Monday, 18 May 2026

Agentic AI and the Online Gambling Industry

A New Paradigm of Cybercrime

by Attorney-at-law Dr George Zlati[1]University lecturer, specialized in cybercrime and blockchain technology

Attorney-at-law Dr George Zlati – University lecturer, specialized in cybercrime and blockchain technology

Context

In a series of two articles previously published we analysed the main risks associated with online gambling, as well as the typologies of cybercrime affecting the industry.[2] One of the conclusions of those analyses was that the use of bots based on artificial intelligence could, in the immediately following years, significantly replace the human factor. This prediction has materialised within a much shorter timeframe than anticipated. Over the course of 2025, a technological transition took place that changes the terms of the problem: the shift from conventional bots and generative AI models to quasi-autonomous AI agents capable of planning and executing complex attacks with reduced or no human supervision.

The ENISA Threat Landscape 2025 report highlights that the reference year marks a period in which artificial intelligence reshaped the cyber-threat landscape, with AI-assisted phishing campaigns accounting for over 80% of observed social engineering.[3] Along the same lines, the Sumsub Identity Fraud Report finds that the share of multi-step attacks grew from 10% in 2024 to 28% in 2025, equivalent to an increase of approximately 180% in a single year.[4] For the online gambling industry, whose platforms combine high transaction volumes, sensitive personal data and bonus-type products, this shift is particularly relevant.

From Conventional Bots to AI Agents

The difference between a conventional bot and an AI agent is not one of labelling. A traditional bot executes a predefined sequence (fills in a form, solves a captcha, repeats a bet) on the basis of rigid automation; its behaviour is predictable and, as a rule, detectable through behavioural analysis. By contrast, the AI agent receives an abstract objective (for example, “obtain €5,000 in welcome bonuses across 200 EU-licensed platforms”), breaks it down into sub-objectives, independently selects the necessary tools and adjusts its strategy between iterations. Where it encounters a detection mechanism it cannot circumvent, the AI agent retains the information, transfers it to other sessions and attempts a different approach on the next run.

This capacity for cumulative learning explains why the Sumsub report describes the emergence, in 2025, of systems in which a single agent can orchestrate an entire attack chain, combining the generation of forged identity documents, deepfake video submission and human-like interaction at high speed.[5]

Agentic AI

Modus Operandi of the Offender Assisted by Agentic AI

The mass creation of fictitious accounts has accelerated sharply with the rise of artificial intelligence. Instead of a network of bots simultaneously creating tens of thousands of superficial, easily detectable accounts, we are now faced with algorithmic identity farms in which each account is built as a plausible identity, “matured” over months through micro-transactions, utility payments and social-media interactions, until the profile surpasses advanced KYC controls. According to the Deloitte Center for Financial Services, fraud facilitated by generative AI is estimated to produce losses of approximately USD 40 billion in the United States by 2027, compared to USD 12.3 billion in 2023.[6]

Closely related, the circumvention of KYC procedures through deepfake technology has become operational at scale. Specialised applications such as JINKUSU CAM (reported by the OECD AI Incident Monitor in April 2026)[7] or ProKYC (reported in October 2024)[8] are traded on darknet forums. These tools enable the real-time injection of a synthetic video source directly into the browser’s camera stream, bypassing both liveness verification and random-gesture prompts. They are not operated manually but are controlled by autonomous agents that synchronise the deepfake stream with synthetically generated identity documents and device metadata. OKX has publicly acknowledged that the abuse of AI to circumvent KYC controls has become a cross-cutting problem for the entire crypto sector.[9]

Money laundering through gambling platforms, particularly crypto-casinos, now operates through AI agents. On 7 April 2026, Whale.io announced the launch of the first Model Context Protocol (MCP) for a crypto-casino, enabling external agents to interact directly with the platform, placing bets and interpreting the state of the game autonomously.[10] Although the autonomous-withdrawal function is not expressly mentioned in the announcement, the same infrastructure can be exploited to automate the classic laundering cycle: funding the account with virtual currency derived from criminal offences, placing a high number of bets on high-probability outcomes and withdrawing the “winnings” to a new wallet. [11] The emergence of automated interfaces such as the one proposed by Whale.io is liable to industrialise this model.

Algorithmic bet manipulation and collusion between agents constitute a specific risk. In online poker, several autonomous agents can collude without using text messages or static patterns, dynamically adjusting their play based on a global strategy. In sports betting, agents can exploit the lag between an event occurring and the odds being updated, a phenomenon known as latency arbitrage. We wish to emphasise, however, that the mere exploitation of latency is not in itself unlawful. It becomes relevant under criminal law only where it involves unauthorised access to the operator’s information flow or the alteration of odds through active conduct designed to artificially influence the system’s decisional mechanism.

Finally, prompt injection attacks against the operator’s chatbots round out the threat landscape. According to the Top 10 list published by OWASP for 2025, prompt injection constitutes the principal vulnerability of applications based on large language models.[12] An AI agent controlled by the offender can transmit hidden instructions to the chatbot, either directly or through content hosted on third-party pages, causing it to disclose confidential information, grant unjustified bonuses or alter account parameters.

Challenges of Legal Classification

The legal classification of the conduct described above does not, in itself, raise unusual difficulties. The acts fall within the scope of Article 249 of the Romanian Criminal Code (computer fraud), Article 244 CC (fraud), Article 250 CC (fraudulent financial operations), Article 325 CC (computer forgery) or Article 360 CC (unauthorised access to a computer system). Money laundering is applicable under Article 49 of Law No 129/2019, and the operation of gambling without a licence remains subject to Government Emergency Ordinance No 77/2009.

The AI agent, however advanced it may be, is a tool in the hands of the human offender, similar to an automated script or a malicious program. Criminal liability therefore falls on the user who directed the use of the agent with a view to producing the unlawful result, regardless of the degree of operational autonomy of the system.

A problem specific to self-evolving AI agents remains, however, the scenario in which, by virtue of its own learning capacity, the agent independently discovers an unlawful technique not concretely anticipated by the user. The solution fits within the classical logic of culpability: if the technique was foreseeable for a reasonably informed user, the offence is established in the form of indirect intent; if it was not foreseeable, liability for a negligent offence may be examined, to the extent that such an offence is criminalised; and if foreseeability cannot be established at all, mistake of fact (Article 30 CC) operates with exculpatory effect, excluding the intentional form of the offence. The user’s responsibility is not reduced to the moment of launching the agent, but is assessed against the entirety of the reasonable control exercised over the manner in which the agent operates: the choice of model, the definition of objectives, the restrictions imposed, the monitoring of results.

Two distinctions are warranted for cases involving an autonomous agent operating at scale. Where the agent simultaneously attacks dozens or hundreds of platforms and succeeds only on a few, the remaining attempts remain punishable, each operator constituting a distinct passive subject. The automated creation of a high number of fictitious accounts on the same operator’s platform, by contrast, takes the form of a continuing offence, grounded in the unity of the user’s criminal resolution.

As regards the platform operator, where its own AI agent (chatbot, anti-fraud system, personalisation engine) is compromised through prompt injection or data poisoning, the corporate criminal liability of the legal person (Article 135 CC) becomes relevant. The operator’s conduct may take the form of commission by omission (Article 17 CC), the source of the duty to act being the licence agreement issued by the Romanian National Office for Gambling (ONJN), the provisions of Government Emergency Ordinance No 77/2009, Article 26 of Regulation (EU) 2024/1689 and, in cross-border situations, Directive (EU) 2022/2555 (NIS2).[13] The obligations laid down by Regulation (EU) 2024/1689, in particular the retention of operational logs for at least six months (Article 26(6)) and continuous monitoring (Article 26(5)), establish the expected standard of diligence.

Evidentiary Regime

Investigating an offence committed through an AI agent raises a specific set of evidentiary challenges. The decisive evidence will typically consist of the agent’s operational logs (required, indeed, by Article 26(6) of Regulation (EU) 2024/1689), the initial prompts, the system prompts, the API keys and the logs of MCP-type protocols. Their assessment and interpretation generally require the appointment of a digital forensics expert, and the link between the agent and the natural-person user is established, ideally, by correlating walletdevice fingerprint ↔ identity, a mechanism supported by emerging solutions such as Agent-to-Human Binding.

The European Framework, the AI Act and Agentic Defence

From 2 August 2026, the majority of the provisions of Regulation (EU) 2024/1689, including those concerning the high-risk systems listed in Annex III, become fully applicable.[14] Online-gambling operators deploying agents for the behavioural profiling of users or for bonus-award decisions must carefully examine whether their own systems fall within this category. The ceiling for administrative sanctions varies according to the type of infringement: EUR 35 million or 7% of worldwide turnover for prohibited practices (Article 5), and EUR 15 million or 3% for obligations relating to high-risk systems (Article 99(4)).

On the defensive side, conventional mechanisms (captcha, device fingerprinting, facial scanning, static anti-fraud rules) are becoming insufficient in the face of AI agents capable of mapping and circumventing them between iterations. Building an agentic defence in turn requires deploying autonomous agents that monitor gambling behaviour and correlate signals across platforms using graph-analytics technology. Chainalysis and TRM Labs launched, in March 2026, blockchain-investigation systems operated by autonomous agents, and Sumsub proposed, in January 2026, the Agent-to-Human Binding solution, under which each agent is linked to a responsible natural person, a prerequisite for any legal construction based on imputation.[15]

Conclusions

The transition from traditional bots to AI agents that plan, learn and adapt poses challenges that are at once technological and legal for the online gambling industry. Classic modi operandi (fake accounts, bonus abuse, KYC circumvention, money laundering, bet manipulation) persist in structure but are now deployed at far greater scale and velocity.

For the in-house counsel of a gambling operator, its own platform’s exposure may be assessed through five successive questions: (i) are all interactions between the operator’s AI agents and users logged for at least six months?; (ii) is there a written procedure for responding to prompt injection and data poisoning, with a clear ONJN notification threshold?; (iii) is each AI agent assigned to a named natural person responsible for it, so that an omissive conduct may be imputed to the operator under Article 17 CC?; (iv) does the KYC procedure go beyond facial scanning and basic liveness, incorporating video-injection detection and device-metadata coherence checks?; (v) have behavioural-profiling and bonus-award systems been explicitly assessed against Annex III of Regulation (EU) 2024/1689? A negative answer to any of the first three questions opens direct criminal exposure, while negative answers to the remaining two open administrative exposure under the AI Act.

For the gambling industry, 2026 is no longer the year in which Agentic AI is a topic of interest for the future; it is the year in which, in the absence of the logging required by Article 26 of Regulation (EU) 2024/1689 and of an internal procedure for responding to prompt injection and data poisoning, the operator risks both administrative and criminal liability for the conduct of its own system.

 

[1] Attorney-at-law, PhD, at Zlati, Ionescu & Chiperi – Civil Professional Partnership of Attorneys, university lecturer at the Faculty of Law of Babeș-Bolyai University in Cluj-Napoca, specialising in cybercrime and blockchain technology.

[2] See G. Zlati, Risks Associated with Online Gambling, and Cybercrime Risks for the Online Gambling Industry, Casino Inside, https://www.casinoinside.ro/.

[3] ENISA, Threat Landscape 2025, October 2025 (version 1.2, January 2026), https://www.enisa.europa.eu/publications/enisa-threat-landscape-2025.

[4] Sumsub, Identity Fraud Report 2025-2026, official press release, November 2025, https://sumsub.com/newsroom/sumsubs-annual-report-fraud-shifts-to-complex-multi-step-schemes-in-2025-agentic-ai-scams-poised-to-surge-in-2026/.

[5] Ibid.

[6] Deloitte Center for Financial Services, Generative AI Is Expected to Magnify the Risk of Deepfakes and Other Fraud in Banking, May 2024, https://www.deloitte.com/us/en/insights/industry/financial-services/deepfake-banking-fraud-risk-on-the-rise.html.

[7] OECD AI Incident Monitor, AI Deepfake Tools Bypass KYC, Fueling Financial Fraud in Crypto and Banking, incident reported on 6 April 2026, https://oecd.ai/en/incidents/2026-04-06-c4a3.

[8] OECD AI Incident Monitor, ProKYC incident, reported on 11 October 2024, https://oecd.ai/en/incidents/2024-10-11-c970; for technical analysis, see Cato Networks CTRL report.

[9] See S. Cole, AI-Generated Fake IDs Bypass Crypto Exchange KYC Checks: OKX Says Industry-Wide Issue, 404 Media / Nasdaq, February 2026, https://www.nasdaq.com/articles/ai-generated-fake-ids-bypass-crypto-exchange-kyc-checks-okx-says-industry-wide-issue.

[10] Whale.io Launches the First AI Agent MCP for Crypto Casino, press release dated 7 April 2026, https://chainwire.org/2026/04/07/whale-io-launches-the-first-ai-agent-mcp-for-crypto-casino/.

[11] Chainalysis, 2025 Crypto Crime Report, January 2025, https://www.chainalysis.com/blog/2025-crypto-crime-report-introduction/. The data are also cited by FATF, Targeted Update on the Implementation of the FATF Standards on Virtual Assets and VASPs, June 2025; see also FATF, Horizon Scan – AI and Deepfakes, 22 December 2025.

[12] OWASP Foundation, Top 10 for Large Language Model Applications — LLM01:2025 Prompt Injection, https://genai.owasp.org/llmrisk/llm01-prompt-injection/.

[13] See, for an analysis of corporate criminal liability in the financial-technology sector, A.R. Trandafir (Ilie), Răspunderea penală a persoanei juridice [Criminal Liability of Legal Persons], C.H. Beck, Bucharest, 2020, p. 145 et seq.

[14] Regulation (EU) 2024/1689 of the European Parliament and of the Council of 13 June 2024 laying down harmonised rules on artificial intelligence, OJ L 1689/2024, Art. 113. Sanctions are set out in Art. 99(3)–(5).

[15] Chainalysis Introduces the First Blockchain Intelligence Agents, 31 March 2026; TRM Labs, Co-Case Agent: An AI Assistant for Every Crypto Investigation, 25 March 2026; Sumsub, AI Agent Verification Introduces Agent-to-Human Binding, 29 January 2026.





Author: Editor

Share This Post On

Submit a Comment

Your email address will not be published. Required fields are marked *