Responsible AI in Gaming: Malta's New AI Gaming Charter

Two professionals reviewing a document beside computer monitors in a blue-lit technology workspace.

Artificial intelligence is rapidly becoming part of the day-to-day operations of the gaming industry. From customer support and data analytics to fraud detection, responsible gambling and software development, AI offers gaming businesses significant opportunities to improve efficiency, strengthen decision-making and enhance player protection.

Recognising both the opportunities and risks associated with AI, the Malta Gaming Authority (MGA), in collaboration with the Malta Digital Innovation Authority (MDIA), published the AI Gaming Charter on the Ethical and Responsible Use of AI Operations (the “Charter”) on 18 September 2026. 

 
A voluntary framework for responsible AI
The Charter is intended to provide a voluntary, sector-specific framework promoting the responsible, transparent and accountable use of AI within gaming operations, while complementing existing legal and regulatory frameworks, including the EU AI Act and the GDPR. 

It applies to MGA-licensed B2C operators and B2B critical gaming suppliers and covers both customer-facing and internal AI systems. The Charter adopts the EU AI Act's definition of an AI system and indicates that traditional rules-based automation which does not learn, infer or generate outputs, such as systems operating solely on predefined rules, generally falls outside its scope. Importantly, the Charter does not create new legal or regulatory obligations but instead provides practical guidance on responsible AI use alongside existing legal requirements. While certain principles reflected in the Charter may overlap with obligations arising under applicable law, others are intended as gaming-sector good practice, making it important for organisations to assess the regulatory requirements applicable to each AI system on a case-by-case basis.

 
An impact-based approach
The Charter adopts an impact-based approach, recognising that the level of governance applied to an AI system should be proportionate to its purpose and potential impact. Higher-impact systems, such as those used in responsible gambling, AML, KYC, fraud detection or player-related decision-making, may warrant enhanced safeguards, including testing, monitoring, documentation and human oversight. Importantly, the fact that a human takes the final decision does not necessarily reduce the significance of an AI system where it materially influences the outcome.

 
Transparency without compromising commercially sensitive information
Players and other relevant users should, where appropriate, be able to understand when they are interacting with AI and the role that an AI system plays in influencing relevant outcomes. Where an AI-supported decision materially affects an individual, the Charter envisages meaningful, human-readable explanations and, where applicable, appropriate avenues for human review, challenge or redress. 

The Charter nevertheless recognises that transparency has limits. Responsible AI does not require businesses to disclose source code, detailed model architecture, trade secrets or sensitive fraud, AML and security logic where doing so could undermine intellectual property rights or the integrity of gaming operations. Rather, the objective is to provide meaningful information about the purpose, role, limitations and effect of the AI system.  

The Charter also addresses “AI washing”, namely the practice of overstating or misrepresenting the use or capabilities of AI. Licensees are encouraged to ensure that representations regarding their AI capabilities are factual and proportionate, rather than presenting AI as a guarantee of accuracy, fairness or safety. 

 
Fairness, privacy and human oversight
The Charter emphasises fairness, encouraging licensees to assess data quality, test for bias and monitor outcomes, particularly where AI may materially affect players. Where personal data is processed, organisations must continue to comply with the GDPR, including its principles of lawfulness, fairness, transparency and data minimisation. The Charter also stresses the importance of meaningful human oversight, recognising that AI should support rather than replace human judgement, especially in decisions that may affect players or gaming integrity. 

 
From AI use to AI governance
Perhaps one of the most significant practical aspects of the Charter is its emphasis on developing structured internal governance around AI.

Licensees are encouraged to maintain an AI inventory identifying the AI systems used within their organisation, together with matters such as their purpose, owner, deployment context, risk tier, key dependencies, lifecycle status and the organisation's role under the EU AI Act. 

The Charter also recommends establishing an AI governance framework which is proportionate to the business's size, complexity and AI risk profile. This may include designating a senior individual with responsibility for AI governance and establishing an AI oversight or ethics committee, or an equivalent documented governance forum. 

Effective governance does not end once an AI system is deployed. Licensees should consider appropriate testing, impact assessments, performance monitoring and incident-management procedures throughout the system's lifecycle. Higher-impact applications may require more extensive controls, including defined performance thresholds, enhanced testing, model and version controls, monitoring for changes in performance and mechanisms allowing systems to be rolled back or suspended where necessary. 

 
What should gaming businesses consider?
The Charter provides a useful framework for organisations to assess their use of AI. Businesses may wish to:
  • identify the AI systems used across their operations;
  • establish the purpose of each system and whether it may affect players or regulated outcomes;
  • determine their role in relation to each system under the EU AI Act;
  • assess the applicable risk profile and legal requirements;
  • review existing governance, documentation, data management and human oversight arrangements;
  • consider whether appropriate testing and monitoring mechanisms are in place; and
  • assign clear responsibility for AI governance within the organisation.
For organisations adopting new AI solutions, these considerations are likely to be most effective when incorporated from the outset and supported by collaboration across legal, compliance, data protection, responsible gambling, AML, information security and operational teams.

 
Looking ahead
The Charter reflects an increasingly structured approach to AI governance within Malta's gaming sector, while recognising the potential of AI to enhance areas such as player protection, risk detection and operational efficiency when deployed responsibly. Although voluntary, the Charter provides a practical benchmark against which gaming businesses can assess their AI governance practices and prepare for compliance with the EU AI Act, the GDPR and other applicable legal and regulatory requirements.

 
How Can BDO Malta help?
BDO Malta's multidisciplinary team, comprising legal, regulatory, risk and technology specialists, can assist gaming operators and suppliers in assessing AI use cases, reviewing AI-related policies, procedures and contractual arrangements, and advising on obligations arising under the EU AI Act, the GDPR and other applicable regulatory frameworks. We can also support businesses in developing proportionate governance, risk management and compliance frameworks to facilitate the responsible deployment of AI within their operations.