Contents
Published: September 2026 · By John Suit, Salience Cyber
A New York Times investigation published September 19 has reopened a question most organizations have been putting off: who is watching what our AI actually does?
According to the Times, DraftKings built a machine-learning model in 2023 that scored online casino customers by how much they were expected to lose after getting a free bet or bonus. The paper based its reporting on internal memos, presentations, betting records and interviews with more than 40 former employees. The model reportedly weighed signals like how often someone played, their daily account balances, and how much of what they wagered they lost. Staff called the output an “elasticity” score. The higher someone’s score, the more promotions came their way.
The outcome is what gives many readers pause. Coverage of the investigation says roughly $400 million in bonus bets and perks went to the highest scorers in 2025. Former employees also told the Times that a separate project to flag customers at risk of gambling harm was shelved. The data and the infrastructure could have worked in both directions, but only one direction reportedly made it to production.
DraftKings disputes the characterization. It points to its responsible-gaming tools, including cooling-off periods and self-exclusion, and says it monitors more than two dozen indicators of risky behavior.
This Isn’t Just a Gambling Story
It’s easy to read this as a problem specific to sportsbooks. It isn’t. The underlying pattern shows up anywhere AI meets sensitive data:
Models optimize whatever you point them at. A model trained to maximize revenue per promotional dollar will learn which behaviors predict revenue — whether or not anyone intended it to. If compulsive patterns like chasing losses or escalating deposits happen to predict revenue, the model will find them. Nobody has to write “target vulnerable people” into the code for that to be the result.
The most consequential AI decisions are often invisible. The Times story came to light through former employees, not through any external audit or monitoring. Inside most organizations, AI activity is even less visible than that. Employees paste data into GenAI tools. Agents run workflows with access to internal systems. Models get tested, tuned and deployed with little centralized oversight.
Regulators are catching up. The proposed SAFE Bet Act from Sen. Richard Blumenthal and Rep. Paul Tonko would bar sportsbooks from using AI to track individual betting habits and serve personalized offers. Similar scrutiny is building across finance, healthcare, insurance and consumer tech. “We didn’t know what our AI was doing” will not hold up as a defense.
The Real Risk: AI Activity Nobody Can See
Most security programs were built for a world of users, files, and network traffic. AI adds a new layer on top of that:
- Shadow AI: employees using unapproved AI tools and feeding them customer data, source code or strategy documents
- Prompt injection: attackers hiding instructions in content that hijack an AI tool or agent
- Agentic exploitation: autonomous AI workflows being manipulated into taking actions no human approved
- Data exposure: sensitive information reaching models and services outside your control
Every one of these risks comes down to the same root cause: a lack of visibility. You can’t govern, audit, or defend AI activity you can’t see or understand. Organizations that wait for a whistleblower, a breach or a headline to learn how AI is being used across their environment are already behind.
Security That Doesn’t Get in the Way
The traditional answer to new risk is more friction: block the tools, lock down the endpoints, and slow everyone down. Teams then route around the controls, and the risk moves somewhere even harder to see.
There’s a better approach. Oversight of AI should happen where people actually use AI, and it should be light enough that they don’t notice it.
Take Control of AI Activity Without Slowing Your Team Down
Salience Cyber watches AI activity in the browser and on the host, and can stop it in either. It uses an AI-aware browser extension and a lightweight system sensor. The sensor runs entirely in userspace, with no kernel drivers, no root privileges, and no LLM in the path.
With Salience Cyber, you can:
- See every AI tool, GenAI session and agentic workflow in use across your organization, including shadow AI
- Understand what data is flowing into AI and what actions AI agents are taking
- Stop prompt injection, AI-generated malware and agent exploitation at runtime, before damage is done
It does all of this without disrupting the user’s experience. Your teams keep using the AI tools that make them productive, and your security and compliance teams get the oversight they need.
The DraftKings story is a reminder that AI’s impact comes down to what it’s allowed to do and who is watching. Make sure that’s you.