top of page

DraftKings AI Investigation Puts Betting Personalization Under Regulatory Scrutiny

5 days ago
13 min read

DraftKings faces an AI investigation after Massachusetts regulators responded to allegations that its promotional models identified customers likely to keep gambling and losing. The Massachusetts Gaming Commission said on September 24 that it would examine DraftKings first, then question every licensed sportsbook in the state.

The inquiry follows a New York Times investigation published five days earlier. That report described a machine-learning model built from customer betting records in 2023. The system reportedly estimated how strongly individual casino customers would respond to promotions, including how much additional money they might lose.

DraftKings disputes the central implication. The company told the Times that its promotions target sustained engagement, not customer losses. It also says it monitors potentially risky behavior and provides budgeting, account-history, limit-setting, and cooling-off tools.

The regulatory question extends beyond one model or company. FanDuel, BetMGM, Fanatics Sportsbook, and other licensed operators also rely on customer data to acquire, retain, and protect players. Massachusetts now wants to know where those activities overlap, what controls govern them, and whether existing rules address the resulting risks.

That makes the DraftKings AI investigation more than a dispute about targeted advertising. It is an early test of whether regulators can distinguish ordinary personalization from automated decisions that might exploit vulnerable customers.

Massachusetts Is Moving From AI Research to Operator Review

The immediate change is that Massachusetts will now inspect how betting companies use AI, rather than treating the technology as a future policy issue.

Commission Chair Jordan Maynard said staff would engage directly with DraftKings to understand the specifics reported by the Times. Executive Director Dean Serpa and the commission’s AI task force will lead the work, according to coverage of the operator review.

The review will then extend to every licensed online sportsbook in Massachusetts. Regulators expect to examine AI and machine learning across customer acquisition, promotions, responsible gaming, and other customer-facing operations.

That broad scope matters. An investigation limited to one DraftKings model might determine whether a particular allegation is accurate. An industry-wide review can reveal whether the reported practices reflect one company’s choices or a common operating model.

The commission has not announced an enforcement action, concluded that DraftKings violated state rules, or proposed a new regulation. Its first task is fact-finding. Maynard said additional policy action would follow only when appropriate.

Commissioner Paul Brodeur called the Times findings troubling but stressed the need to establish facts on the ground. That distinction is important because the available reporting describes internal systems and decisions, not a completed regulatory finding.

Massachusetts already has a basis for asking detailed technical questions. Its sports-wagering rules require operators to document controls for computerized algorithms, automated decision-making, machine learning, and artificial intelligence.

Those controls must address permissible uses, prohibited purposes, and the data feeding automated systems. The framework gives regulators a route into model governance without waiting for a new AI statute.

DraftKings also sits squarely within the commission’s authority. The company launched sports betting in Massachusetts on March 10, 2023. It received a full five-year Category 3 license in July 2025, according to its license record.

However, legal authority does not make the review simple. Regulators must establish which models operated in Massachusetts, when they operated, and what decisions they influenced.

They must also separate online casino activity from sports wagering. Massachusetts permits mobile sports betting but not the broad online casino operations available in several other states. A model developed using casino data does not automatically prove that the same system affected Massachusetts bettors.

The regulator therefore needs more than a presentation about company-wide AI strategy. It needs model inventories, deployment records, data lineage, experiment designs, internal approvals, and evidence showing which Massachusetts customers entered any relevant workflow.

The first regulatory milestone will be whether the commission asks those precise questions. A general discussion about responsible gaming would leave the reported conflict unresolved.

The DraftKings AI Investigation Centers on Two Uses of the Same Data

The core tension is not whether DraftKings uses machine learning, but why predictive data appeared useful for promotions and less acceptable for early risk intervention.

The Times said it interviewed more than 40 former DraftKings employees and reviewed internal research memos, presentations, Slack messages, and customer betting records. Its promotion model investigation described a system that analyzed dozens of data points.

Those inputs reportedly included betting frequency, daily account balances, and the amount a customer lost relative to total wagers. The model assigned what amounted to a promotion-elasticity score, meaning an estimate of how betting behavior would change after an incentive.

Elasticity is not automatically a measure of addiction. A customer can respond to a promotion without experiencing gambling harm. A person can also develop harmful behavior without ranking highly in a marketing model.

Yet the signals can overlap. Increased betting frequency, declining balances, repeated losses, and strong responses to incentives can have both commercial and safety relevance. Context, validation, and the action attached to the score determine what the model does.

The Times reported that customers with higher elasticity scores tended to wager more on slot games than customers with lower scores. It also cited an internal finding that slot revenue was more responsive to promotions than revenue from other casino games.

The commercial logic is clear. Promotions cost money, so an operator wants to send them where they will change behavior. Machine learning can rank customers more precisely than a broad campaign based on geography or recent activity.

DraftKings reportedly told investors that analytics improved margins on promotion-driven sports bets by 13 percent in 2025. It also said AI helped personalize hundreds of millions of dollars in promotional spending.

The controversy begins when the optimized outcome includes additional customer losses. A model does not need a variable labeled vulnerability to create risk. It can discover behavioral combinations that correlate with profitable but potentially harmful play.

Former employee Jayden Butts told the Times that the model’s practical logic amounted to giving more incentives to customers expected to lose more and continue playing. He left DraftKings in 2024, according to the report.

DraftKings rejected the suggestion that it improperly targets customers based on losses. It said promotions go to customers who show sustained engagement with its platform.

That response creates a testable question for Massachusetts. Regulators can compare the company’s stated selection policy with the actual variables, objective functions, score thresholds, and downstream campaign decisions.

The reported contrast with responsible-gambling work sharpens that question. Former employees also described an internal effort to predict which customers faced elevated gambling risk.

One employee reportedly reviewed academic research and trained a model using records from customers already flagged for risky behavior. The project did not reach deployment.

Lori Kalani, DraftKings’ chief responsible gaming officer, told the Times that the company monitors potentially risky behaviors. She said it declined to use predictive risk technology because evidence did not show that the approach was helpful.

That concern is not inherently unreasonable. A weak safety model can produce false positives, miss customers in distress, or prompt interventions that lack clinical support. Automated risk labels also raise privacy and fairness questions.

Still, the evidentiary standard must be consistent. If uncertain predictions are acceptable when selecting commercial offers, regulators can ask why comparable uncertainty blocks preventive uses entirely.

This is the central tradeoff in DraftKings AI gambling practices. The business can optimize measurable short-term responses, while responsible-gaming systems must predict a more complex and less observable form of harm.

Massachusetts Already Identified the Limits of AI Risk Detection

The commission’s own research supports caution about predictive safety tools, but it also recommends stronger oversight of commercial personalization.

In November 2025, the Massachusetts Gaming Commission published research from the University of Nevada, Las Vegas International Gaming Institute. The AI risk report examined current and potential gambling-industry uses of artificial intelligence.

Researchers found that AI was already embedded in core business functions. They identified advanced personalization as a source of possible customer benefits and increased risk for vulnerable populations.

That dual-use finding closely matches the current dispute. A behavioral model can tailor an account reminder, recommend a deposit limit, select a promotion, or prioritize a customer for VIP attention. The underlying analytical capability does not determine whether the outcome protects or pressures the customer.

The report also found uneven evidence behind commonly cited markers of gambling harm. Many behavioral indicators lacked strong validation, while payment-related indicators had the strongest supporting evidence.

That conclusion helps explain why DraftKings might question a predictive intervention model. Frequency or session duration alone cannot establish that a customer has a gambling disorder. Even a sophisticated score can confuse intense recreational play with genuine distress.

The research did not recommend ignoring predictive systems. It instead described a governance problem involving model evidence, financial data, privacy, consent, cross-operator visibility, and regulatory barriers.

No single operator sees a customer’s complete financial or gambling activity. Someone might maintain accounts across several sportsbooks while showing only moderate activity at each one. A model trained on one platform can therefore underestimate cumulative risk.

Financial data can provide stronger warning signs, but it is also more sensitive. Linking affordability information to betting accounts raises questions about consent, access, retention, security, and appropriate intervention.

Cross-operator data sharing presents another conflict. It could help identify customers moving rapidly among platforms, but it could also create a centralized record of sensitive financial and behavioral information.

These limitations should shape the Massachusetts review. Regulators should not demand that every operator deploy an unproven prediction model as a quick response to bad publicity.

They can still require operators to explain why one model was approved while another was rejected. Relevant evidence includes validation standards, error tolerances, responsible owners, audit procedures, and the consequences of wrong predictions.

A false marketing prediction might waste a promotional credit. A false safety prediction could restrict an account or incorrectly label a customer. Conversely, failing to identify a vulnerable customer can allow serious harm to continue.

Those outcomes have different costs, which can justify different model thresholds. However, different thresholds do not justify a complete lack of scrutiny over commercial optimization.

The commission’s report also recommended internal AI leadership or a dedicated task force. Massachusetts subsequently created such a task force, which will now participate in the operator evaluations.

That sequence gives the inquiry more credibility. The regulator did not encounter algorithmic gambling for the first time after one newspaper story. It commissioned research, studied the evidence gaps, and created an internal structure before the present controversy.

The harder question is whether the commission has enough technical access. Operators can describe a model in broad language while withholding the details that reveal its actual objective.

A meaningful audit must examine training labels, feature importance, experimental groups, deployment dates, and measured outcomes. It should also test whether stated exclusions worked, including rules intended to protect self-excluded or otherwise restricted customers.

Without that evidence, AI sports betting regulation risks becoming a disclosure exercise. Companies could submit policy documents that sound protective while automated systems continue operating beyond effective review.

DraftKings’ Responsible-Gaming Tools Do Not Resolve the Model Conflict

Player controls can reduce harm, but voluntary tools do not answer how DraftKings decides which customers receive offers.

DraftKings has invested in visible responsible-engagement features. These include My Budget Builder, My Stat Sheet, player-set limits, cooling-off periods, and educational experiences developed with Mindway AI.

On September 14, five days before the Times investigation appeared, the company announced additional customer initiatives. Its responsible engagement update introduced custom cooling-off periods ranging from three to 364 days.

DraftKings also expanded Gamalyze, a gamified educational experience created with Mindway AI. The company has used football and casino-themed versions to encourage customers to reflect on gambling decisions.

These features show that DraftKings does not categorically reject AI or behavioral tools for customer protection. They also demonstrate an effort to place budgeting and account controls inside the product.

However, voluntary controls operate at a different point in the customer journey. A limit works after someone recognizes a need and chooses to activate it. A cooling-off period also depends on the customer initiating a pause.

Predictive intervention asks whether an operator should act before that request. It examines whether a pattern of deposits, losses, repeated sessions, or promotion responses warrants outreach or promotional restraint.

DraftKings says it already monitors risky behavior and contacts some customers. The unresolved issue is how those decisions relate to its marketing systems.

For example, a regulator could ask whether a responsible-gaming flag automatically suppresses promotional messages. It could examine how quickly that suppression takes effect and whether it covers email, push notifications, VIP outreach, and in-app offers.

Massachusetts has prior evidence that operational controls can fail even when rules are clear. In 2024, DraftKings mistakenly sent a golf-betting email to more than 1.2 million Massachusetts residents or registered users, including 184 people on the state’s voluntary self-exclusion list.

That incident does not prove intentional targeting. It does show why regulators cannot evaluate safeguards only by reading formal policies.

DraftKings also says its long-term business depends on customers betting within their means and treating gambling as entertainment. That position aligns customer protection with commercial sustainability.

The short-term incentives are more complicated. A promotion team is measured through engagement, conversion, betting activity, customer retention, and margin. A responsible-gaming team is measured through reduced risk and effective interventions.

Those goals can coexist, but they can also conflict around the same customer. A person who responds strongly to incentives can look valuable to one system and concerning to another.

Governance should resolve that conflict before either model reaches the customer. The company needs an explicit hierarchy showing when safety signals override revenue optimization.

Independent review is especially important because companies select their own performance metrics. A promotion can appear successful if it raises betting volume, even if the campaign also concentrates losses among high-risk users.

The reverse problem affects responsible-gaming tools. An operator can count how many people opened a budgeting feature without showing whether harmful play declined.

The Massachusetts inquiry should therefore focus on outcomes. It can ask how promotional models changed losses, deposit behavior, session frequency, and subsequent risk flags for each scored group.

It can also test DraftKings against other licensed operators. If FanDuel, BetMGM, or Fanatics uses different suppression rules or review processes, those differences can identify workable safeguards.

The goal should not be to demand identical models. It should be to establish a baseline: operators must know what their automated systems optimize, identify foreseeable harms, document conflicts, and prove that protective controls operate in practice.

The Industry Faces a Governance Test, Not an AI Ban

Treating every statistical model as dangerous would miss the problem, because the decisive issue is the action attached to a prediction.

Sportsbooks have used data analysis long before generative AI became a familiar consumer term. They calculate odds, detect fraud, segment customers, forecast value, manage bonuses, and monitor suspicious activity.

Machine learning expands those capabilities by finding patterns across many variables. It can update rankings quickly and personalize decisions for individual accounts.

That does not make every automated decision equivalent. Fraud detection protects the platform and legitimate customers. A safer-play alert can direct support toward a person showing risk. A promotion model attempts to increase profitable activity.

The DraftKings AI investigation asks where commercial personalization crosses a regulatory or ethical line. That boundary cannot depend only on whether an algorithm uses a particular technical method.

A basic scoring rule can cause harm if it pressures vulnerable customers. A complex model can benefit customers if it stops promotions, recommends limits, or triggers careful human review.

Regulators therefore need purpose-based rules. They should assess what outcome the operator seeks, which data it uses, who experiences the consequences, and what appeal or correction process exists.

Automated decisions also need clear ownership. A data-science team might build a score, while marketing staff decide how to use it. Compliance staff may review only the final campaign rather than the model behind it.

That separation can create accountability gaps. Each group can accurately describe its own limited role while no one owns the combined customer impact.

Massachusetts can address that problem through model inventories and named accountable executives. Every material system should have an owner, approved purpose, defined data sources, validation schedule, and retirement process.

Operators should also document prohibited uses. A company might ban campaigns aimed at self-excluded customers, people with active cooling-off settings, or accounts under responsible-gaming review.

Those exclusions need technical enforcement and regular testing. A written restriction offers little protection if customer lists, model scores, and messaging systems do not synchronize correctly.

Human review is not a complete answer. Staff members can follow biased recommendations or approve high volumes of automated decisions without meaningful evaluation.

Effective oversight requires access to explanations that match the decision. Regulators do not necessarily need every line of proprietary code, but they do need enough evidence to reconstruct why customers entered a target group.

Data retention is another concern. Historical betting records can improve prediction, but they also preserve detailed accounts of financial behavior and personal habits.

The commission should ask how long feature data and model scores remain available. It should examine whether information collected for safety can later enter marketing workflows, or whether strict separation prevents that reuse.

Competition creates further pressure. If one sportsbook improves margins through more precise promotions, rivals have an incentive to develop similar systems. Voluntary restraint becomes harder when each operator believes others are extracting more value from customer data.

That dynamic supports common minimum rules. Clear standards can limit harmful competition without banning legitimate analytics or requiring companies to disclose trade secrets publicly.

The review also offers a chance to distinguish personalization from manipulation. A relevant offer based on a preferred sport is different from an incentive timed around repeated deposits, attempts to recover losses, or other potential distress signals.

The boundary will still require judgment. Yet uncertainty is a reason to establish governance, not a reason to leave automated decisions unexamined.

Three Signals Will Show Whether the Review Changes Betting Oversight

The next test is whether Massachusetts converts broad concern into evidence requests, enforceable boundaries, and measurable customer protections.

The first signal is the information demanded from DraftKings. A review focused on presentations and general policies would weaken the inquiry’s value.

A stronger process would request model documentation, deployment histories, experiment results, promotion criteria, responsible-gaming exclusions, and Massachusetts-specific records. That evidence would show whether reported casino practices touched sports bettors in the state.

The second signal is whether the commission publishes a common framework for all operators. The review already covers acquisition, promotions, and responsible gaming across licensed sportsbooks.

A useful framework would define material automated decisions and require inventories, accountable owners, testing, and incident reporting. It would also clarify when operators must notify regulators about major model changes.

Such a framework would strengthen the article’s central judgment. It would show that Massachusetts sees AI oversight as an ongoing licensing responsibility, not a one-time response to DraftKings.

The third signal is how the commission handles the gap between commercial and safety models. Regulators should not assume that predictive risk detection is accurate merely because promotion optimization exists.

They can require operators to explain their evidence standards for both uses. They can also examine whether uncertain risk signals at least suppress marketing, even when they do not justify account restrictions.

That intermediate action matters. A sportsbook does not need to diagnose gambling addiction to decide that a potentially vulnerable customer should stop receiving targeted incentives.

The review’s outcome remains uncertain. Massachusetts might find that the reported systems never operated in its sports-wagering market. It might identify control weaknesses, require corrective action, or begin formal rulemaking.

DraftKings may also provide evidence that its promotional systems excluded risky customers and did not target losses as alleged. The commission has not reached a conclusion, and the Times findings remain disputed by the company.

Still, the underlying governance issue will persist. Betting platforms can observe customer behavior continuously, personalize offers rapidly, and test which incentives produce more activity.

Those capabilities create a responsibility that generic AI principles cannot satisfy. Regulators need to examine actual objectives, data, decisions, and outcomes.

For bettors, the practical question is whether personalization serves their stated preferences or exploits patterns they may not recognize. For product and data teams, the question is who can stop a profitable model when its customer impact becomes difficult to defend.

Watch what Massachusetts requests, what it publishes, and whether safety signals gain authority over marketing systems. Those three developments will determine whether the DraftKings AI investigation becomes a lasting model for AI sports betting regulation.

Give every agent the context to do better work

Connect your agents to the knowledge, decisions, and history already organized in remio.

remio currently supports Windows 10+ (x64) and Macs with Apple silicon.

Your AI Partner at Work
Get more done with remio

Plan. Create. Deliver.
All in one place.

bottom of page