Britain's gambling regulator keeps remote casino at high risk, lifts gambling software to medium, and warns AI-generated documents are defeating CDD checks.
Table of contents
Great Britain's Gambling Commission risk assessment, published on 30 July 2026, keeps remote casino, betting and bingo at high risk and lifts gambling software from low to medium. It covers April 2023 to October 2025 and names AI-generated identity documents, deepfake video and unlicensed site supply chains as the fastest moving threats.
- Gambling software is the only sector whose rating moved, rising from low to medium because licensed suppliers are reaching unlicensed sites through resellers and third-party contracts.
- The regulator reports a rise in the scale and sophistication of attempts to defeat customer due diligence using false documents, deepfake video and face swaps.
- Eleven separate risks in the remote casino chapter score the maximum 9 out of 9, four of them about identity: customers who are not physically present, linked or duplicate accounts, third-party and mule account use, and false or AI-generated documents.
- The Gambling Commission risk assessment discharges the regulator's own duty under Regulation 17(1) of the Money Laundering Regulations 2017, and operators must take it into account under Licence Condition 12.1.1 of the Licence Conditions and Codes of Practice (LCCP).
- HM Government has allocated 26 million pounds over three years to disrupt illegal gambling markets, the source of the newly rated business-to-business exposure.
What did the Gambling Commission publish on 30 July 2026?
The Gambling Commission risk assessment for 2026 landed on 30 July, replacing the 2023 edition. It examines money laundering and terrorist financing risk across all licensed remote and non-remote gambling in Great Britain for the period 1 April 2023 to 31 October 2025, and it rates every sub-sector against the others.
The document is not advisory colour. Its executive summary states that it satisfies the regulator's own obligation under Regulation 17(1) of the Money Laundering, Terrorist Financing and Transfer of Funds (Information on the Payer) Regulations 2017, and that it sets the frequency and intensity of supervision under Regulation 46(2)(c). Where an operator's own risk assessment disagrees with the supervisor's, the operator has to explain why.
The headline ratings are unchanged in every sector except one.
| Sector | 2023 rating | 2026 rating |
|---|---|---|
| Casino, betting and bingo (remote) | High | High |
| Casino (non-remote) | High | High |
| Betting (non-remote, off-course) | High | High |
| Betting (non-remote, on-course) | Medium | Medium |
| Bingo (non-remote) | Medium | Medium |
| Gambling software (remote and non-remote) | Low | Medium |
| Adult Gaming Centres | Medium | Medium |
| Family Entertainment Centres | Low | Low |
| Society lotteries and external lottery managers | Low | Low |
| The National Lottery | Low | Low |
| Gaming machine technical | Low | Low |
The sharpest passage sits in the remote casino chapter, where the regulator says it is aware of growing attempts to bypass due diligence using false documentation, "deepfake videos and face swaps generated by AI". That is a supervisor stating, in its own statutory risk assessment, that document-and-selfie onboarding is being beaten at scale. It matches what identity vendors reported weeks earlier, when LexisNexis Risk Solutions put deepfake attempts in roughly one of every 100 failed checks.
Why did gambling software move from low to medium risk?
Gambling software rose from low to medium because licensed suppliers are being pulled into the illegal market through their own commercial chains. The software chapter cites weak monitoring of third-party contracts, resellers who place licensed games on unlicensed websites, and cross-border arrangements with several parties in the middle.
Two risks in that chapter now score 6 out of 9. Due diligence on business-to-business customers and test houses rose on both likelihood and impact. Cryptoasset transactions enter as a new risk at the same score, in a sector that historically handled none. Insufficient monitoring of third-party contracts and a partner linked to a high-risk jurisdiction both enter at 4 out of 9.
The case studies are unusually concrete. In one, a software company took a loan whose ultimate source of funds was revenue from a remote casino offering cryptoasset facilities, a casino that was itself telling customers how to circumvent geo-blocking. In another, a licence applicant had raised money through an initial coin offering where source of funds checks had not been done and some identity documents could not be matched to the investor list. One of those investors had a money laundering conviction.
The Gambling Commission risk assessment ties that upgrade directly to the growth of unlicensed sites. The illegal markets chapter records that HM Government has allocated 26 million pounds over three years so the Commission can attack unlicensed operations across the supply chain, and it names payment service providers as the first regulated link through which money from illegal gambling enters the legitimate system.
What does the Gambling Commission risk assessment change for your obligations?
The Money Laundering Regulations 2017 apply directly to casinos only. Every other licensed operator sits outside them but still carries duties under the Proceeds of Crime Act 2002 (POCA), the Terrorism Act 2000, the Sanctions and Anti-Money Laundering Act 2018 and Licence Condition 12.1.1 of the LCCP, which requires operators to take account of the regulator's published learning.
Scores below are the regulator's own, on a matrix that multiplies likelihood by impact to a maximum of 9. Counted entry by entry, the remote casino chapter carries eleven risks at that maximum, so the rows here are the identity-facing subset rather than the full list.
| Duty | Status in the 2026 ratings | Remote casino score | What changes for you |
|---|---|---|---|
| [Customer due diligence](/resources/glossary/customer-due-diligence-cdd) on customers not physically present | New risk | 9 out of 9 | Evidence identity from a source that cannot be re-rendered, not a document image |
| Controls over linked or duplicate accounts | New risk | 9 out of 9 | Apply limits and monitoring across a customer's accounts, not per account |
| Third-party and mule account use | Reworded | 9 out of 9 | Establish who controls an account, not only who opened it |
| False or AI-generated identity documents | Reworded | 9 out of 9 | Test onboarding against injected and synthetic documents, not poor scans |
| Scrutiny of source of funds documents | New risk | 6 out of 9 | Record how the evidence was challenged, not that it was collected |
| Foreign [politically exposed persons](/resources/glossary/politically-exposed-person-pep) | No change | 6 out of 9 | Keep foreign PEP handling distinct from domestic |
| Domestic politically exposed persons | No change | 2 out of 9 | A lighter risk-based treatment is defensible if documented |
| Customers on financial sanctions lists | No change | 3 out of 9 | Screening stays mandatory despite the lower numeric score |
The source of funds entry is worth reading in the regulator's own words, because it targets the review step rather than the collection step: the chapter lists it as "Failure to appropriately scrutinise source of funds documents". On reporting, smurfing and mule accounts remain live typologies, escalation runs through the MLRO under POCA, and thin monitoring shows up in the ratings as anti-money laundering thresholds that are predominantly loss based.
For casinos offering money service business (MSB) activity such as cheque cashing or currency exchange, supervision stays with the Commission rather than HMRC under Regulation 7(2). The MSB chapter shows a small footprint carrying large tickets.
| Money service business activity in casinos, calendar year 2024 | Figure |
|---|---|
| Remote casino licensees offering some MSB activity | About 3 per cent |
| Non-remote casino licensees offering some MSB activity | About 56 per cent |
| Licensees offering cheque cashing | 14 |
| Licensees offering foreign currency exchange | 22 |
| Estimated value of MSB activity in casinos | 70 million pounds |
The Gambling Commission risk assessment sets no compliance deadline of its own. Licence Condition 12.1.1 requires policies to be kept under review and revised to stay effective, so the trigger is publication itself rather than a dated cut-off.
What is still uncertain in the new ratings?
Five things remain unresolved: the age of the evidence, comparability with 2023, a terrorist financing rating that diverges from the national picture, unallocated liability for software resale, and the perimeter of the regulated sector itself. Each affects how much weight an operator can safely put on the published scores.
The evidence window closes on 31 October 2025, so the AI-driven onboarding fraud the document warns about is described using data already nine months old at publication. In a threat category where tooling changes quarterly, the ratings probably understate the current position rather than overstate it.
Comparability is the next problem. The regulator kept the 2023 methodology but revised the wording used to describe risks, and many entries carry both a "new risk" and a "new wording" tag. A team reading an entry as newly identified may be reading a relabelled one, which makes internal trend analysis harder to evidence to an examiner.
Terrorist financing is rated differently at national and sector level. The national assessment treats casinos as low risk for terrorist financing while the Commission rates the sector medium. Both agree the likelihood is low, and on the Commission's matrix a low likelihood combined with a severe impact lands at medium, the same arithmetic that puts sanctioned customers at 3 out of 9. Operators will need to say which framing drives their controls.
Liability for software resale is also unsettled. If a reseller places a licensed supplier's games on an unlicensed site, the supplier's exposure turns on contract monitoring the regulator calls insufficient without quantifying it. Expect that gap to be tested in enforcement before it is settled in guidance.
The perimeter itself is in play. This assessment feeds the Treasury and Home Office decision on whether gambling operators other than casinos should stay outside the Regulations, and it sets no timetable for that decision. A future rating rise in a non-casino sector is the trigger any extension would rest on.
How does this compare with the 2023 assessment and the national picture?
Against the 2023 edition, the change in the Gambling Commission risk assessment is narrow: one sector up, everything else held. That restraint is informative, because the regulator is signalling that the risk profile of gambling has not deteriorated broadly, only at the seam where licensed businesses touch unlicensed ones.
Against the national picture the direction is upward. The National Risk Assessment of Money Laundering and Terrorist Financing raised the casino sector to medium risk, citing more money moving through remote casinos, new ways to play casino games, a revised view of money service activity in casinos, and the growth of illegal casinos targeting British consumers. Money service businesses remain high risk nationally for both money laundering and terrorist financing.
The remote casino numbers explain the attention. The remote casino chapter puts gross gambling yield for the sector at 5.0 billion pounds between April 2024 and March 2025, of which 4.2 billion came from slots. That is a large, fast, card-not-present flow onboarded by exactly the document-upload controls the regulator now says are being defeated.
How should compliance teams respond?
Rewrite the firm-level risk assessment against the 2026 ratings rather than appending to the old one, and record where you diverge from the supervisor and why. Then test onboarding against injected and synthetic documents, re-examine whether anti-money laundering thresholds are loss based, rebuild linked-account detection to work across a customer's accounts, and add named-counterparty monitoring to reseller contracts.
Suppliers have the harder job, because the new exposure sits in commercial paperwork rather than in the onboarding funnel. Knowing which sites actually run your games, and who the counterparty behind a reseller is, now belongs to the financial crime function rather than to sales.
The deeper lesson is about what a document image can prove. When a supervisor writes that face swaps and deepfake video are defeating due diligence, the answer is a stronger evidence source, not a stricter review of the same pixels. Zyphe reads the near-field communication (NFC) chip in a passport or national ID to ICAO 9303 and eIDAS standards with two-step liveness and no image upload, so there is no photo to forge, and shards the resulting data across a decentralised network so no single node holds a complete record. See KYC software and AML software, or book a demo.
The bottom line
The 2026 Gambling Commission risk assessment does two things. It tells suppliers that a business-to-business relationship is now a money laundering control point, and it tells remote operators that their supervisor no longer treats a document image plus a selfie as dependable proof of identity. Any firm onboarding customers remotely should read that second point as addressed to it.
Cited sources
- Gambling Commission, 2026 money laundering and terrorist financing risk assessment: executive summary
- Gambling Commission, 2026 risk assessment: casino (remote) risks and ratings
- Gambling Commission, 2026 risk assessment: gambling software sector
- Gambling Commission, 2026 risk assessment: casinos offering money service businesses
- Gambling Commission, 2026 risk assessment: illegal markets and the 26 million pound enforcement allocation
- HM Treasury and Home Office, National Risk Assessment of Money Laundering and Terrorist Financing 2025
- The Money Laundering, Terrorist Financing and Transfer of Funds (Information on the Payer) Regulations 2017
- LexisNexis Risk Solutions, One in every 100 identity check failures involves a deepfake document, image or liveness video, 14 July 2026
Michelangelo Frigo (Co-Founder at Zyphe) Michelangelo Frigo is a privacy and identity infrastructure expert and co-founder of Zyphe.