Skip to main content
All Watch files
ConfirmedPlayer protection·Watch Explained·Netherlands·Algorithmic safer-gambling monitoring

A regulator-backed gambling risk model is now open source - but it is not a compliance shield

Dutch researchers trained a player-risk model on two years of betting data from 13 casinos. The regulator says operators may use it, without guarantees.

Published 24 August 2026 · Updated 24 August 20267 minute read
By iGaming Atlas Editorial Team2 primary sourcesNext review 10 September 2026
Jump to a section

Evidence behind the story

What we checked

Primary documents

2 checked

Response record

Response included

Last source check

24 August 2026

Next scheduled review

10 September 2026

Why this matters

A transparent reference model can let regulators and researchers challenge closed operator systems, but its greatest value may be comparability rather than automation. Treating a score as a verdict would recreate the opacity it was designed to reduce.

Procedural status

Model released; adoption optional

The KSA hosts the open code and methodology and invites use as a supplementary tool. It has not converted the model into a safe harbour or universal intervention rule.

The current picture

  • University of Amsterdam researchers released an open-source model that scores risky online gambling behaviour.
  • The university says training used all wagers from players at 13 Dutch online casinos over two years, from 30 July 2023 to 30 July 2025.
  • The KSA says the model can supplement an operator's duty-of-care controls but provides no compliance guarantee.

Confirmed by the record

  • The model examines staking patterns, frequency and timing, and reactions to winning and losing streaks.
  • The work was funded from the KSA's Addiction Prevention Fund and developed by UvA researchers.
  • The KSA describes the code and methodology as public and available through its site.
  • The university says the model covers all forms of online gambling present in the dataset.

Not established

  • Open-source publication does not prove the model performs equally across every operator, market or player population.
  • A risk score is not a clinical diagnosis of gambling disorder.
  • Using the model does not establish that an operator has met every duty-of-care obligation.
  • The public announcements do not report a regulatory threshold at which a specific intervention becomes mandatory.

Sources for each key claim

Evidence map

Each core claim is paired with the document used to substantiate it. Open the record and check our reading.

1

The model scores player risk from actual behaviour such as staking, timing and reactions to streaks.

2

The university says the training data covered all wagers at 13 Dutch casinos over a two-year period.

3

The regulator says operator use offers no guarantee and can only supplement duty-of-care measures.

What changed, and when

  1. 30 July 2023

    Training window begins

    The university says the dataset starts on this date.

  2. 30 July 2025

    Training window ends

    Two years of wagering data from 13 Dutch online casinos are included.

  3. 18 August 2026

    Model released

    The KSA and University of Amsterdam announce public code and methodology.

The unusual part is not the machine learning

Online casinos already analyse deposits, stakes, session timing and losses. The unusual part of the Dutch project is that the resulting risk model is intended to be inspectable. The Kansspelautoriteit has published access to code and methodology developed by University of Amsterdam researchers, creating a reference outside a single operator's private system.

That changes who can ask meaningful questions. Researchers can examine assumptions, regulators can compare an operator's outputs with an independent baseline, and operators can test whether their controls miss patterns visible elsewhere. Open code does not guarantee good decisions, but it makes some decisions contestable.

What the model watches

The KSA says the algorithm considers how much and how often a person stakes, the frequency and timing of play - including repeated night-time sessions - and how behaviour changes after wins and losses. It converts those patterns into a risk score rather than waiting for one dramatic loss to trigger attention.

The University of Amsterdam says the training material comprised all wagers from all players at 13 Dutch online casinos between 30 July 2023 and 30 July 2025. That breadth is notable, but it should be described accurately: it is a large Dutch regulatory dataset, not proof of universal performance in every future market.

A score is not a diagnosis

Behavioural models estimate patterns associated with risk. They do not diagnose a clinical disorder, establish why a person played at night or determine on their own what intervention is proportionate. False positives can burden players who are not in difficulty; false negatives can leave genuine harm unseen.

The meaningful questions are therefore about validation: how often the model is right, what kinds of risk it misses, whether performance changes across games and player groups, and what human review follows a flag. None of those questions disappears because the code is public.

The regulator rejects the easy safe-harbour story

The KSA explicitly says operators can use the model to improve duty-of-care work, but that doing so gives them no guarantees. It may only form an additional part of their measures. That sentence prevents a powerful but false compliance claim: 'we ran the official model, therefore our intervention was adequate.'

Duty of care includes what an operator does with information, not only how it scores information. Contact timing, affordability context, product controls, limits, escalation and record-keeping can remain relevant even when the initial risk detection is technically sophisticated.

Why regulators may gain more than operators

Operators already possess detailed first-party data and often have proprietary models. A transparent reference gives supervisors a way to compare those systems without accepting their internal labels at face value. A large disagreement between scores can become the beginning of an audit question rather than an invisible modelling choice.

The UvA also says the project drew on collaboration with Spain's DGOJ. That cross-regulator lineage hints at a wider use: a common research baseline that can be tested across legal systems while local intervention rules remain distinct.

What would make the release truly consequential

The code release is the opening, not the conclusion. Independent replication, clear error metrics, documentation of data limitations and evidence about real-world interventions will determine whether the model improves outcomes. Version history will matter too, because player behaviour and products change.

Atlas will treat future claims in layers. The model is public; its training scope is described; its use is optional and supplementary. Whether it becomes a supervisory benchmark, changes enforcement or reduces harm is not yet established.

Transparency can still fail without governance

Open source allows inspection, but most affected players will not read code. Operators and regulators still need plain-language explanations of what data is used, what a flag means, who reviews it and how a person can challenge a mistaken inference.

That is the differentiating story here. The Netherlands has not produced an automated answer to gambling harm. It has produced a public tool that can make hidden scoring systems easier to question - provided institutions publish the evidence needed to question how it is applied.

Response record

The KSA's own limitation is prominent: model use is supplementary and provides operators no compliance guarantee.

Status: included

Sources checked