Guide · Betting, Gambling & Prediction MarketsUpdated August 17, 2026
The law treats a betting operator as a financial institution. Most request-response functions are not built to that standard. This page covers what arrives, how strong programs verify and produce, and what regulators check.
A sportsbook, an online casino, and a prediction market hold the same data a bank holds: verified identity, payment instruments, transaction history, and a geolocation record for every customer. US law treats a betting operator as a financial institution under the Bank Secrecy Act. UK, EU, and Australian law treats it as an obliged entity. Banks built their response functions over decades. Betting operators have had about five years.
No betting operator publishes its request numbers. Comparable account-based money businesses do. Kraken reported 4,923 government requests in 2023 and 6,826 in 2024, a 38.6 percent increase. Coinbase has received more than ten thousand requests a year since 2022. Casinos and card clubs filed about 77,000 suspicious activity reports in fiscal 2025.
The growth follows the market. Legal US sports betting expanded from a handful of states to 39 plus DC, and licensed operations in the UK, Europe, and Australia grew over the same period.
At many operators, one person handles all of this volume. The intake address is often that person's own inbox, because the first subpoena arrived there. The function sits in legal at some companies, and in compliance or financial crime at others. A single-person function has no coverage for vacation, sickness, or departure. The deadlines continue through all three.
Request volume in this vertical divides into two different jobs. Which job you have determines how to build the function.
Most volume at a US-licensed operator is compulsory process: subpoenas, search warrants, and grand jury demands. Each carries a deadline set by a court or an agency. The job is to process every request before its deadline.
At an internationally licensed group, a large share of volume arrives with no legal compulsion: a foreign police force asking without citing an authority, a financial intelligence unit requesting broadly, an agency asking for data it has no power to demand. The job is to decide, case by case, whether to disclose. A voluntary disclosure to the wrong requester creates liability to your own customer.
Identify your mix before you design intake, staffing, or policy. A due-date policy written for subpoenas does not help an MLRO decide whether to answer a request with no legal force.
Forged legal process is cheap, good, and documented at the federal level. In November 2024 the FBI warned that criminals were using compromised US and foreign government email accounts to send fraudulent emergency data requests to US companies. Betting operators are a specific target because they house so much data: verified identity, Social Security number, bank accounts, home address, device data, and a complete financial-behavioral history sit in a single production. One fake subpoena returns a full doxxing kit. The threat comes in two forms:
The forged document
FORGERYAI can draft a convincing subpoena in minutes from public court formats and an operator's own published submission instructions.
The compromised real account
TAKEOVERA real account on a real government or police domain, sold by country and agency. The document and the domain both pass review. The sender is not the account owner.
Manual verification fails against the second form. The phone number printed on a forged subpoena connects to the forger. A compromised .gov account passes domain checks, document checks, and callback checks.
The alternative is to verify requesters through a network, before first contact. Kodex verifies 15,000+ government agencies and 150,000+ verified investigators across 180+ countries. A requester's identity is established once and monitored across every company on the network.
For the verification procedure, see how to verify a law enforcement request. For the forged-EDR threat, see fraudulent emergency data requests.
Subpoenas, warrants, and court orders are not the full list. Operators also receive these request types:
This is an AML vertical first, and the request types reflect that.
FinCEN publishes sports-betting-specific laundering typologies. The crimes behind most requests are the ones an AML program already monitors: laundering, fraud, identity theft, account takeover, and proceeds of crime.
Verification establishes that the requester is real. Production is a separate question: does this document compel this data from this entity? Five rules cover most cases:
State gaming commission AML examinations now test whether the program works. Examiners sample case files and check for a complete, timestamped record from intake to resolution. A program that keeps this record as part of normal work answers the examiner in an afternoon.
The same shift is visible in every jurisdiction:
FinCEN
The effectiveness framework requires operators to show the program works, and FinCEN has published sports-betting-specific laundering typologies.
UK Gambling Commission
Enforcement actions continue to accumulate, and obliged-entity duties make request handling part of the AML program.
AUSTRAC
Multiple major operators are in or exiting enforcement simultaneously, with AML program failures at the center of each action.
Nevada Reg 5
Recent amendments assign AML responsibility to a named, personally licensed individual. Vendors in this workflow may also need state gaming-vendor licenses, in particular in New Jersey and Pennsylvania.
The EU e-Evidence Regulation, with its 8-hour emergency deadlines, is also cited to this industry. A US-only operator with no EU offering is out of scope. For EU-facing operators, the regulation's financial-services carve-out does not clearly cover gambling, and adjacent services such as chat and community features are the most likely route into scope. Confirm scope with counsel.
Is a sportsbook or online casino legally required to respond to law enforcement requests?
Yes. The legal basis differs by geography. In the US, licensed operators are casinos and money services businesses under the Bank Secrecy Act, with SAR filing obligations and standing distribution lists such as FinCEN 314(a). In the UK, EU, and Australia, licensed operators are obliged entities under their AML frameworks. Compulsory legal process, such as a subpoena or warrant, carries its own response deadline set by the issuing court or agency.
What's the difference between a compulsory request and a voluntary one?
A compulsory request, such as a subpoena, warrant, or grand jury demand, has legal force and a deadline. A voluntary request does not. The agency is asking, not compelling. At internationally licensed groups, a meaningful share of volume is voluntary. Producing data against an unauthorized voluntary request creates liability to the customer whose data was disclosed.
Does EU e-Evidence apply to gambling operators?
For a US-only operator with no EU offering, no. For EU-facing operators, possibly. The regulation's financial-services carve-out does not clearly cover gambling, and adjacent services such as chat and community features are the most likely route into scope. Confirm with counsel.
How do you verify that a law enforcement request is genuine?
Document inspection and phone callbacks do not catch a compromised government email account, because the domain and the document both pass review. The reliable method is to verify requester identity against a network where agencies and investigators are known before first contact and monitored across every company on the network.
How fast should a betting operator respond to a subpoena?
Set a deadline the team can meet on a day when several subpoenas arrive at once, state it consistently to requesting agencies, and do not miss it. A deliberate, consistent deadline matters more than a short one.
Programs in this vertical sit along a common line. At the early end, the intake address is one person, the tracker is a spreadsheet, and verification is a web search. In the middle, there is a shared alias, written procedures, and a fixed default deadline. This handles routine volume and little fraud. The strongest programs combine verified intake, network-based requester verification, self-set deadlines that hold for months, entity-aware production, and coverage that does not depend on one person. Most operators sit earlier on this line than they estimate, and moving up does not require a rebuild. The full handbook maps the line, with the regulatory reference behind every claim on this page.
Kodex is the network for handling legal requests: requesters are verified before a human reads the request, requests are structured and routed to the correct entity, and responses are delivered with a complete audit trail. To see it against your own volume, request a demo and bring your last quarter's numbers.
New to this area? Start with the complete guide to law enforcement data request management.
We use cookies to keep the site running, understand how it's used, and measure our marketing. You choose what to allow — read more in our Privacy Policy.