Standards are not usually the part of the gambling industry that gets the most attention. They tend to sit in the background, folded into technical working groups and regulatory discussions rather than the day-to-day commercial narrative. But that is becoming harder to maintain as iGaming faces tougher questions around player protection, cyber resilience, AI and the way operators report data across markets.
In the second part of this interview, Mark Pace discusses the gaps he still sees in responsible gaming, the case for a centralised limits system, the industry’s weaknesses in cyber resilience, and the unresolved questions around the use of AI. He also discusses the areas where companies are now looking to launch new IGSA committees.
Q: A lot of progress has been made in Responsible Gaming, but where do you think the current model still falls short most clearly?
M. Pace: Much effort and money have been spent by many companies working hard to do good in the area commonly referred to as Responsible Gaming or RG. Many of these companies are genuinely interested in aiding those players needing assistance with maintaining gambling as another form of entertainment. There is also a lot of research that has been, and continues to be, conducted to provide data which can be used to improve the identification of individuals who may be exhibiting signs of being negatively affected by their gambling, and ways in which those individuals can be assisted. We see two opportunities in this space:
IGSA is relaunching a committee looking at challenges in the RG space, and one of the first things the committee may tackle is the creation of a data dictionary. This will define the terms and identify the correct way in which they are to be used. This data dictionary can then be used to update regulatory requirements and operator messaging, which will provide a clear and consistent message across gaming jurisdictions to operators and those looking for assistance.
The second challenge we see is that while there are many excellent RG-related systems that have been developed, whether they are enhanced via artificial intelligence or research and fact-based, they are still limited in their ability to do good. The underlying reason for this is that in many cases, the scope of the solution is limited to a particular operator’s dataset.
For example, an online operator may have several different online brands and may have systems in place to aggregate players’ data across those brands. This provides the operator with an enterprise-wide view of a player’s behaviour. That operator can then apply their RG tools to identify which of their players may need assistance.
However, that operator’s reach is limited to the player’s activity across their enterprise. That operator is blind to their player’s activities with other brands. Therefore, while a player may not trigger the RG indicators across that operator’s brands, that same player’s aggregate gambling across other brands would indicate that the player has an RG issue.
Q: Does that mean the industry needs to start thinking more seriously about jurisdiction-wide tools that can address that blind spot?
M. Pace: Many regulated jurisdictions have a central exclusion system, whereby an individual can register their name once, on one website, which may be managed by the regulatory authority. Once registered on that website, the player is then prohibited from gambling in that jurisdiction and excluded from receiving any gambling-related promotional messages. The central exclusion system process is simple for players to use and has proven to be effective.
Unfortunately, we lack a similar approach to understanding player behaviour across all gaming sites to determine when an individual might need RG assistance. There are many valid reasons why very few jurisdictions have tried to tackle this challenge, not the least of which are data privacy and security issues. The result of this lack of a centralised view of player activity is that the responsibility for dealing with RG has been pushed onto operators and suppliers, and how they apply RG solutions is often a factor of their risk appetite.
We see an opportunity to empower the player to manage their gambling entertainment and to provide a means, where it is legal, for a designated entity to get access to holistic player gaming activity, which can then be used with RG-related tools.
A centralised limits system (CLS), patterned after centralised exclusion systems, can be a valuable tool in the RG toolkit. A CLS allows players to set daily, weekly, monthly, and yearly limits regarding deposits, wagering, play time, and loss, using a single site that is operated by the regulatory authority or a designated entity. When an individual seeks to create a new online gaming account with a particular brand, they would be directed to the CLS to set those limits, which may have to pass jurisdictionally-identified reasonability tests. Once the limits are established, whenever a player logs onto an online gaming site, their limit balance values are downloaded to that gaming site. As they play, their activity is tracked against the limit values. If a player reaches a set limit, any mandated actions, whether required by regulators or imposed by operators, are immediately enforced, and the player’s CLS limit balances are immediately updated. If a player ends a session without reaching any limit, then the player’s CLS balance is updated so that the next time the player logs on to any site within the jurisdiction, their limit values reflect the balance left.
Having a CLS makes it easier for players to set up limits, allows players to take responsibility for their gambling entertainment, provides players with feedback, and activates processes such as cool-down periods. When limits are reached, this eliminates the blind spot created by players’ activities across brands and takes the burden away from operators and suppliers.
Q: Cyber attacks on major operators have underlined how exposed the industry can be. In your view, where do companies still underestimate cyber risk most, and what does real cyber resiliency look like beyond routine testing?
M. Pace: Cyber Resiliency goes beyond an annual Penetration Test and Vulnerability Assessment. Unfortunately, many think that these alone provide them with the protection they need.
As we have seen recently in the United States with the attacks on Caesar’s, MGM, and most recently Wynn, even large, well-funded, and diligent companies dedicating significant resources to IT Security can be hacked. Threat actors are constantly probing for the weak link, and our industry, long thought to be immune to hacking attacks, has found out the hard way that we are on hackers’ radars. We have also learned that our enterprises are not as protected as we thought.
There are lots of reasons why this is the case, such as the fact that the IT security tools and specialised IT security personnel are expensive, companies have varying risk appetites, and that cyber resiliency is like insurance: you know you need it, but you hate to pay for it. We believe that there is a fundamental gap between how secure companies think they are compared to how secure they really are.
We also see cyber resiliency as a core responsibility of all gaming industry constituents, from component suppliers, technology suppliers, software suppliers, network suppliers, data centre providers, all the way to operators. Across the gaming industry supply chain, security by design should be a standard that is implemented by all. The weak link could be anywhere.
Q: As AI adoption accelerates across gaming, what do you see as the biggest unanswered questions around accountability, oversight and ethical use?
M. Pace: The use of AI is seemingly everywhere. This raises a concern that many governments are addressing in various ways: What is the appropriate and inappropriate use of AI? The AI guidance provided by the EU AI Act and the US Executive Orders are all well and good, but they are too broad, and each industry should undertake the creation of a much more detailed set of processes and procedures for how AI should be implemented.
At IGSA, we looked at what governments are doing and sought to provide guidance that is tailored to our industry. This exercise started by establishing an Ethical AI committee and posing additional questions regarding the use of AI. What does the ethical use of AI in gaming look like? Who owns an AI algorithm or AI-enabled application? Who is responsible for identifying issues with an AI algorithm or AI-enabled application? Who has the responsibility to notify regulators, affected people, etc., of an issue? What level of transparency should there be?
IGSA’s Ethical AI committee has already published nine Best Practices, which were shared with various regulatory authorities to solicit input. These Best Practices are geared towards helping regulators understand what they should be requiring in terms of AI usage in our industry. The committee is now working on a companion FAQ document and additional Best Practices.
Q: You’re seeing companies come in with ideas for new committees. Does that give you a sense of where the industry’s priorities are shifting?
M. Pace: Per IGSA bylaws, at least three different companies must be willing to devote resources to work within a committee for it to be considered for creation.
Illegal gaming, sports integrity, and online skill gaming are three areas we are currently discussing with various companies interested in working on developing standards or best practices in each of those areas.
What comes through from Pace’s answers is that the industry is dealing with a wider set of risks than it was even a few years ago, and many of them do not sit neatly within one operator, one product or one jurisdiction. Responsible gaming, cyber resilience and AI oversight all raise questions that are difficult to solve in isolation.
For IGSA, that creates an opening, but also a test. Having a framework is one thing. Getting enough of the industry to back it, build around it and apply it in practice is another.
You can read part one of our interview with Mark Pace here.
Subscribe HERE to SiGMA’s Top 10 News countdown and SiGMA’s weekly newsletter to stay up to date with all the latest iGaming News from the biggest iGaming community in the world and benefit from subscriber-only offers.





