In just under three hours, a Hacker News submission about DraftKings' targeting system amassed 528 points and 377 comments. The technical detail driving that reaction was narrower than the headline: a machine learning system reportedly looked for bettors likely to respond to a promotion and likely to lose. When those two predictions meet, a forecast about harm can become a marketing audience.
The Electronic Frontier Foundation's account, published September 24 and based on a New York Times investigation, says DraftKings trained a model on customers' betting records to identify that overlap. DraftKings told the Times that its promotions are directed toward people who spend substantial time on the app. It rejected the suggestion that its marketing is unfair or improperly targets customers, according to a separate ProPublica investigation that cites the same reporting.
The AI label hides a familiar prediction problem
Nothing in the available reporting indicates that a chatbot or generative model decided whom to contact. EFF describes machine learning trained on betting records. DraftKings' own 2025 annual report says the company uses data science and machine learning across its products to improve conversion and monetization. The filing also says its fantasy-sports home screen is customized from a customer's past entry history.
That points to a conventional predictive system: historical behavior goes in, and a likelihood comes out. The exact model, its features and the thresholds and training labels have not been disclosed in the sources reviewed here. Calling it AI can make the system sound more mysterious than the documented business purpose. DraftKings' filing says it spends on personalized cross-product offers to retain and monetize paying users, and that data science supports its marketing operations.
DraftKings also warns investors that AI can produce inaccurate or misleading results and that systems with less human oversight may cause unauthorized or harmful outcomes. Its filing discusses data-privacy violations and legal liability among the possible consequences. Those are broad corporate risk disclosures, yet they show the company already treats AI governance as an operational issue that reaches beyond model performance.
The hard question sits downstream of the prediction. A model might estimate that a customer will open an offer or continue betting after making another deposit. The product still needs a rule about whether that person is eligible to receive the offer. EFF's report says the same predicted loss that makes the customer valuable to the sportsbook may also indicate vulnerability. Model accuracy cannot settle that policy choice.
Safety and marketing can read the same event stream
A ten-week ProPublica test shows how the collision can look from one account. Reporter Jake Pearson deliberately copied behaviors associated with problem gambling while using an account in his own name and disclosing that he was a journalist. The day after he lost nearly $1,800 while chasing losses, DraftKings invited him to audition for its VIP program.
Later in the experiment, the app sent Pearson to its responsible-gaming center after his losses approached $4,500 in 24 hours. He set a two-hour daily limit and a $100 deposit limit. ProPublica reports that DraftKings sent the first of four promotional alerts about half an hour later. In another episode, a responsible-gaming prompt was followed hours later by an offer promoting repeated live microbets. One account cannot measure a platform-wide rate. It does expose a specific integration failure worth testing: a safety action did not silence the promotion channel.
DraftKings disputed the broader interpretation. Its chief responsible gaming officer told ProPublica that the company may close an account when enough warning signs appear, although DraftKings did not provide a count of such closures. The company also said responsible gaming is embedded across the business and that more than 5,000 employees receive annual training. When asked about the sequence on Pearson's account, the executive said the company would review it and cautioned against drawing broad conclusions from a single case.
For engineers, the useful unit of scrutiny is the entire decision path. A responsible-gaming classifier can work as designed while a campaign service continues to rank the same person highly. An account limit can be stored correctly while a notification job reads an older audience snapshot. ProPublica's observed half-hour gap does not establish which failure occurred. It gives auditors a reproducible outcome to check: after a user activates a limit, promotional messages should stop under a defined rule and stay stopped across every channel.
First-party data can still create a surveillance problem
EFF says the reported targeting relied on first-party data, meaning information DraftKings collected from its own customers instead of records bought from a broker. That distinction matters because many privacy controls focus on cross-site tracking or the sale of data. Neither would prevent a betting service from learning from its own ledger of wagers, deposits, losses and promotion responses.
DraftKings describes the breadth of that internal view in its annual report. Its products share account-management technology, one identity system and, in many cases, a common wallet. The company says this setup lets users move across its fantasy sports, sportsbook and online-casino products without separate credentials or payment methods. It also creates a connected behavioral record that can support both recommendations and risk detection.
The word first-party can sound reassuring because no outside data broker is required. Here it describes the route by which the data was collected, not the sensitivity of the inference made from it. EFF argues that limits aimed only at third-party sharing would leave this kind of targeting intact. Its preferred policy is a ban on behavioral advertising, a position broader than the evidence needed to assess DraftKings' reported model. The narrower technical finding is already consequential: a company can build a high-risk marketing segment entirely inside its own product.
The conflict was visible before this report
DraftKings' annual report records a pending lawsuit brought by the City of Baltimore in April 2025. The city alleges that DraftKings used data to identify users with a gambling disorder and then directed promotions at them. It also alleges misleading offers, urgent messages and a VIP program that exploited vulnerable users. These are allegations, not findings. DraftKings says it intends to defend the case vigorously, and its filing said an appeal over the venue remained pending when the report was filed.
The same filing calls responsible gaming fundamental to DraftKings' mission and says the company gives customers tools and resources to support responsible play. Elsewhere, it warns investors that poorly managed AI could bring reputational harm or legal liability. Those statements frame the control problem in the company's own terms. Conversion systems and consumer-protection systems cannot be assessed as separate products when both act on the same account.
An effective review would trace signals associated with loss chasing and self-imposed limits to every service allowed to consume them. Promotion eligibility needs an exclusion rule that outranks predicted response. That rule must survive cached audiences, notification schedules, product transfers and delayed jobs. The public sources do not establish whether DraftKings has those controls or how often they intervene, which is precisely the missing evidence regulators and auditors need.
What happens next should be measurable. Watch the Baltimore case for discovery about data flows and targeting criteria, and watch DraftKings for a public account of how responsible-gaming events suppress promotions. A model card alone would not answer the issue raised by the 528-point discussion. The decisive test is what the rest of the system does after the model identifies a profitable customer who may also be in trouble.