TL;DR: Unlicensed operators and AI-enabled fraud are scaling faster than current safeguards in iGaming, with regulators and operators now forced to rethink how player protection works across borders, according to SumSub’s live podcast episode from ICE Barcelona. Isolated controls are no longer enough when enforcement, education, and data sharing have to operate across multiple jurisdictions.
At a glance
What this is: This podcast episode examines how industrialised fraud, unlicensed operators, and underage exposure risks are breaking traditional player protection approaches in gaming.
Why it matters: It matters because IAM and fraud teams in regulated environments need controls that work across jurisdictions, not isolated checks that fail against coordinated abuse.
Context
Player protection in gaming is not just a content moderation or responsible gaming problem. It is a governance problem that spans identity verification, fraud prevention, underage access, and cross-border enforcement, where the weakest jurisdiction or control point can undermine the whole model.
The article argues that current safeguards are being outpaced by industrialised fraud networks and unlicensed operators. The operational question for practitioners is no longer whether to add another control, but how to coordinate data, education, and enforcement across multiple stakeholders so the programme still works at scale.
Key questions
Q: What breaks when player protection controls are managed in silos?
A: Siloed controls miss the way industrialised fraud moves across accounts, operators, and jurisdictions. A verification check or fraud rule can look effective in isolation while the full abuse chain continues elsewhere. The real failure is end-to-end coordination, because player protection depends on shared signals, shared escalation, and shared accountability across the ecosystem.
Q: Why do cross-border gaming fraud cases need coordinated enforcement?
A: Because attackers exploit gaps between jurisdictions, single-organisation controls rarely stop them. When one party sees only onboarding risk, another sees only transaction abuse, and a third sees only regulatory non-compliance, the abuse path survives. Coordinated enforcement turns disconnected observations into a usable response that can actually interrupt the pattern.
Q: What are the signs that player protection is failing in gaming programmes?
A: Look for repeated abuse patterns that pass through onboarding, behavioural monitoring, and intervention without a joined-up response. If responsible gaming, fraud, and compliance teams each see part of the issue but no one can close the case, the programme is underperforming. Slow handoffs are often the clearest indicator that governance, not technology, is the weak point.
A: Operators should treat fraud and responsible gambling as overlapping uses of the same behavioral data, not separate problems. Session activity, deposit history, device fingerprints, and account linkage can reveal both account abuse and emerging harm. The practical move is a shared risk view with separate decision logic, so teams can coordinate on one case instead of maintaining duplicate queues and blind spots.
Technical breakdown
Why isolated player protection controls fail against industrialised fraud
Player protection breaks down when controls are designed for one platform, one regulator, or one fraud pattern at a time. Industrialised fraud networks adapt across accounts, devices, channels, and jurisdictions, which makes isolated checks easy to route around. In gaming, that means verification, monitoring, and intervention need to be joined up or they become point fixes that create a false sense of coverage. The problem is not the absence of controls, but the absence of coordination between them.
Practical implication: map where identity, fraud, and responsible gaming controls do not share signals or escalation paths.
Cross-border enforcement and data sharing in gaming protection
Cross-border gaming risk is fundamentally a coordination problem. Regulators, operators, technology providers, and law enforcement each hold part of the picture, but none can see the full abuse chain on their own. When fraud activity and unlicensed operations move across jurisdictions, the effectiveness of any single control depends on how quickly evidence and decisions can move between parties. That makes governance, not just tooling, the limiting factor in player protection.
Practical implication: define the data-sharing and escalation routes your programme can actually use before incidents force improvisation.
Underage exposure is an identity and governance failure
Underage exposure risk shows that player protection is not just about stopping fraud. It also depends on whether age, access, and behavioural signals are linked to a lifecycle process that can respond when risk changes. If checks are treated as one-time onboarding events, the programme misses the ongoing nature of misuse, coercion, and account manipulation. In practice, the control failure is not simply weak verification, but weak governance over who can remain active and under what conditions.
Practical implication: treat age-risk and responsible gaming triggers as lifecycle controls, not one-off onboarding checks.
NHI Mgmt Group analysis
Player protection in gaming has become a multi-stakeholder identity problem, not a single-control problem. The article shows regulators, operators, technology providers, and law enforcement all carrying part of the burden, which means governance breaks down whenever those parties operate in silos. The practical conclusion is that player protection now depends on orchestrated decision-making across the ecosystem, not isolated platform controls.
Industrialised fraud changes the economics of abuse faster than traditional safeguards can respond. When fraud is organised, repeatable, and distributed across borders, static controls become a cost of doing business for attackers rather than a barrier. That makes signal sharing, enforcement coordination, and rapid intervention central to any credible protection model.
Responsible gaming only works when it is treated as an operational control, not a compliance slogan. The article’s emphasis on moving beyond box-ticking is the right framing because surface-level policy rarely changes attacker behaviour. Practitioners need to think in terms of measurable prevention, escalation, and cross-party accountability.
Coordination debt: player protection fails when each stakeholder optimises its own checkpoint but no one owns the end-to-end abuse path. That is the core governance gap this discussion exposes. The implication is that gaming programmes should be judged on how well they close the handoff gaps between verification, monitoring, enforcement, and intervention.
Better education is a control, not an afterthought. The article rightly treats player education as part of the defence model because informed users are less vulnerable to manipulation and abuse. In a fraud-heavy environment, education supports detection, reporting, and earlier intervention, which makes it a real operational layer rather than a communications exercise.
From our research library:
- Nearly 60% of companies reported that fraud losses were still increasing in 2025.
What this signals
Coordination debt: gaming programmes fail when identity checks, fraud controls, and responsible gaming interventions are designed as separate checkpoints instead of one end-to-end abuse response. The attack surface is organisational as much as technical, which means handoffs matter as much as detection quality.
The practical shift for regulated gaming is from isolated control design to ecosystem governance. If regulators, operators, technology providers, and law enforcement cannot exchange evidence quickly, the fraud network will always move faster than the response.
For practitioners
- Align player protection owners across functions Bring fraud, responsible gaming, compliance, and identity teams into one operating model so escalation does not stop at departmental boundaries.
- Build cross-border escalation paths Document how suspicious activity, unlicensed operator evidence, and underage exposure signals move between jurisdictions and partner organisations.
- Use shared signals for intervention Connect identity verification, behavioural monitoring, and player risk data so that a single signal can trigger coordinated action rather than isolated review.
- Treat player education as a control Make user guidance part of prevention design by linking it to fraud reporting, account review, and responsible gaming interventions.
- Measure the handoff gaps Review where cases stall between detection, escalation, and enforcement, then track those handoffs as governance failures rather than operational noise.
Key takeaways
- Industrialised fraud in gaming outpaces controls that were designed for individual checkpoints rather than coordinated prevention.
- The article shows that player protection now depends on how well organisations share data, escalate cases, and enforce decisions across jurisdictions.
- Operators that treat responsible gaming, fraud prevention, and education as one governance model will have a better chance of closing the handoff gaps.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
NIST CSF 2.0 and NIST SP 800-63 set the technical controls, while GDPR defines the regulatory obligations.
| Framework | Control / Reference | Relevance |
|---|---|---|
| NIST CSF 2.0 | PR.AA-05 — Access Permissions, Entitlements and Authorizations | Player protection depends on controlling who can access accounts and services across the gaming lifecycle. |
| GV.SC-07 — Supply Chain Risk Management | The article stresses coordination across regulators, operators, providers, and law enforcement. | |
| Recommendation — Apply PR.AA-05 to align access decisions with identity and risk signals across player workflows. Use GV.SC-07 to define shared accountability and evidence exchange with external partners. | ||
| NIST SP 800-63 | SP 800-63A — Enrollment and Identity Proofing | Underage exposure and player verification hinge on proofing at onboarding and beyond. |
| Recommendation — Strengthen SP 800-63A-aligned proofing where age assurance or regulated enrollment is required. | ||
| GDPR | Art.32 — Security of Processing | Cross-border player data handling and fraud controls raise processing security obligations. |
| Recommendation — Use Art.32 to align security measures with the risks of cross-border player data processing. | ||
Key terms
- Industrialised Fraud: Industrialised fraud is repeatable, scaled abuse carried out like an operation rather than a one-off attack. In gaming, it uses automation, shared infrastructure, and coordinated behaviour to defeat point-in-time checks and move through onboarding, funding, and play with minimal friction.
- Player Protection: Player protection is the set of controls used to prevent harm, fraud, and unlawful participation in regulated gaming environments. It combines identity checks, monitoring, intervention, and compliance enforcement so that operators can reduce abuse while meeting legal and responsible gaming obligations.
- Responsible Gaming Compliance: Responsible gaming compliance is the set of policies and controls used to identify potential addiction risk and meet legal obligations in regulated gaming. It typically combines transaction monitoring, behavioural analysis, and rule-based alerts so operators can intervene early and document that they acted on risk signals.
- Cross-Border Enforcement: Cross-border enforcement is the coordination of policy, monitoring, and action across multiple legal or operational jurisdictions. For gaming teams, it means aligning identity and fraud signals so that abuse can be recognised and addressed even when it moves between markets or providers.
Deepen your knowledge
NHI governance, agentic AI identity, and machine identity lifecycle are core topics in our NHI Foundation Level course, the industry's only accredited NHI security programme. If you are building or maturing an IAM programme, it is worth exploring.
Published by the NHIMG editorial team on June 10, 2026.
Updated on October 10, 2026.
NHI Mgmt Group, the independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org