Massachusetts Is Investigating Gambling Companies’ Use of A.I.

By Gammatek ISPL, Compliance & Industrial Systems Analyst at Gammatek ISPL
Last updated: September 25, 2026 | 13 min read
Author block: Gammatek ISPL writes on regulatory compliance and enterprise risk systems at Gammatek ISPL, where the team builds compliance and audit software for regulated industries. This piece draws on public reporting, the Massachusetts Gaming Commission's public statements, and Gammatek's own experience helping regulated companies build defensible AI governance and audit trails.
Why This Matters
On September 24, 2026, the Massachusetts Gaming Commission announced it would examine how DraftKings and other licensed sportsbooks use artificial intelligence — a direct response to a New York Times investigation reporting that DraftKings had built a machine-learning model to identify customers most likely to keep losing money, then targeted them with promotional offers, while reportedly shelving a separate tool meant to flag problem gambling. If you run, advise, or invest in any company that uses AI to make decisions about customers — not just gambling companies — this story matters, because it's a live example of exactly the kind of AI use that turns into a regulatory investigation, a lawsuit, and a reputational crisis almost overnight. The gap between "our AI model works well" and "our AI model is now the subject of a state investigation" can be a single unflattering internal memo becoming public.
What Actually Happened
According to reporting, the New York Times investigation into DraftKings drew on interviews with roughly 40 former employees, internal research memos, Slack messages, and betting records. The reporting described an internal metric DraftKings staff called "elasticity" — a measure of how much more a given customer might wager if offered the right promotional incentive. Six former employees who worked on these systems told the Times they were concerned the technology could cause harm to people struggling with gambling addiction, and the report also stated that DraftKings had shelved a separate tool designed to flag at-risk gamblers for intervention.
Massachusetts Gaming Commission Chairman Jordan Maynard announced the commission would examine how DraftKings, and other licensed operators in the state, use AI for customer acquisition, promotions, and responsible-gambling functions. The commission noted it had already been monitoring this space — it had commissioned an earlier study on AI in gambling from the University of Nevada, Las Vegas's International Gaming Institute, which recommended forming an internal AI task force, something the commission has since done. DraftKings, for its part, said it complies with Massachusetts sports-betting rules and denied using AI specifically to target people based on their losses.
[
One detail worth pulling out for readers outside the gambling industry: this wasn't a regulator reacting cold. Massachusetts had already funded a year-long independent study on AI in gambling and had already stood up an internal AI task force before this specific controversy broke. The DraftKings story accelerated existing oversight machinery rather than creating it from scratch — which is itself a lesson: regulators in AI-adjacent industries are increasingly building standing infrastructure to investigate quickly when something like this surfaces, rather than starting from zero.
Why This Isn't Really a "Gambling Industry" Story
It's tempting to read this as a story specific to sports betting. It isn't, structurally. Strip away the gambling context and the pattern is generic: a company builds an AI model that optimizes for a business metric (in this case, betting volume), that model works exactly as designed, and the outcome — concentrating harm on the most vulnerable users of the product — becomes a regulatory and PR crisis specifically because the model worked.
This is a known failure mode across industries that use AI for customer targeting: recommendation engines, credit and lending algorithms, insurance pricing models, and ad-targeting systems have all faced versions of this same criticism — a system optimized cleanly for a narrow metric, with no meaningful check on whether that metric correlates with harm to a subset of users.
What Regulated Companies Should Actually Take From This
This is where most coverage of the story stops — at the gambling industry angle. The more useful question for any company deploying AI in a regulated space is: what would it look like if your own systems were reviewed the way DraftKings' just was?
A few concrete implementation considerations, drawn from what tends to separate companies that survive this kind of scrutiny from those that don't:
1. Document why a model does what it does, before regulators ask. The DraftKings case became a crisis partly because of what internal memos revealed after the fact — a paper trail explaining the "elasticity" metric's intent existed, but only became visible under investigation, not proactively. Companies that maintain clear, contemporaneous documentation of what a model optimizes for, and why, are in a fundamentally different position when scrutiny arrives than companies whose reasoning only gets reconstructed after a reporter or regulator asks.
2. A model built for one purpose doesn't stay contained to that purpose without active governance. Reports indicate DraftKings had built tools to flag at-risk gamblers, separately from the tools used for targeting, and that the flagging tool was reportedly not deployed the same way. Any organization running multiple AI systems with different (and potentially conflicting) objectives needs a governance layer that actively reconciles them — not just builds them independently and hopes they don't contradict each other in practice.
3. "It performed well" is not a defense once harm is identified. A recurring pattern across AI controversies in regulated industries: the model worked exactly as intended, and that's precisely the problem. Technical performance and defensible governance are two different questions, and companies that only measure the first are exposed on the second.
4. Contract and vendor relationships around AI tooling need the same audit trail as the AI itself. Many AI systems used for customer targeting are built or supported by third-party vendors, data brokers, or analytics platforms. When a regulator investigates, they don't stop at the internal team — they look at every vendor and data relationship that fed the model. A company with a clear enterprise contract management software system tracking exactly which vendors supply which data, under what terms, is in a materially stronger position than one reconstructing those relationships from old emails.
5. Data retention and backup practices become evidence, for better or worse. Investigations like this one lean heavily on internal records — Slack messages, memos, betting records going back years. Whether a company's enterprise backup and recovery systems (or corporate backup software) preserve records in a way that supports a clear, defensible account of decision-making, or instead creates gaps and inconsistencies that look evasive, has real consequences once regulators start asking for a paper trail.
6. Responsible-use teams need real staffing, not just a task force announcement. Massachusetts responded to this story partly by pointing to an AI task force it had already formed. Whether that task force has genuine authority and headcount — supported by real enterprise HR software tracking who owns AI governance responsibilities, and whether that's a full-time role or an afterthought — is often the difference between a task force that catches problems early and one that exists mainly for the press release.
What Happens Next in This Case
The Massachusetts Gaming Commission's review is still in its early stages as of this writing — commission staff are set to meet directly with DraftKings to examine its AI practices, and the commission has said it will evaluate other licensed operators as well, not just DraftKings specifically. Commissioner Paul Brodeur has publicly described the underlying NYT findings as "troubling," while also noting that AI-driven customer targeting isn't unique to gambling — it's a pattern common across customer-facing industries generally. Whether this results in new rules, enforcement action, or simply a published report remains to be seen, and the outcome is worth watching for anyone in an AI-adjacent regulated industry, since Massachusetts' approach may become a template other states reference.
The Broader Pattern
Step back from this specific case, and it fits a broader shift already underway: AI oversight is moving from abstract policy conversation to concrete, company-specific investigation. A regulator doesn't need a comprehensive AI law on the books to start asking a company hard questions about a specific model — as this case shows, a single investigative report was enough to trigger a formal review. Any company treating "there's no AI-specific regulation yet" as meaning "we're not exposed" is reading the current moment wrong. The exposure isn't purely legal — it's documentation, governance, and the ability to give a clear, defensible account of what a system does and why, whenever someone asks.
Where Compliance Software Fits
This is exactly the gap that dedicated compliance and audit infrastructure is built to close — not the AI model itself, but the layer around it: documented decision rationale, vendor and contract tracking, retained records that hold up under scrutiny, and clear ownership of governance responsibilities. Companies that treat this as infrastructure to build before a regulator asks are in a fundamentally different position than companies building it reactively, under investigation, with a reporter's deadline already public.
See how Gammatek's compliance platform helps regulated companies build audit-ready AI governance → https://www.gammateksolutions.com/post/top-mathematicians-are-outraged-by-openai-s-methods




Comments