AI that never leaves the building
Zero. That is how much sensitive player and operational data leaves the property under the approach eConnect president and CEO Henry Valentino described in a recent video interview with CDC Gaming: AI models running on-premises, behind the casino’s own firewall, with nothing shipped off to a vendor’s cloud for processing. On device AI casinos, to use the industry shorthand, do the thinking locally. The cameras, the loyalty database, the table-level data all stay where they already are.
That sounds like a technical footnote. It isn’t. Where the inference happens decides who holds the data, who is liable when it leaks, and which regulator gets to ask questions. For a sector that already operates under surveillance mandates, anti-money-laundering reporting and a growing stack of state biometric privacy laws, “the model runs here, not there” is one of the more consequential architecture choices a supplier can make.
Why eConnect rebuilt instead of bolting AI on
The detail worth noting from the interview is that eConnect didn’t add AI features to its existing platform. It rebuilt the platform around AI from the ground up. Valentino’s framing is that retrofitting intelligence onto software designed for a pre-AI world produces something slower and more awkward than starting over.
Anyone who has watched enterprise software try to graft machine learning onto a decade-old codebase will recognise the problem. Legacy surveillance and player-tracking systems were built to record, store and let a human search. AI workloads want the opposite: continuous streams, structured events, GPUs sitting next to the data, and a schema that assumes a model is reading every frame rather than a supervisor scrubbing through footage after an incident.
There’s a practical reason the processing stays local too. A mid-size US casino floor runs a lot of cameras, often well into the hundreds, all recording continuously. Pushing that volume of high-resolution video to a cloud region, paying egress on it, and waiting for a round trip before a surveillance operator gets an alert is a poor fit for anything that needs to happen in the next ten seconds. Edge AI gaming deployments exist partly for privacy and partly because physics and bandwidth bills don’t negotiate.
On device AI casinos versus the cloud: the real trade-offs
Neither model is strictly better. They fail in different ways, and operators choose based on what they’re more afraid of.
| Factor | On-premise / edge AI | Cloud AI |
|---|---|---|
| Where player data sits | Inside the property, behind the operator’s firewall | On vendor or hyperscaler infrastructure |
| Latency for live alerts | Local, no round trip | Depends on connectivity and region |
| Cost shape | Upfront hardware, predictable running cost | Low upfront, usage and egress charges scale with volume |
| Breach exposure | Concentrated at the property | Third-party vendor becomes part of the attack surface |
| Model updates | Pushed per site, slower to roll out | Continuous, centrally managed |
| Regulatory story | Simpler: data never crossed a border or a contract | Requires vendor due diligence and data-processing terms |
The cloud wins on convenience and on how fast a supplier can improve its models. On-premise wins on the question a tribal gaming commission or a state regulator is most likely to ask: who else has copies of this?
The uncarded player problem, and why it’s the commercial driver
Valentino’s third point in the interview is the one with money attached. AI, he argues, could help casinos get more out of data they already collect, including identifying uncarded players and improving day-to-day operational decisions.
Uncarded play is a long-standing blind spot. A player who never signs up for the loyalty program, or who plays without inserting the card, is largely invisible to the systems that tell a marketing department who matters. Operators have always known a meaningful share of floor activity falls into that bucket. They have never had a cheap way to quantify it. Video analytics running locally against table and slot footage changes the economics of answering that question.
Read that honestly and you get the tension at the centre of this trend. The privacy argument for keeping AI on-site is genuine, and so is the fact that the same AI is being pointed at people who deliberately chose not to identify themselves. Keeping the processing in-house limits who can see the output. It does not reduce how much is being observed. Both things are true, and the industry coverage tends to mention only the first.
Where casino data privacy law actually bites
US casinos are not lightly regulated data handlers. Under the Bank Secrecy Act, casinos above a revenue threshold are treated as financial institutions and must file currency transaction reports for cash in or out exceeding $10,000 in a gaming day, plus suspicious activity reports. That means they already hold identity documents, transaction histories and surveillance footage tied to named individuals.
Layer biometrics on top and the exposure grows. Illinois’ Biometric Information Privacy Act requires written consent before collecting face or other biometric identifiers and gives individuals a private right of action with damages set per violation, which is why BIPA litigation has hit retailers, employers and entertainment venues hard. Texas and Washington have their own biometric statutes, and several state comprehensive privacy laws now classify biometric data as sensitive, requiring opt-in consent.
Against that backdrop, “the data never left our firewall” is a materially easier sentence to say to a regulator, an insurer or a plaintiff’s lawyer than “our vendor processes it in a shared cloud environment.” It doesn’t eliminate liability. Consent requirements apply regardless of where the GPU sits. But it removes a whole class of third-party and cross-border questions from the file.
What it means for players on the floor
Three things follow from this, and they’re worth knowing whether you play in Las Vegas, at a tribal property or online.
- On-premise AI narrows the blast radius, not the lens. Fewer parties hold your data, which genuinely reduces breach risk. The amount being analysed about your play is going up either way.
- Not carding your play no longer means not being counted. If analytics can recognise returning faces or patterns at a table, anonymity on the floor is thinner than it used to be, with or without a loyalty card.
- The same technology enforces player protection. Local facial matching is how properties check arrivals against self-exclusion lists. Keeping that list on site, rather than in a third-party cloud, is the version most state and tribal regulators prefer, and it’s a reasonable argument for the approach.
Among current gaming technology trends, this one is quiet and structural rather than flashy. Nobody markets “AI without cloud” to players. But the choice to rebuild for local inference, made by a supplier whose products sit in surveillance rooms, is a signal about where the industry thinks player data security risk now lives: not in the model, in the transit.
If you want to know what a specific property holds on you, ask. Most US operators publish a privacy notice covering loyalty data, surveillance footage and retention periods, and in states with comprehensive privacy laws you can request access or deletion of some of it. And if tracking of your own play is a concern because the play itself has stopped being fun, self-exclusion and deposit limit tools exist at every licensed operator, and the National Problem Gambling Helpline, operated by the National Council on Problem Gambling, is reachable at 1-800-MY-RESET (previously 1-800-522-4700). The separate 1-800-GAMBLER network, run by a different organisation, is another route to help.
