AI Governance Institute
← News

DraftKings AI Model Targets Chronic Losing Gamblers With Promotional Ads

What happened

The Electronic Frontier Foundation published DraftKings Is Using AI to Supercharge the Harms of Online Behavioral Advertising on September 24, 2026. The report analyzes how the sports betting platform trains machine learning models on its own customer betting histories. The goal: classify and target chronic losing gamblers with promotional content. No third-party data sharing is required. First-party behavioral records alone are sufficient to build predictive models. Those models identify the most financially vulnerable users and re-engage them. The report frames this as a structural governance problem, not a data-sharing one, because standard consent and data-minimization requirements were met throughout. The analysis does not allege a breach of current law. It argues that AI makes the harm scalable in ways existing consumer protection frameworks were not designed to address.

Why it matters

  • ·Behavioral data collected for one lawful purpose (account operation, fraud prevention) can be repurposed to train models that target vulnerable customers. Existing data minimization and purpose-limitation controls under frameworks like the Proposed CPPA Regulations on Cybersecurity, Risk Assessments, and Automated Decision-Making Technologies may not block this if the data use is deemed consistent with the original collection context.
  • ·This case signals growing regulatory interest in AI-powered personalized marketing that targets people showing signs of harm. Compliance teams in gaming, financial services, insurance, and health tech should assess whether their model-driven retention or re-engagement programs could be characterized as predatory targeting under consumer protection or unfair-practices standards, including FTC Enforcement on AI (Section 5 of the FTC Act).
  • ·The EFF analysis underscores that AI amplifies the harm of behavioral advertising by enabling precision targeting at scale with no incremental data cost. This exposes a gap in existing fairness and bias monitoring controls. Those controls check for outcome disparity across demographic groups. They do not check for systematic targeting of individual vulnerability states identified through predictive modeling.

Governance controls affected

What to do now

  • ☐Map every machine learning model used in customer marketing, retention, or re-engagement to the underlying data inputs: flag any model trained on loss history, financial distress signals, or behavioral patterns that could classify customers by vulnerability.
  • ☐Review your stated purpose for collecting customer behavioral data against the downstream uses those data inputs currently feed, and identify any model application where the use would surprise a reasonable customer who read your privacy notice at sign-up.
  • ☐Ask your data science and marketing teams whether any AI-driven campaign segmentation or personalized outreach specifically targets customers who have stopped engaging or who show high-loss patterns, and document whether human review is required before those segments receive promotional content.
  • ☐Assess whether your AI fairness and bias monitoring program checks for disproportionate targeting of vulnerable populations (not just protected class disparities), and update your evaluation criteria if that check is absent.
  • ☐Engage legal counsel to evaluate your customer-facing AI marketing uses against FTC unfair-practices authority and any applicable state automated decision-making or consumer protection rules, particularly if your business operates in gaming, lending, insurance, or health-adjacent categories.

What to watch next

Regulators are increasingly treating AI-powered behavioral targeting of vulnerable populations as a consumer harm issue, not merely a data privacy one. The FTC Enforcement on AI (Section 5 of the FTC Act) provides existing authority to act on unfair or deceptive practices without waiting for new AI-specific legislation. State-level automated decision-making rules are advancing in California and Colorado. They are beginning to require impact assessments for AI systems that affect consumer access to products and services. This could extend to retention and re-engagement marketing. Compliance teams should monitor whether the DraftKings analysis draws a formal regulatory response and whether problem-gambling advocacy groups file complaints that prompt FTC or state attorney general review.

Stay ahead of stories like this

Get every US AI governance development like this one, plus the rest of the week's developments. Every Thursday.

Powered by Buttondown.

Related Coverage

Research2026-09-28

Six-Pillar AI Governance Model Sets Enterprise Program Maturity Benchmark

Concurrency, a technology consulting firm, has published a practitioner framework organizing enterprise AI governance into six pillars: inventory, validation, monitoring, explainability, fairness testing, and incident response. The framework targets enterprises that have deployed AI but lack structured approval gates, continuous monitoring, or audit evidence. It provides a replicable operating model that compliance teams can use to measure and close program gaps.

Enforcement2026-09-28

EU AI Office Inspections Target Hiring, Credit, and Healthcare AI

The European AI Office and national market surveillance authorities launched coordinated compliance inspections of high-risk AI systems in September 2026. The inspections focus on resume-screening tools, credit-assessment systems, and healthcare triage applications. Organizations lacking documentation, audit trails, and rapid remediation plans are the primary targets.

Research2026-09-26

BIS Warns AI Strains Core Bank Supervisory Expectations on Model Governance

The Bank for International Settlements (BIS) published a speech on September 18, 2026, signaling that advanced AI and large language models (LLMs) are outpacing existing supervisory expectations for banks. The speech identifies governance, model validation, independent review, and explainability as the primary stress points. Banks and their enterprise counterparts in financial services should treat this as a forward signal that supervisors will raise the bar on AI model oversight.