Regulated Before There Were Rules: Lessons from Launching Online Gaming for the AI Companies Facing Regulators Now
What launching regulated U.S. online gaming taught me about operating when the rules are being written in real time and what AI companies facing regulators in 2026 should learn from an industry that already lived this.


In 2014, I sat in rooms where the people regulating us were, at the same time, writing the rules they would regulate us with.
I was CISO for PokerStars and Resorts Casino Hotel during the launch and maturation of regulated online gaming in the United States, one of the first times a state had tried to take an industry that existed offshore, in legal gray zones, and bring it onshore under formal oversight. New Jersey had passed a law. What it didn't have, and couldn't have, was a mature rulebook. The technology was new to the regulators. The risks were new to everyone. The precedents didn't exist because we were the precedent.
That experience has been sitting quietly on my resume for a decade. In 2026, it's suddenly the most relevant thing on it, because AI companies are now living the exact same situation, and most of them are handling it the way gaming's worst actors did rather than the way its survivors did.
The parallels are almost embarrassingly direct. A technology that grew up faster than oversight. Regulators asserting jurisdiction while still learning what the technology is. A patchwork of state rules, federal ambiguity, and international frameworks phasing in on different timelines. Enterprise customers and the public demanding assurances that no settled standard yet defines. And companies trying to decide, with the market moving underneath them, how much governance to build before anyone forces them to.
Online gaming already ran this experiment. Here is what it taught, at the level of pattern.
When the rules don't exist, the regulator's confidence is the license
The first thing you learn operating in an unwritten category is that "compliance" is not available to you. You cannot comply with rules that haven't been finished. There is no checklist to complete, no certification to earn, no safe harbor to stand in. What determines whether you get to operate, and keep operating, is something much softer and much harder: whether the people overseeing you believe your organization is trying to be governable.
That belief is built or destroyed in every interaction. It's built when your answers are complete on the first ask. It's built when your documentation reflects how things actually work rather than how the policy says they should. It's built when you flag a problem before they find it. It's destroyed, often permanently, the first time they catch a gap between what you said and what was true.
In gaming, we understood that regulatory confidence was the actual asset. The controls, the reporting, the audits — those were the evidence, but confidence was the product. Companies that treated the regulator as an obstacle to be managed got managed right back, with conditions, delays, and scrutiny that compounded. Companies that treated the regulator's confidence as a first-class engineering requirement got something priceless in a new category: the benefit of the doubt when something inevitably went wrong.
AI companies should hear this precisely: while the EU AI Act phases in, while U.S. states pass conflicting statutes, while agencies stretch existing authority over new technology, there is no compliance posture that protects you — because the rules will keep moving for years. What protects you is being the company regulators believe is governable. That is buildable today, with no rulebook required, and almost no one is deliberately building it.
Regulators learn your technology from you, so teaching honestly is the job
Here's what surprised me most in those rooms: the regulators knew they didn't fully understand the technology, and they were watching closely to see who would help them understand it honestly.
Online gaming oversight required regulators to get smart, fast, about things they had never overseen — geolocation, identity verification, payment flows, platform security, game integrity, the mechanics of how a digital product could be manipulated and how you'd know. They learned it primarily from the operators. Which meant every operator faced a choice in every interaction: educate candidly, including about your own risks and limitations, or manage the narrative and hope the knowledge gap works in your favor.
The candid teachers ended up shaping the category. When you honestly explain how your technology works, where it can fail, and what controls actually address which risks, the rules that eventually get written reflect operational reality, they're rules you can live with, because you helped the regulator understand what's real. When you obfuscate, the rules get written from fear and from the loudest headline, and they land on you anyway, in a form nobody can operate under.
AI companies are making this exact choice right now, mostly without realizing it's a choice. Regulators are forming their mental model of how AI systems work, fail, and can be controlled, from hearings, from incidents, from vendors, and from the companies in front of them. The companies explaining model risk honestly, admitting what evaluation can and can't detect, and being specific about their own limitations are writing the future rulebook in their favor. The companies treating every regulatory interaction as a PR exercise are outsourcing rule-writing to the next headline. In an unwritten category, candor is not a virtue. It's a strategy, arguably the dominant one.
You are regulated for the sins of your category, not your conduct
Online gaming did not arrive at regulators as a blank slate. It arrived carrying decades of baggage: offshore operators, gray-market history, money-laundering fears, addiction concerns, and an ambient public assumption that the industry was fundamentally untrustworthy. It did not matter how clean your specific operation was. The skepticism in the room was earned by the category, and every company paid the category's bill.
Once you internalize that, your posture changes. You stop arguing that the skepticism is unfair, it is unfair, and it's also the operating environment, and you start designing for it. In gaming, that meant building controls and transparency that anticipated the accusation before it was made: prove the games aren't rigged, prove minors can't play, prove the money is clean, prove the platform is secure. You built the answer to your category's reputation, not to your own conduct.
AI in 2026 carries its own category bill: high-profile failures, hallucination headlines, bias findings, safety debates, deepfakes, and a public narrative that oscillates between magic and menace. When an AI company sits down with a regulator, an enterprise customer, or a Senate staffer, it inherits all of it. The productive response isn't defensiveness about your own excellent conduct. It's showing up with the proof that the category's known failure modes are specifically, demonstrably addressed in your systems, before anyone asks. The companies that treat category skepticism as a design input, not an insult, are the ones that convert it into advantage, because they're the ones with answers ready while competitors are still objecting to the question.
Volunteer the higher standard, the ratchet only turns one way
A pattern you learn quickly in emerging regulation: rules ratchet. They get stricter over time, almost never looser, and each incident anywhere in the category tightens them for everyone. Which produces a counterintuitive strategy , build beyond today's requirements on purpose, because today's voluntary standard is tomorrow's floor, and you'd rather already be standing on it than climbing to it under deadline.
In gaming, the operators who built identity, geolocation, and security controls beyond the minimum had two structural advantages. When rules tightened, and they always tightened, the compliant-by-default operators absorbed the change as paperwork while minimum-builders absorbed it as re-engineering. And in every discussion about what future rules should require, the above-minimum operators could advocate for standards they already met, which is a rather comfortable negotiating position.
There's a trap here worth naming, though: volunteering standards is not the same as volunteering theater. Regulators in a learning phase develop a sharp nose for controls that exist to be shown versus controls that exist to work. One demonstrably real control, with evidence, with history, with a named owner, buys more confidence than a binder of aspirational ones. AI companies drafting "responsible AI principles" should sit with that distinction. Principles are the binder. What ratchet-proofs you is operational: evaluation regimes that run whether or not anyone's watching, incident processes that have actually fired, model documentation a third party could verify. Build the thing, not the deck about the thing.
Speed versus readiness is a false binary — readiness was the speed
Every conversation about governance in a fast-moving market eventually collides with the same objection: we can't slow down for this. It was gaming's constant refrain in 2014, and it's AI's refrain today, usually delivered as though the trade-off were self-evident.
Our experience was the opposite. In a regulated launch, readiness was the speed. The gate to market wasn't engineering velocity, it was regulatory sign-off, and sign-off moved at the speed of confidence. Operators who built readiness in from the start moved through approvals while operators who bolted it on afterward sat in remediation cycles, answering the same questions repeatedly because their first answers hadn't held up. The "slow" companies shipped first.
The same inversion is arriving in AI, just through different gates. The gate might be an enterprise customer's AI risk review, a financial services client's model-governance requirement, a public-sector procurement, an EU market entry, or an S-1 diligence process asking pointed questions about AI liability. In each case, the company with demonstrable governance clears the gate in weeks; the company without it enters a remediation loop measured in quarters, while its "slower" competitor takes the contract. Governance debt behaves exactly like technical debt: invisible while you accumulate it, then suddenly the only thing anyone will talk about, at the worst possible moment.
Don't build a governance island, one model for old risk and new
One structural detail from those years turned out to matter more than I understood at the time. I was CISO across both the digital platform and the physical casino operation, online gaming risk and decades-old risks like cash handling, physical security, and hospitality operations, in one governance model. Not a shiny new digital risk framework on the side, quietly disconnected from how the rest of the enterprise was governed.
That unification was the point. Regulators and boards don't experience "digital risk" and "traditional risk" as separate things; they experience one company that is either governed or isn't. When the new risk domain lives inside the same accountability structure as everything else, same escalation paths, same reporting, same named ownership — every existing trust relationship the organization has transfers to the new domain. When it lives on an island, the island has to earn every unit of trust from scratch, and it usually reports to no one in particular.
This is, quietly, the biggest structural mistake I see in AI governance right now: the AI ethics board, the responsible AI council, the standalone framework — all disconnected from enterprise risk management, security, and the board's existing oversight machinery. It feels like taking AI seriously. Functionally, it's an island. When the regulator or the diligence team arrives, they find AI risk governed by a committee with no budget, no enforcement path, and no connection to the people who own risk everywhere else in the company. Fold AI risk into the governance that already works. Give it a named owner inside the existing structure. Novel risk does not require novel governance, it requires the boring, connected kind.
What the survivors knew
Regulated U.S. online gaming worked. The category that arrived carrying maximum skepticism became a functioning, trusted, multi-state industry, not because the rules were perfect, but because enough operators understood that in an unwritten category, trust is the infrastructure everything else runs on.
The survivors' playbook, compressed: treat regulatory confidence as the product, not a tax. Teach honestly, because whoever educates the regulator shapes the rules. Design for your category's reputation, not your own self-image. Build past the minimum before the ratchet turns. Recognize that readiness is velocity wherever a skeptical gatekeeper stands between you and revenue. And govern the new risk inside the structure that already governs everything else.
None of that required knowing the final rules. All of it was available before the rules existed. That's the actual lesson for AI companies in 2026: the uncertainty you're pointing at as the reason to wait is the same uncertainty gaming faced, and waiting was the one strategy that reliably failed.
The rules for AI will take years to settle. The question of whether your company is governable is being answered now, in every regulator interaction, every enterprise security review, every incident response, whether you're answering it deliberately or by default.
I'd suggest answering it deliberately. I've seen what happens to the companies that don't get a vote in their own rulebook.
Tyson Martin is a trust, security, and AI governance executive who served as CISO during the launch of regulated U.S. online gaming and has since led through public-company crisis recovery and complex ownership transitions. He advises boards and executive teams at companies where trust is priced by investors, regulators, and enterprise buyers.
Tyson Martin is the executive public and pre-IPO companies in financial services, AI/data, SaaS, and cloud hire to make trust a measurable asset, one accountable answer to Is it secure? Is it resilient? Is the AI governed?
© 2026. All rights reserved.
Navigation
Free Resources
Contact


Stay ahead of your next board agenda
Sign up for Reports & Learnings From the Boardroom. Plain-English AI and cyber governance insights, biweekly. No pitch.
No spam. Unsubscribe anytime. · Or download the Director's AI Question Pack — 25 questions free
