Today’s gaming companies are no longer simply building games. They are operating digital ecosystems that combine social experiences, developer communities, virtual economies and AI-enabled services at global scale. Gaming experienced massive growth during the pandemic as the world sought new ways to engage online. The growth has steadied, and the forces driving that growth are fundamentally changing how games are developed, distributed and monetized.
Gaming is becoming more connected, collaborative and reliant on technologies such as AI. Business models have evolved beyond one-time purchases to subscriptions, virtual economies and ongoing player engagement. Together, these shifts are creating new opportunities for growth while introducing greater operational, legal and regulatory complexity.
In this new era, executives must balance innovation with governance, particularly in areas such as online safety, age assurance, intellectual property and monetization. Gaming companies that integrate compliance into product development from the start, rather than treating it as an afterthought, will be better positioned to provide their players and developers a safe and seamless experience on their platform.
Forces reshaping the gaming industry
Among the forces reshaping the gaming landscape, these four stand out in terms of creating governance, compliance and trust challenges.
1. Connected, persistent gaming ecosystems
While battle royale titles such as Call of Duty helped normalize large-scale online interaction, today’s gaming platforms extend far beyond matchmaking and voice chat. Players now participate in creator-driven experiences, virtual economies, social communities and live events that operate continuously across devices and geographies. As a result, players expect seamless experiences across consoles, PCs, mobile devices and cloud platforms, while companies increasingly rely on subscriptions, live-service content and virtual economies to drive growth.
This evolution has expanded engagement and revenue potential, but it has also introduced new risk exposures. For example, expanded communication and social features can create additional opportunities for bad actors to target minors, promote illegal products or engage in harmful conduct. Likewise, virtual currencies, digital marketplaces and creator monetization programs can increase exposure to fraud, account compromise, payments-related risks and financial crime concerns.
2. Co-development is a business necessity
Modern games require larger teams, longer development cycles and specialized expertise. In response, studios are embracing co-development models in which developers, publishers and specialized third parties jointly support game development, online services, content creation and live operations.
Publishers may retain overall responsibility for the game’s vision, direction and player experience while relying on external partners for environment design, localization, quality assurance or live-service support. While these arrangements accelerate production and control costs, they also expand the organization’s risk perimeter. Publishers increasingly need assurance that development partners meet the same standards they hold themselves to for data handling, security, content controls and incident response, often across multiple jurisdictions and contracting models.
3. AI is changing how games are built
Studios are using AI-powered tools to generate assets, build environments, create dialogue, automate testing and explore design variations. These capabilities can shorten production timelines, reduce costs and improve productivity.
Morgan Stanley estimates AI-driven efficiencies could unlock roughly $22 billion in additional annual profit across the industry as development costs fall and companies reinvest savings into new experiences and operations.
4. Monetization models continue to evolve
Revenue generation now extends far beyond one-time game sales. Subscriptions, in-game purchases, virtual goods and creator-driven economies have become essential sources of recurring revenue.
While these models offer significant commercial advantages, they also place gaming companies at the center of debates around consumer protection, virtual assets, gambling adjacency and pricing transparency.
Looking forward: Where do future challenges sit within gaming?
Many gaming operating models were built during periods of rapid expansion, when product innovation and user growth often took precedence over governance. As a result, organizations are now managing complex ecosystems that were never designed to address today’s expectations around child safety, AI oversight, content moderation and virtual economies.
As regulatory expectations expand globally, many organizations are finding that ad hoc processes no longer scale. Governance, risk and compliance frameworks increasingly need to operate consistently across products, regions, creator ecosystems and business lines while remaining flexible enough to absorb new requirements without rebuilding from scratch each time.
Compliance gaps often emerge only after a regulatory inquiry, public controversy or security incident. Several risk categories are drawing increasing attention.
Content, UGC and IP risk
User-generated content (UGC) platforms such as Minecraft Marketplace and Steam Workshop ecosystems enable creators to create and monetize content at scale.
While these models drive engagement and innovation, they also raise difficult questions around content moderation, child safety, intellectual property ownership, licensing rights, creator monetization and platform accountability. When user-created content incorporates third-party IP or generates commercial value, responsibility becomes increasingly difficult to define.
Child safety and age assurance
While people of all ages participate in online gaming, children and teens represent a significant share of the player population. In the United States, the Entertainment Software Association’s 2025 Essential Facts report found that 83% of Generation Alpha (ages 5-12) play video games weekly.
As a result, parents, regulators and gaming companies often share a common objective: ensuring that young users can safely participate in online experiences while protecting their privacy and personal information. Achieving that objective requires companies to understand which users are children and which are adults. Consequently, age assurance has become a critical capability, helping organizations deliver age-appropriate experiences, apply appropriate safeguards and comply with evolving regulatory expectations.
Regulators increasingly expect platforms to verify user age rather than rely solely on self-attestation. As age-appropriate design requirements expand globally, gaming companies face difficult trade-offs among safety, privacy, cost and user experience.
Technologies such as age estimation and biometric verification may strengthen safeguards but also introduce additional privacy and data protection obligations.
Monetization and consumer protection risk
As monetization models diversify, gaming companies find themselves at the center of consumer protection and financial regulatory scrutiny. The growth of loot boxes, virtual currencies, in-game purchases and secondary asset markets has intensified attention from policymakers, who continue to debate where the line exists between entertainment mechanics and gambling-related activity.
At the same time, consumers now expect transparency around subscriptions, automatic renewals, pricing and cancellation rights.
Cybersecurity risk
As gaming platforms have evolved into connected digital ecosystems, they increasingly combine elements of social networks, payment services, content marketplaces and entertainment platforms. Features such as virtual economies, user-generated content, creator monetization programs, cross-platform identities and live-service environments have expanded both the value of these ecosystems and the opportunities available to threat actors.
Attackers are no longer focused solely on corporate systems and customer data. Player accounts, virtual assets and in-game currencies have become attractive targets, with account takeover driven by credential stuffing, phishing and bot-based attacks giving access to player identities, stored payment details and in-game assets. AI is accelerating these efforts, automating phishing and credential attacks at scale and creating more convincing lures that impersonate trusted platforms, while also being turned against game integrity and anti-cheat systems. At the same time, live-service titles remain among the most targeted for distributed denial-of-service (DDoS) attacks, where disrupting availability can take popular games offline and erode player trust.
As studios increasingly rely on co-development partners, cloud platforms, payment providers and content moderation vendors, the attack surface continues to expand. Recent incidents have shown how a single compromised vendor can expose an organization’s data even when its own systems were never directly breached, and how attacks on back-end game systems can flood virtual economies and destabilize in-game marketplaces. Cybersecurity failures can impact not only data confidentiality but also player trust, game integrity, brand reputation and the long-term viability of virtual economies.
The AI factor
AI is helping studios accelerate content creation, automate testing and improve development efficiency. AI is also changing how gaming companies operate by supporting content moderation, player support, fraud detection and creator tools.
As AI becomes more deeply embedded across development workflows and player-facing experiences, organizations face growing questions around transparency, safety and accountability. These questions become particularly complex within creator ecosystems, where AI-generated content raises new challenges around intellectual property and ownership when that content is distributed or monetized on a platform.
Organizations that derive the greatest value from AI treat governance as an enabler of innovation, establishing clear accountability, maintaining appropriate human oversight and continuously monitoring systems for unintended consequences.
Building governance into the game
Based on Protiviti’s experience supporting gaming companies, the organizations navigating this environment most successfully are treating compliance, trust and safety as a design input rather than a post-launch remediation exercise. Here are seven strategies gaming companies can incorporate now in this new risk paradigm.
1. Establish age assurance and child safety programs
As expectations for online safety increase, companies should move beyond basic self-attestation and adopt risk-based age assurance approaches that match verification methods to the level of risk presented. Flexible frameworks can help organizations balance evolving legal requirements with privacy, safety and user experience considerations.
2. Establish scalable trust and safety operations
As gaming platforms expand into social, creator-driven and commerce-enabled ecosystems, trust and safety capabilities become increasingly important to protect users and maintain player trust. Organizations should establish clear governance for community standards, content moderation, investigations and critical incident management, supported by documented policies and consistent enforcement practices. Effective programs combine user reporting, appeals processes and escalation pathways for higher-severity harms. As regulatory expectations evolve, organizations should be prepared to demonstrate how safety decisions are made and consistently enforced across their platforms.
3. Build privacy and security into the player experience
Privacy and security considerations should be integrated into product development from the outset rather than addressed after launch. As gaming platforms introduce features such as cross-platform accounts, virtual currencies, creator ecosystems and AI-enabled functionality, organizations should assess how personal information is collected, used, shared and protected throughout the player journey.
Security and privacy teams should work alongside product, engineering, and trust and safety functions to identify risks early, implement appropriate safeguards and ensure controls evolve alongside new features. A proactive approach can help safeguard personal information, reduce the risk of security and privacy incidents, strengthen player trust, and support compliance with an increasingly complex regulatory landscape.
4. Align innovation, risk management and regulatory expectations
Risk, legal and compliance teams should be engaged early in product development, particularly for high-risk features such as AI-enabled functionality, user-generated content and monetization mechanics.
Organizations should also evaluate governance decisions through the lenses of growth, customer trust, monetization and brand reputation, not just regulatory compliance.
5. Make executive-level decisions about risk trade-offs
Many of today’s most difficult questions involve trade-offs between safety, privacy, cost and user experience. Decisions regarding age assurance, acceptable user friction and appropriate levels of AI oversight increasingly require executive and board-level involvement.
6. Establish clear governance for user-generated content
Creator ecosystems require clear ownership, licensing and usage frameworks. Organizations should establish guardrails for third-party intellectual property, content monetization and derivative works while maintaining robust moderation, reporting and appeals processes.
7. Implement practical AI governance
Effective AI governance begins with identifying use cases, classifying risk levels and applying proportional controls. Gaming companies should continuously test AI systems for performance, fairness and unintended consequences while ensuring players understand when AI influences recommendations, moderation or monetization decisions.
Waiting for global alignment is not a viable strategy
The regulatory environment surrounding gaming will remain fragmented for the foreseeable future. Standards related to age assurance, AI, virtual economies and intellectual property continue to evolve across jurisdictions, often faster than organizations can adapt.
Gaming companies that build flexible governance capabilities now will be better positioned to innovate with confidence, adapt to changing requirements and maintain player trust. By embedding governance into product development, monetization strategies and platform operations, organizations can reduce risk while preserving agility.
Perfection is not attainable in such a fast-moving environment. But better-informed decisions are. Increasingly, strong governance is becoming not just a compliance requirement but also a competitive differentiator.
Protiviti Associate Director Bridget Ostojic, Associate Director Tim Kelly and Senior Manager Eli Valenzuela contributed to this report.
