UK Watchdog Warns AI Is Being Used to Bypass Gambling KYC

Customers of UK gambling websites are using artificial intelligence and other techniques to bypass know-your-customer checks, the Gambling Commission has warned.
The regulator highlighted the issue in a new assessment of money laundering risks in the sector, Public reporting indicates that .
Identity controls face synthetic evidence
AI can help criminals alter documents, generate convincing images and imitate a customer during remote verification. Gambling platforms may also face account sharing, identity rental and the use of third parties to pass checks.
Operators should combine document verification with liveness testing, device intelligence, payment ownership checks and ongoing behavioural monitoring. A successful onboarding check should not prevent later review when deposits, withdrawals or account access patterns change.
Controls must also account for accessibility and avoid unfairly excluding legitimate customers. The regulator’s warning shows why identity verification should be treated as a continuous risk process rather than a single gateway at registration.
Risk indicators after onboarding
An account may pass identity checks yet still be controlled by another person. Operators should look for rapid changes in device, location or payment instrument; multiple accounts using the same technical identifiers; and withdrawals to methods not associated with the verified customer.
Gambling risk assessments should connect KYC with affordability, source-of-funds and transaction monitoring. AI-generated documents are more difficult to detect visually, so verification should use authoritative data and consistency checks. Manual review remains important where automated systems return conflicting signals.
Questions for gambling operators
- Can the same device or payment method open several accounts?
- Are identity checks repeated after material account changes?
- Do withdrawals return to an instrument owned by the verified customer?
- Can reviewers identify AI-altered documents and synthetic images?
Next focus: Operators should test controls against realistic synthetic identities rather than relying on vendor accuracy claims. Red-team exercises can show whether a combination of generated documents, manipulated video and third-party payments defeats the full onboarding process.



