Skip to content
InsightsInsight

AI moves fast, and so must the system around it

Machine flagging jumped in 2025 while total suspicious matches fell. That says something about sensitivity, and something harder about who carries the burden of proof.

GAMECHANGER360 Editorial6 min read
Flowing green signal waves on dark green

One number that explains the year

Suspicious matches flagged with the help of AI rose by about 56 per cent in 2025. Total suspicious matches fell by about 1 per cent. Sportradar published both figures in February 2026, drawn from monitoring across more than a million events in 70 sports.

Read together, they support a narrow conclusion. Manipulation did not increase. Detection became more sensitive. Models are catching subtler patterns and smaller markets that a human analyst working through a shortlist would have passed over.

That is a genuine gain, and it arrives with a bill attached. Every extra flag is a case that someone has to open, assess, and either escalate or close. A federation whose inbound signals double, while nothing else about it changes, does not become better protected. It becomes slower, and it starts closing cases for reasons of capacity rather than reasons of evidence. Sensitivity is only worth buying if the system behind it can absorb what the sensitivity produces.

Two technologies, one word

Most conversations about AI in integrity work collapse two different technologies into a single term. They answer different questions and they fail in different ways.

Anomaly detection models how a betting market should behave and flags departures from that. Sportradar's UFDS AI compares in-play odds against model-based forecasts built on more than twenty years of historical data. The output is a statement about an event: this market moved in a way the model did not expect. It says nothing about who caused the movement, or whether anyone did.

Identity matching answers a question about people. Is someone who is barred from betting on a competition holding an account with an operator that takes bets on it? IC360's ProhiBet cross-references anonymised identifiers against sportsbook customer records under encryption. In March 2026 the NCAA extended it to match officials, covering more than 220 referees and alternates assigned to its Division I basketball championships. There is no forecast and no probability here. It is a comparison of identities.

The distinction is not academic, because the two carry different weight and different duties. An anomaly is a place to start looking, and on its own it is almost never evidence of anything. A match on identity is closer to a fact, and it is also personal data about a named individual, which pulls in a body of law that anomaly scores on a market do not. An organisation that buys one and describes it to its board as the other ends up with misplaced confidence in one direction and unexamined legal exposure in the other.

What the law says as of today

Where an AI system profiles named individuals, and the output materially affects them, the EU AI Act's high-risk analysis applies, with its duties on documentation, data governance, logging and human oversight. Players, match officials, agents and bettors are all named individuals for this purpose.

The date moved this year. Regulation (EU) 2026/1744, the Digital Omnibus on AI, was published in the Official Journal on 24 July 2026 and entered into force three days later. It defers the obligations for stand-alone Annex III high-risk systems from 2 August 2026 to 2 December 2027, and Annex I systems from 2 August 2027 to 2 August 2028.

Two points about that deferral, both of which get lost in summaries. First, it moved a deadline and not a standard: the substantive requirements are unchanged, and the reason for the delay was that harmonised standards were not ready. Second, it did not move everything. The Article 50 transparency and AI content labelling duties stayed on 2 August 2026 and apply now. Obligations on general-purpose AI providers have applied since August 2025. The Article 5 prohibitions have applied since February 2025.

So an organisation building risk scoring on individuals has roughly fifteen months before the stand-alone high-risk duties apply to it, and no additional time at all on transparency.

The gap nobody has filled

Here is the part that should shape procurement. As of today, no sports body has published guidance specific to the use of AI in competition-manipulation detection. Not the Council of Europe, not the bodies working under the Macolin Convention, not IBIA, not the ITIA, not the monitoring suppliers themselves. The applicable framework is general: the EU AI Act, the GDPR, and the Council of Europe Framework Convention on Artificial Intelligence and Human Rights, Democracy and the Rule of Law. The EU has published a study on AI in the sport sector and a Council working document dated 8 April 2026, both preparatory rather than binding.

The consequence is that there is no safe harbour. No integrity unit can tell a disciplinary panel, an appeal body or a data protection regulator that its model was used in line with sector guidance, because there is no sector guidance to be in line with. The burden of showing that an AI-assisted decision was sound sits entirely with the organisation that made it.

In practice that means being able to reconstruct, after the fact and in front of someone hostile, what the system was given, what it returned, which configuration and which model version were running at the time, who read the output, and what they decided on the basis of it. Very few integrity functions can do that today for the tools already in use.

How we build for it

Five choices in the GAMECHANGER360 platform follow directly from the position above.

Model-agnostic by design. OpenAI and Google Gemini are integrated, and other models can be added. Model choice is configuration, set per product and per organisation, so it changes without the products changing. A customer is not tied to one provider's commercial terms, availability or compliance posture, and moving provider does not mean moving platform.

Retrieval over the organisation's own material, with citations. Answers are drawn from indexed documents that the organisation supplies: its regulations, codes, policy manuals, disciplinary decisions and case files. Each answer carries a citation back to the passage it used, so it can be checked rather than trusted. Where the material does not support an answer, the gap stays visible instead of being filled in.

Organisation-scoped knowledge. Indexes are separated by organisation. One federation's case material never surfaces in another's answers. Customer content is not used to train public models. Access runs through scoped keys, roles and audit logs, and retention and residency are configured per deployment under the UK and EU GDPR.

Human accountability for anything that affects a person. The system can raise a risk score, order a queue and retrieve the rule that applies. It does not sanction anyone, clear anyone or close a case. A named person decides, and the decision and its basis are recorded alongside the output that informed it.

Tested with practitioners before release. Configuration changes are tried in a test console against real queries, by the people who will have to defend the result, before learners and analysts meet them.

None of this makes a model more accurate. It makes the decisions around a model defensible, which is the part that gets tested.

What to ask before you buy

Three questions separate an integrity programme that can use AI from one that has merely bought some.

Which of the two technologies is this, and which question does it answer? If a supplier's answer covers both, ask again.

If we act on this output and the person affected appeals, what can we produce? Name the artefacts, not the intention.

Who is accountable for the decision, in a job title that already exists in our structure? If the answer is the tool, the answer is nobody.

December 2027 reads like a long way off. It is one budget cycle and one procurement round away, and the transparency duties are live already. The organisations that will be comfortable then are the ones building the record now.

Related reading

Integrity is infrastructure.

One system connecting education, reporting, monitoring and intelligence across sport.

The Integrity Brief

A monthly briefing on integrity risk, regulation and the systems protecting sport. No noise.

By subscribing you agree to our privacy policy. Unsubscribe at any time.