Key Points
- Spelinspektionen removed the AML exemption for land-based commercial casinos effective 1 September 2026, following a risk reclassification made in September 2025.
- Twelve licence holders operating across 425 gaming locations must now build full risk-based AML programmes, including customer due diligence and suspicious activity reporting to Sweden’s Financial Intelligence Unit.
- The change puts Sweden ahead of the EU’s incoming Anti-Money Laundering Regulation, which becomes directly applicable across all member states from 10 July 2027.
For over five years, Sweden’s restaurant casinos operated inside a regulatory blind spot. They served real money across gaming tables, accepted cash, processed Swish payments, and ran card games in licensed venues across the country, all while sitting largely outside the country’s anti-money laundering framework. That ended on Tuesday, 1 September 2026, and the speed at which Spelinspektionen expects compliance makes the gap feel even starker.
The Swedish gambling regulator confirmed that the previous AML exemption had been repealed under an amendment to its regulations on measures against money laundering and terrorist financing, effective from that date. There was no transitional grace period. Compliance, the regulator stated, must already be in place.
What Changed and Why the Timing Matters?
The resolution, which was officially adopted on 2 March 2026, amended the AML regulations for the gambling sector of Spelinspektionen SIFS 2019:2. As of the adoption of this amendment, the land-based commercial casino activities covered by Chapter 9 of the Gambling Act are no longer exempt. The phrase ‘state-owned casino’ has been removed since the last state-owned casino in Sweden is now defunct.
The groundwork for this change was laid in September 2025, when Spelinspektionen revised its sector-wide money laundering risk assessment and concluded that the risk for land-based commercial casino gaming could no longer be considered low. Following that reassessment, the exemption lost its justification. “Risks for money laundering in commercial land-based casino gambling are no longer assessed as low,” the regulator stated plainly when it announced the findings behind the rule change.
Twelve Operators, 425 Locations, and a Compliance Gap No One Is Talking About
The scale of what is now required deserves closer attention. As of September 2025, 12 licence holders were operating across 425 gaming locations across Sweden, offering lower-stakes games such as roulette, cards and dice in restaurant settings. These are not high-gloss casino floors staffed by compliance professionals. Many were never designed with KYC infrastructure in mind, which is precisely why the regulator’s “already in place” expectation is more significant than it first appears.
Each operator must now produce a general risk assessment, establish written procedures and guidelines, train staff, assess individual customer risk, and build ongoing transaction monitoring. Spelinspektionen’s guidance makes clear that this risk assessment is the foundation for everything else: “The general risk assessment is fundamental to all other work to prevent money laundering and terrorist financing,” the authority stated.
Where suspicious behaviour cannot be explained after review, operators must report it to Sweden’s Financial Intelligence Unit. Proof of wrongdoing is not required before filing. Waiting for certainty is itself a compliance failure under the framework.
One detail that most coverage has skipped entirely: the player registration exemption under the Gambling Act itself remains. Operators are not required to formally record every player’s name, address and personal identity number. But AML obligations can still require identification where risk indicators appear. Spelinspektionen put it directly: “The fact that a licensee does not need to register its customers in accordance with the provisions of the Gambling Act therefore does not exclude that the licensee may need to register its customers in another way in order to meet the customer due diligence requirements of the Money Laundering Act.” That line, between Gambling Act registration and AML identification, is exactly where compliance uncertainty will concentrate in the months ahead.
The Swish Problem Nobody Flagged
The specific vulnerabilities Spelinspektionen identified point to something the regulator flagged but most commentary has passed over. Cash, payment cards and Swish, Sweden’s dominant mobile payment platform, were all in active use across these venues. The ability to switch between payment methods, rather than any single method, was flagged as a structural weakness. Swish is frictionless, near-universal in Sweden and does not trigger automatic suspicion in small transaction volumes. A venue accepting both cash and Swish creates a mixing environment that is harder to audit than either method alone. The regulator described this as one of the factors that led it to rate land-based commercial casino gambling as medium risk in 2025.
The wider risk picture the regulator painted was equally sharp. “Economic crime and money laundering is a major social problem in Sweden,” Spelinspektionen warned, describing criminal actors exploiting legal corporate structures with “increasingly professional and sophisticated” methods. “Even though cash handling has decreased in society at large, cash continues to play a significant role in the criminal economy,” the authority added. Restaurant casinos, sitting at the intersection of multiple payment methods and low regulatory scrutiny, fit that profile more closely than the old exemption acknowledged.
The State Casino Closure Left a Void the Rules Did Not Fill
Swedish gambling was regulated by the Gambling Act from January 1st, 2019. The regulation replaced the state monopoly with the licensing of competition. Obligations concerning anti-money laundering were implemented by the SIFS 2019:2 from the very beginning. Restaurant casinos, classified at that time as low-risk establishments, were excepted. Such an exception lasted until the situation in terms of risk changed.
The last state-owned Swedish casino, Casino Cosmopol of Stockholm, was shut down in April 2025 after the Riksdag made a decision to do so on April 2nd, 2025. “From a business point of view, the best thing to do is close immediately because the company has been losing money for many years,” Ola Enquist, CEO of Casino Cosmopol, said back then. Thus, when the state casino was no longer in operation, the importance of the restaurant casinos increased relative to the land-based casino market. The exemption was getting less justifiable.
Spelinspektionen had already signalled its enforcement direction. In 2025, the regulator concluded major AML investigations into prominent online operators, resulting in fines ranging from SEK 5.5 million to SEK 7 million against TSG Interactive (PokerStars), Betsson Nordic and Snabbare for failing to collect sufficient customer information and source-of-funds documentation. Maintaining an exemption for restaurant casinos while holding online operators to that standard was a contradiction that the rule change resolves.
The EU Deadline Already Running in the Background
The Swedish policy is not an isolated event. As per the Sixth Anti-Money Laundering Directive (AMLD6, Directive 2024/1640), member states are required to transpose the requirements of the directive by 10 July 2027. The European Union Anti-Money Laundering Authority began functioning in Frankfurt on 1 July 2025 and is currently working on 23 technical standards up to 2026.
Spelinspektionen confirmed it is actively tracking this, noting that work is ongoing on the new EU framework and that “it is important that licensees follow the development of the new regulations and stay updated on upcoming changes.” Restaurant casino operators brought into AML obligations today will face another layer of European-level requirements within a year. Building a compliant programme now, under national rules, is considerably easier than rebuilding it in 2027 under European enforcement.
Expert Analysis
We find the five-year carve-out harder to defend the longer we look at it. Sweden built a reputational position as one of Europe’s more serious regulated markets after 2019. Embedding AML obligations across the licensed sector while quietly exempting a segment that accepted cash, card and Swish simultaneously was always a tension the framework was carrying. The September 2025 risk reclassification made the contradiction visible. The September 2026 rule change finally resolves it.
The Swish dimension is the part of this story we think deserves a sharper lens. The conversation around casino AML risk defaults to cash, and cash is a genuine concern. But Swish changes the risk profile meaningfully. It is instant, widely accepted and generates transaction records that are less aggregated and easier to fragment than bank transfers. In a venue where the operator is not formally required to register every player, a customer making a series of small Swish payments across an evening creates a pattern that is genuinely difficult to reconstruct without proactive monitoring. The regulator identified this. The compliance response from 12 operators across 425 locations will determine whether the identification was enough.
Whether smaller restaurant casino operators can realistically build credible AML programmes at pace is the question the regulator has not fully answered. These businesses were not structured for compliance infrastructure. The “already in place” framing closes the door on any managed transition. We expect Spelinspektionen’s tolerance for early-stage gaps in this sector to be considerably shorter than some operators may be assuming, particularly with the EU clock already running toward July 2027.