27.08.2026 · 9 min read
You asked which casino is best. ChatGPT went to the regulator

Ask ChatGPT which online casino is best and it goes looking for who licensed the domain before it answers, with no licensing question anywhere in the prompt.
That makes your regulator's website part of your commercial surface. Three things about your brand are now measurable, namely whether an assistant can confirm your licence at all, which fields of your register row it reads out, and what it falls back on when the check fails. In August I measured all three across 81 controlled runs, then went to see what the registers themselves hand back.
Where the regulator published data a machine could read, the reads were exact. 42 British register facts with no errors, ten New Jersey revenue figures right and in order.
Where online casino is prohibited, no brand was named at all across nine Australian runs. One answer was the single word "None."
Across sixteen licensing jurisdictions tested with a plain HTTP request, seven registers returned the full dataset.
What the 81 runs showed
Three markets, chosen because their law differs. New Jersey licenses online casino and sports betting, Great Britain licenses both nationally and publishes a downloadable register, and Australia licenses wagering while prohibiting online casino. Nine questions per market, each repeated three times, captured on 5 August 2026 in ChatGPT web using Temporary Chat, one prompt per fresh conversation, no follow-ups, with the exit IP verified before every block. Each run was scored on whether a register was reached, whether the exact record was found, whether the facts matched, the local-law overlay, the verdict direction and the recommendation. Claims about licensing jurisdictions were checked against our own register snapshots, and claims about the Australian and New Jersey regulators against those regulators' published documents.
Britain was the cleanest. Asked which online casinos are legal there, ChatGPT answered with a three-column table of brand, licensed operator and UKGC account number, which the question had not asked for. Twenty-one fields, all twenty-one correct against the register the same day. Across the British runs I checked 42 register facts and found no errors. It also cleared four sibling-licence traps. bet365 holds separate casino and sport licences and it took the gaming one both times, it picked the online Grosvenor licensee over the land-based company with an almost identical name, and it skipped a surrendered Ladbrokes account for the active one.
New Jersey was the same on a different surface. Asked for the ten best online casinos there, one run ranked them by regulator revenue and quoted ten figures, all correct and in the right order. Those brand-level numbers are not in the regulator's press release. They sit inside a monthly PDF filing, one page per licensee. On which casinos are legal in the state, two of three runs fetched the regulator's authorised-sites page and scored 35 of 35 and 25 of 26.
Australia prohibits online casino, and there the same question produced nothing. Across all nine runs on the three prohibited-product questions it named zero brands, and one entire answer to the legality question was the word "None." Those runs cited the Interactive Gambling Act 2001 and the prohibited game classes, so they read as legal findings. In three of three runs the model stated that an overseas licence from Curaçao or Malta does not make a casino legal in Australia, which is the assistant telling the player that an offshore licence carries no weight where they live.

Captured 5 August 2026 from a verified Perth exit IP.
The source a run used changed the answer, in both directions, in the same week. In Australia, asked for the ten best AFL betting sites, one run of three read the Northern Territory government's list of licensed operators, found two brands flagged as not currently trading, and removed them, saying it was doing so despite their appearance on some comparison websites. In New Jersey, one run of three leaned on a comparison site instead of the regulator and named four brands as currently legal that hold no authorisation there. Two had closed years earlier and one never held one.
Two things the model was reliably worse at. Dates were the weak field throughout, with a British enforcement penalty dated to the wrong month in one run of three and thirteen future-dated claims across five British cells. And on one offshore brand that publishes no certificate at all, two runs in two markets described an expiry taken from a certificate linked on its site, where the archived page carries no such link. Both of those verdicts were still cautious and still protective, which is a separate fact from the quality of the evidence behind them.
What changed on the second turn
The protocol allowed one prompt per conversation and no follow-ups, so this is a single capture from outside the 81 runs, and one example is not a rate.
I pushed back on the Australian refusal with five words. I didn't ask about legal.
The reply conceded the point and produced a ranked shortlist of four offshore casinos, each with a recommendation label, four more named as brands to avoid, and a final pick. Casino Guru Safety Index scores were quoted per brand. Position three carried a score of 7.1 and the answer's own note that Casino Guru records no licence and an undisclosed owner. It stayed ranked, stayed labelled best for pokies, and stayed in the final pick line.

Second turn, after the user replies that they did not ask about legality. Brand names redacted by me.
The sourcing changed with it. Six cold Australian runs on prohibited products cited only the regulator and government departments, with no affiliate sources. This second turn cited affiliate and review sites, and named that ecosystem while using it. So the behaviour in the 81 runs belongs to the opening answer, and anyone measuring AI visibility with cold single prompts is seeing the first turn only.
Whether regulators make a licence readable
All of the above depends on the regulator publishing something a machine can reach, so I tested that directly. On 1 August I fetched the register of every licensing jurisdiction we track and re-checked availability on 17 August. One plain request, follow the links, read what comes back, no JavaScript, no proof-of-work, no custom headers, no decryption. I make no claim about ChatGPT's own browsing, which I cannot see. The audit answers one question. What does a regulator hand to a client that is not a person with a browser.

Seven returned the full register. Six returned nothing to a plain request. Curaçao and Gibraltar answered in part, and Costa Rica has no register at all. These sixteen are licensing jurisdictions, which is a different list from the three markets probed above.
The Netherlands is my favourite illustration of the whole problem. The official register page at the regulator's own domain is an iframe wrapped around a different website, and the data lives on that other site's public API. Fetch the official URL and you get nothing back. The register page is not the register, which is a pattern I have now hit often enough to check for first.
A withheld bulk register does not mean a single-brand lookup fails, and several of these still answer one domain at a time. What it costs is visible in one run. Asked about a brand licensed in Anjouan, an answer named the register, said it could not retrieve the entry through the available search interface, and left the claim empty. That record exists in our snapshot. A valid licence went unreported, and the operator holding it paid for a credential that answer could not read.
For regulators, the useful finding is simpler. A register published as an affirmative list of who holds a licence made it possible for one answer to state that a brand was absent, naming the register and its edition date. A register built as a per-record lookup cannot support that sentence at all, because absence from a search box proves nothing.

A named register, a stated absence and an edition date.
Curaçao, and a correction
Look up a domain in the Curaçao certificate register and you get one of five results, and only one permits taking player deposits.

From our 1 August 2026 snapshot. 4,091 domains held a valid certificate. 1,041 sat in one of three non-licensed states, 92 of those applications with 70 rejected.
A resolving seal does not distinguish between those five states, and that distinction is the whole check.
Curaçao is also where I got something wrong. Earlier this month I watched ChatGPT report a licensee's status, licence number, company registration number and expiry, and I concluded it had invented the record. It had not. The regulator publishes dated editions of its licence registry as PDFs on a separate host, and I had not been reading them. Eleven claims in that answer, eleven correct, including the company number I had said appeared nowhere. It had also caught a real defect I had waved away, namely that the operator's own footer publishes its expiry as an issue date with the wrong year.
The rule I took from it is that a negative finding about a register means enumerating everything the regulator publishes, and not just querying the surface you already automate.
What an operator should check
Four things, none of which need tooling.
Pull your own record from your regulator's register and read every field it publishes about you.
Compare the domain list on that record against the domains you actually run, because assistants use that mapping and a live domain missing from your record has nothing behind it to find.
Ask an assistant about your brand three times in a fresh chat from each market you care about, because single runs can mislead you.
See what your regulator's register returns to something that is not a browser, which is the check that produced every finding above.
Scope. Three markets and 81 runs show how this behaves, not how often it happens across the market. This is one model and one interface, ChatGPT on the web, captured on 5 August 2026, with the register ground truth frozen on 1 and 2 August and availability re-checked on 17 August. The follow-up is a single out-of-protocol capture and is counted separately.
I run brand protection and AI visibility for iGaming operators at WhiteLobby, where we maintain our own snapshots of the official gambling registers.
Categories
Comments (0)
No comments yet. Be the first to share your thoughts!




