deployment and, for higher-impact systems, add adversarial testing or red-teaming, drift monitoring, and rollback or kill-switch mechanisms.
Why it matters: AI systems can fail unexpectedly, especially when exposed to novel inputs. Robust testing reduces the risk of harm to players.
Practical steps:
- Implement pre-deployment testing protocols.
- For higher-impact systems, conduct red-team exercises (simulated attacks or edge cases).
- Monitor for model drift (degradation over time) and have rollback plans ready.
8. Compliance, Monitoring, and AI Governance
Expectation: Maintain an AI inventory, name a senior accountable person (such as a Chief AI Officer), and run an AI oversight or ethics committee or equivalent documented forum.
Why it matters: Governance structures ensure that AI is managed systematically rather than ad hoc.
Practical steps:
- Create and update a central inventory of all AI systems.
- Appoint a senior leader to oversee AI governance.
- Establish a regular forum (e.g., quarterly committee meetings) to review AI risks and incidents.
9. Reporting and Metrics
Expectation: Declare the criteria, thresholds, and testing methods used for higher-impact systems, and keep results available to the MGA and MDIA on request.
Why it matters: Regulators need visibility into how AI systems work to ensure compliance with the Charter’s principles.
Practical steps:
- Document performance criteria and thresholds for each higher-impact system.
- Maintain testing logs and results.
- Be prepared to share documentation with regulators upon request.
10. Notification Requirements
Expectation: Notify the MGA of significant changes to AI systems affecting gaming operations; serious incidents involving high-risk systems go to the MDIA and the Information and Data Protection Commissioner (IDPC).
Why it matters: Proactive notification allows regulators to assess risks and coordinate responses.
Practical steps:
- Define “significant change” internally (e.g., model updates, new data sources).
- Establish incident response protocols for high-risk AI incidents.
- Maintain contact lists for regulatory notifications.
The MGA’s Study: Current State of AI Adoption Among Licensees
The Charter is built on a survey sent to all MGA licensees (voluntary participation) plus in-depth interviews with selected licensees. The MGA noted that responses represented a limited subset of the sector and published no percentages—so findings are indicative rather than representative.
Key Findings
Adoption is uneven. The most mature use cases include:
- Operational optimization
- Data analytics
- Customer support chatbots
These are followed by:
- Recommendation engines
- Player profiling
- Fraud detection and AML
- Responsible gambling behavioral modeling
Less common use cases:
- Dynamic odds setting and risk management
- Regulatory reporting
- Player acquisition
- HR
- Player onboarding and KYC
- Payments
- AI-powered live casino
Respondents also reported AI use outside core gaming functions, such as:
- Software development tools
- Creative tools for image and video generation
- Compliance tools that track regulatory change
Governance lags behind use. The study found that:
- Only a minority of organizations have a formal AI strategy or roadmap.
- Only a small number have fully established AI risk assessment processes or incident response plans.
- Only a small number disclose AI use to customers or secure explicit consent for automated processing.
- Among B2B licensees, one respondent said documentation on how its AI systems work is shared with clients.
- Most respondents said human oversight is always applied to AI-based decisions.
What Regulators Said
Speaking at the launch event, Charles Mizzi, CEO of the MGA, stated:
“The AI Gaming Charter reflects a shared commitment between regulators, industry and technology experts to promote the responsible and transparent use of artificial intelligence. Our role as a regulator is not to stand in the way of innovation, but to help create the certainty and confidence needed for innovation to flourish responsibly.”
Kenneth Brincat, CEO of the MDIA, added:
“Trust is fundamental to the responsible adoption of AI.”
He noted that the Charter turns governance principles into sector-specific guidance, pairing the MDIA’s AI expertise with the MGA’s knowledge of the gaming sector.
What Happens Next: Implementation and Support
Voluntary Take-Up
Participation in the Charter is entirely voluntary. Licensees that choose to adopt it are encouraged to:
- Designate one or more responsible individuals as internal points of contact for AI governance.
- Support periodic AI literacy and refresher initiatives for relevant staff.
Annex A: Legal Mapping
Annex A of the Charter maps its principles against the EU AI Act and GDPR, clearly separating what already exists in law from what is sector-specific good practice. Importantly, the mapping does not provide a presumption of conformity with the EU AI Act. Licensees remain responsible for ensuring full legal compliance independently.
Regulatory Engagement
The MGA plans structured engagement with licensees on the Charter, which may take place annually. The document itself may be periodically reviewed and updated.
Available Resources
- EU AI Act Compliance Checker: Hosted on the MDIA website (developed by the EU AI Office).
- AI Helpdesk: The MDIA runs a helpdesk for EU AI Act queries.
The MGA’s Own Use of AI
The regulator is already using AI inside its own licensing checks, as its 2025 annual report (published in July) set out. This demonstrates the MGA’s commitment to practicing what it preaches.
Practical Guidance for Licensees
Getting Started
- Conduct an AI inventory – List all AI systems in use, including internal tools.
- Classify each system – Determine whether it is lower-impact or higher-impact.
- Perform a gap analysis – Compare current practices against the Charter’s nine areas.
- Create a governance framework – Assign senior ownership, establish committees, and document policies.
- Implement documentation – Record purpose, inputs, limitations, and testing results.
- Notify and train – Inform players where appropriate and train staff on AI ethics.
Common Pitfalls to Avoid
- Over-classifying systems – Not every automation tool needs red-teaming.
- Under-documenting – The Charter values records even for low-risk systems.
- Ignoring proxy variables – Geodata and device type can indirectly cause bias.
- Neglecting sustainability – Energy impact should be part of initial decision-making, not an afterthought.
Conclusion
The MGA and MDIA’s AI Gaming Charter represents a proactive, collaborative approach to AI governance in the gambling sector. While voluntary, it sets a clear benchmark for ethical and responsible AI use. Licensees that adopt its principles will be well-positioned to build trust with players, regulators, and the broader public—while avoiding the risks of unchecked AI deployment.
As the EU AI Act and other regulations evolve, early adoption of the Charter’s framework may also ease future compliance burdens.
Related guides
- $24M Florida Slots Case: Owner Seeks Dismissal of RICO and Money Laundering Charges
- ADM Authorises Setka Cup Betting: BETER Gains Access to Italy’s Regulated Market
- ANJL: Ban on Licensed Online Casinos Could Double Brazil’s Illegal Gambling Market
- ASA Maintains Strict Gambling Ad Control: A Comprehensive Guide to Two New Rulings
- ASA upholds complaint against Midnite over AI-generated character in TikTok ad