Inside Malta’s new AI gaming rulebook

A full breakdown of the MGA and MDIA’s AI Gaming Charter: scope, governance duties, and what it means for operators and suppliers.
Share on
Malta Gaming Authority logo

Most Malta-licensed operators are already using AI somewhere in their business. That might be a support chatbot, a fraud model or a marketing engine. Few have written down which systems those are, who owns them, or what happens if one goes wrong. That gap is exactly what the AI Gaming Charter is aimed at closing.

The Malta Gaming Authority (MGA), working with the Malta Digital Innovation Authority (MDIA), officially launched the Charter on 18 September.

It’s voluntary, but it gives licensees something they didn’t have before. It’s a Malta-specific reference point for what “responsible AI use” looks like in a gambling business, rather than a generic AI policy borrowed from another sector. The full Charter document runs to 48 pages.

Why it exists now

The Charter grew out of a targeted consultation the MGA opened in May, following an announcement at SBC Summit Malta in April.

At that event, Francois Piccione of the MGA had already argued that AI in gaming had moved beyond experimentation, and that governance needed to catch up. Kinga Warda, MGA’s Chief Officer for Policy and International Affairs, made a related point at the time: that responsible innovation should be treated as a competitive advantage, not a constraint.

The consultation was followed by a sector-wide survey and interviews with licensees. The results are blunt about where the industry actually stands.

Chatbots, data analytics and operational tools are well embedded. Fraud detection, AML checks, KYC and responsible gambling behavioural modelling are mostly still at proof-of-concept stage. Only a minority of respondents had a formal AI strategy in place.

Very few said they disclose AI use to customers or ask for consent before automated processing, even though most reported that a human always signs off on AI-supported decisions. That mismatch, using AI extensively but documenting and disclosing it poorly, is the specific problem the Charter tries to close.

What actually counts as “AI” here

Not everything automated is in scope. The Charter borrows its definition of an AI System from Article 3(1) of the EU AI Act: a system that infers from data how to generate outputs such as predictions, recommendations or decisions.

A rules engine that just follows a script isn’t an AI System under this definition. The MGA is explicit that it doesn’t want operators treating the Charter as a brake on ordinary workflow automation.

What matters more than the label is impact. The Charter splits systems into two tiers: lower-impact tools, such as internal coding assistants, and higher-impact systems that touch players directly or feed into compliance-sensitive decisions like account restrictions or KYC checks.

The second tier carries real weight. It requires stronger documentation, testing, human oversight and monitoring, while the first can be governed more lightly. Licensees also need to work out their own role under the EU AI Act, since a company can be a Provider for one system and a Deployer for another, each with different obligations attached.

The ten areas it covers

The guidance runs across ten themes, worth knowing even if you never read the full document.

  • Transparency and explainability: telling players when they’re dealing with AI, and avoiding what the Charter calls “AI washing,” where AI capabilities get overstated for marketing purposes.
  • Fairness and non-discrimination: bias testing and awareness of proxy variables. The Charter specifically flags geolocation, deposit patterns, device type, time-of-day activity, and payment behaviour as data points that can encode discrimination without touching protected characteristics directly.
  • Environmental sustainability: factoring in the energy and carbon cost of AI infrastructure, particularly for anyone training or fine-tuning their own models.
  • Data protection and security: standard GDPR principles of minimisation and purpose limitation, applied specifically to AI processing.
  • Human oversight: a person who can review, override, or reverse an AI decision, with defined triggers for escalating a player-facing chatbot conversation to a human agent.
  • Reliability and safety: testing, red-teaming for higher-impact systems, and rollback or kill-switch mechanisms.
  • Governance: the part licensees will feel most, covered below.
  • Reporting and metrics: tracking performance over time rather than treating deployment as a one-off event.
  • Notification requirements: telling the MGA and MDIA when something goes wrong.
  • Regulator involvement: how the two authorities support licensees through the process.

The parts operators will actually have to build

Two sections carry more practical weight than the rest of the document.

The first is logging. For every AI System, the Charter asks licensees to record the model version in use, the date and time of activity, the input processed, the output generated, any errors, and any human override.

Lower-impact systems can get away with sampled or aggregated logs. Higher-impact ones need fuller traceability, matching EU AI Act requirements wherever a system qualifies as High-Risk.

The second is explainability, split two ways. A system-level explanation covers what an AI tool does in general: its purpose, its main inputs, its known limitations. A decision-level explanation is narrower, a plain-language account of why a specific player got a specific outcome.

Neither requires handing over source code or fraud-detection logic. The Charter states plainly that transparency should not require disclosure of “source code, detailed model architecture, proprietary information, trade secrets” where doing so would undermine security.

For AI-generated content specifically, the line follows Article 50 of the EU AI Act. Content generators, or Providers, mark synthetic output in a machine-readable format, and anyone publishing a deepfake or AI-written public-interest content, as a Deployer, has to disclose it visibly.

The governance layer

This is where the Charter asks the most of licensees, and where most will need new internal structure rather than just a policy update.

It recommends an AI inventory, a live record of every AI System, its purpose, owner, risk tier and EU AI Act role. It also calls for a named senior person accountable for AI governance, along the lines of a Chief AI Officer.

Alongside that, licensees are asked to set up an AI oversight or ethics committee with representation from compliance, legal, data protection, risk and technology. Smaller licensees don’t need a standing committee for this. A documented governance forum with clear terms of reference is enough.

Charles Mizzi, CEO of the MGA, said:

“The AI Gaming Charter reflects a shared commitment between regulators, industry and technology experts to promote the responsible and transparent use of artificial intelligence. Our role as a regulator is not to stand in the way of innovation, but to help create the certainty and confidence needed for innovation to flourish responsibly.”

The Charter itself echoes this framing in its opening pages, describing the MGA as a regulator that does “not regulate specific tools or technologies, but rather the outcomes, risks, and behaviours associated with their use.”

Kenneth Brincat, CEO of the MDIA, said:

“Trust is fundamental to the responsible adoption of AI. As its use becomes increasingly embedded across the gaming sector, organisations need practical ways to understand where AI is being used, manage the associated risks and ensure that accountability and human oversight remain firmly in place.”

The document adds that the goal is to help Malta “support technological innovation while ensuring that AI remains transparent, accountable and trustworthy.”

If you’re an operator

The MGA’s own research found contestability handled inconsistently across B2C licensees. Some let players request human review of an AI decision, others don’t offer it at all.

The Charter pushes toward the former. A player affected by an AI-supported decision should get a plain-language explanation and a path to human review. Final calls on account restrictions or responsible gambling flags should stay with a person rather than being fully automated.

If your chatbot or behavioural monitoring tool doesn’t have defined escalation triggers yet, that’s the gap most likely to surface first, whether from a regulator or a complaint.

If you’re a supplier

The same research found B2B suppliers giving their operator clients very little visibility into how their AI actually works. Only one respondent said it provides that documentation at all.

The Charter treats this as unfinished business. A supplier acting as a Deployer of someone else’s AI has different duties than one acting as a Provider of its own, and the Charter expects suppliers to know which applies to each product line they sell.

Where a supplier doesn’t hold the player relationship directly, it’s still expected to support its clients’ compliance through documentation, risk information and engagement with the MGA, rather than leaving the B2C licensee to figure it out unassisted.

What the charter doesn’t do

It’s voluntary, and the MGA has been clear about that. There are no new legal obligations, and nothing that modifies existing duties under the EU AI Act, GDPR, the Data Act or the Cyber Resilience Act.

Where the text says “should” or “are encouraged to,” that’s good practice, not a rule. Where it says “in accordance with applicable law,” it’s pointing at an obligation that already existed before the Charter was written.

That distinction matters, but it shouldn’t be read as an invitation to wait. Voluntary charters have a habit of becoming the template for binding rules once a regulator has seen how the industry responds to them.

Licensees that take the guidance seriously now, building the AI inventory, assigning ownership, and setting up logging and oversight before it’s asked of them, will find it far easier to comply if and when the MGA moves from encouragement to enforcement.


About the author
Bianca Máthe

Bianca Máthe

Bianca Máthe is Publisher of iGaming Republic. She spent close to a decade on the supplier side of iGaming, working across the sector's core verticals: platform and player-engagement technology and crypto payments. That mix gave her a working knowledge of how operators, suppliers and payment providers actually run. In 2025 she started a media project, bringing that operational grounding to her editorial work. Her output includes interviews with high-profile iGaming executives, original reports, and in-depth features covering licensing, M&A, and the operators and suppliers shaping the sector. Based in Malta, she spends much of her time getting closer to emerging sectors like prediction markets, tracking how they're developing before the rest of the industry catches up.

Submit story

Do you have a story worth sharing?
Send it over to our editors!

Send story
Read More
Advertise with us