Distribution Was Switched Off Before the Litigation Ended
ThePrint reported on 4 August 2026 that the government had told app stores and OTT platforms to stop enabling money games, the first large enforcement push under the online gaming law. The next day, The Economic Times reported that the Supreme Court agreed to hear pleas challenging the statute. Those two events define the problem every remaining real money gaming operator now has to solve.
The order matters. Distribution went first. A delisted platform cannot acquire users, cannot ship a build to existing users, and in practice cannot process a deposit, because payment partners read a delisting as a compliance signal long before any court rules. Revenue stops within days. The challenge to the statute will take quarters, and a favourable ruling does not rebuild a distribution channel or restore a terminated payment relationship.
The operating question is what a company does with the eighteen to thirty-six months in which it has no income and a full set of live liabilities. That is a run-off problem: which policies are preserved, which converted, what is bought on the way out, and what is disclosed to whoever underwrites the surviving business.
The Liabilities That Keep Running After the Revenue Stops
A wind-down does not retire exposure. It changes who is chasing it and how long they take. Five categories stay live past the last processed deposit.
- User claims on balances. Wallet balances, bonus credits, contest entries voided mid-tournament and disputed withdrawals all become claims the moment the app is delisted. These are contractual and consumer-forum exposures, and general liability wordings usually respond poorly or not at all.
- Regulatory investigation costs. The largest near-term cash item for most platforms. They arrive as summons, document production, forensic accounting and counsel time, before anyone has been accused of anything.
- Tax and enforcement proceedings. The New Indian Express reported on 25 July 2026 that a Rs 27 crore GST evasion case was unearthed at a Bengaluru online gaming firm, with two arrests. The Times of India reported the same week that a widening betting probe had traced Rs 70,000 crore through 750 shell merchants, with suspected GST evasion of Rs 19,600 crore.
- Asset attachment risk. The Economic Times and Exchange4Media reported on 24 July 2026 that the Enforcement Directorate had attached a fresh Rs 1,906 crore of assets in the Gameskraft-linked Rummy Culture money laundering probe. Attachment does not wait for conviction, and it reaches the balance sheet that would otherwise fund the defence.
- Directors and officers claims. Investors, employees and payment partners all have reasons to look at the board once equity value is impaired, and enforcement agencies have reasons to name individuals rather than only the entity.
The common feature is timing. Every one of these can surface two or three years after the platform goes dark, which is the window in which an unmanaged programme has already lapsed.
Preserve, Convert, Lapse: Sorting the Programme
Sort every policy in the tower into one of three buckets before the first renewal after the shutdown. The rule is whether the cover responds to conduct that has already happened.
Preserve. Cyber and crime cover, and any professional indemnity written for the platform's B2B arm, respond to past conduct and past data. They stay, usually on reduced limits, and they need active handling rather than passive rollover. Fidelity and computer-crime sections become more relevant during a wind-down, because insider risk peaks when employees know the business is closing and access controls decay with the engineering team.
Convert. Directors and officers liability is the policy that has to change shape. A claims-made policy responds to claims first made during the policy period, so letting it lapse at the first post-shutdown renewal leaves the entire tail bare. The conversion is either a run-off placement or an extended reporting period.
Lapse. Covers that respond only to operating activity can go: employee benefit extensions once employment ends, marketing and media liability once campaigns stop, property and equipment cover once the office is surrendered. Do not cancel these quietly. Cancel them with a written record of the date the exposure ended, because that record supports the later argument that any subsequent claim falls outside the exposure period.
How an Extended Reporting Period Is Priced When There Is No Revenue
An extended reporting period, also called tail cover, extends the window in which a claim can be reported under a claims-made policy after the policy has ended. It does not cover new acts. It covers claims first made during the extension arising from acts committed before expiry.
Indian D and O wordings typically offer one, three or six years, and a six-year run-off placement is the length usually chosen where enforcement and tax proceedings are expected to run for years. Premium is quoted as a percentage of the expiring annual premium, and market convention runs roughly:
- One year: 50 to 100 per cent of expiring premium
- Three years: 100 to 175 per cent
- Six years or full run-off: 175 to 300 per cent
Those bands assume an ordinary wind-down. A platform in the middle of an enforcement cycle sits outside them, and the pricing changes in three ways.
First, the underwriter has no turnover to rate against, so the rating base shifts to historical exposure: peak user count, peak wallet float, total deposits processed over the policy periods being tailed, and the jurisdictions in which users were accepted. A platform that shrank quietly for two years gets no credit for the shrinkage, because the tail attaches to the years when the business was large.
Second, known circumstances are excluded. Anything the board has notified, and anything it should have notified, is carved out. That makes notification before expiry the highest-value action available to the board.
Third, the premium is payable in full and in advance and is not refundable. The tail is funded out of the same cash that funds the defence, which is why the decision belongs in the first wind-down board meeting rather than at the renewal date.
The Investigation Costs Line Is the One to Read Word by Word
For a platform in run-off, the D and O limit will most likely be consumed by investigation costs rather than by a judgment. Attachment proceedings, GST assessments and money laundering investigations all generate years of defence spend before anyone reaches a finding.
The wording questions that decide whether it is recoverable are narrow:
- Does Investigation include pre-claim regulatory inquiry? Many Indian wordings trigger only once a formal notice naming an individual is served. An entity-level summons for documents may trigger nothing.
- Are Enforcement Directorate and GST proceedings within the definition of Official Body? Some wordings enumerate financial regulators and omit tax and enforcement authorities.
- Is the investigation costs sublimit inside or outside the aggregate? Inside, it erodes the limit available for the eventual defence.
- How does the conduct exclusion operate? Excluding cover on allegation rather than on final adjudication is close to worthless in a money laundering investigation, where the allegation is the whole event.
- Is there an advancement of defence costs obligation? Advancement matters when the company's assets may be attached.
CNBC TV18's 5 August 2026 piece on Gameskraft jurisprudence and its aftermath points at the same problem: legal exposure from the pre-prohibition years does not close when the prohibition takes effect. It becomes the main event. The cover that matters in 2028 is the cover written over 2022 to 2025 and correctly tailed in 2026. The operating-phase programme is set out in the real money gaming platform insurance guide and the underlying exposures in the platform liability post.
The Platform Is Dark, the User Database Is Not
Shutting down an application does not shut down a data controller. A former money gaming platform holds KYC documents, identity records, bank account details and transaction histories on a user base that may run to tens of millions. Those records have to be retained, because tax assessments, enforcement proceedings and user disputes all demand them. Retention plus a decaying security posture is the worst combination in cyber risk.
The decay pattern is predictable. Security engineers leave first, because they are the most employable. Monitoring alerts route to mailboxes nobody reads. Cloud accounts stay funded but unowned. Third-party integrations keep live credentials long after the commercial relationship ends. A database that is still readable but no longer watched is the asset that surfaces on a breach forum eighteen months later.
A cyber insurance policy in run-off therefore has to be handled differently from one on an operating business:
- Keep incident response and notification, reduce business interruption. There is no revenue to interrupt, so full BI rating on a dark platform wastes limit and premium. Forensics, notification costs, regulatory defence and third-party liability stay at full weight.
- Confirm cover extends to historical data held for legal retention. Some wordings tie cover to systems used in the conduct of the business, and a platform with no business may fall outside that.
- Name the entity that will actually hold the data. If it migrates to a holding company or a liquidator, the named insured has to follow.
- Do not let security warranties fail. Multi-factor authentication, patching and backup warranties given at inception survive the shutdown. A warranty breached because the person responsible resigned is still a breach.
Under the Digital Personal Data Protection framework, ceasing operations does not discharge a data fiduciary's obligations over records retained for legal purposes. A wind-down plan that treats the user database as an abandoned asset creates a live exposure with no operating team behind it.
The Esports Pivot Changes the Risk, Not the History
sigma.world reported on 30 July 2026 that esports titles must register with India's Online Gaming Authority. Registration is the legitimate route forward for a team that wants to keep operating, and several money gaming operators are taking it. It creates an insurance problem, because the pivoted entity often shares a legal shell, a founding team, a technology stack and a user database with the prohibited business.
The risk profile of a registered esports platform is different. With no stake tied to a paid entry, the wallet float shrinks and the payment fraud surface contracts with it. What replaces it is event exposure: prize pool guarantees, venue and public liability at live events, contractual liability to publishers and sponsors, safeguarding obligations for young competitors, broadcast and media liability on streamed content, and player contract disputes. Cyber exposure stays high, since competitive integrity depends on account security and match manipulation is insider fraud under another name.
Disclosure is where most pivots go wrong. A proposal form that presents the esports entity as a new venture and omits the money gaming history breaches the duty of disclosure and hands the insurer a defence on every future claim. Underwriters are entitled to:
- The full corporate history including any name change, and the relationship between the new entity and the prohibited business.
- Whether the same directors serve on both boards, and whether any is under investigation.
- Whether the user database, wallet ledger or payments infrastructure carried over.
- The status of every open tax, enforcement or consumer proceeding against the group.
- Online Gaming Authority registration status and any conditions attached.
The structure that works is separation: a clean new entity, its own D and O tower, its own cyber policy, no shared named insured with the legacy company, and the legacy company running its own tail. Endorsing the esports business onto the old programme saves a little premium and contaminates the new cover with the old history. Sector context sits in the gaming and esports insurance overview.
A Sequence for the Wind-Down Board Meeting
The decisions have a strict order, because several close permanently once an event occurs.
- Notify circumstances under every live claims-made policy before anything expires. List every regulatory contact, every disputed user matter above a threshold, every payment partner termination and every internal finding. This is free, and it converts a future uninsured claim into one attaching to the current policy year.
- Fix the D and O tail length and fund it from the wind-down budget. Six years is the defensible answer where enforcement proceedings are live. Fund it before other creditors have a call on the cash.
- Rebuild the cyber policy around retained data. Strip business interruption, keep incident response, notification, and regulatory defence, and confirm the named insured follows the database wherever it goes.
- Keep crime and fidelity cover through the last day of employment plus a discovery period. Insider risk peaks in the final quarter.
- Document the date each operating exposure ended. Office surrender, last processed deposit, last app build shipped, employment end dates. These decide which policy year a later claim attaches to.
- If pivoting, incorporate and insure separately, and disclose in full. Separate entity, separate tower, complete disclosure of history.
- Preserve the policy documents. A claim notified in 2029 against a 2023 policy year needs the wording, schedule, endorsements and proposal form. Store them somewhere that survives the company's systems being decommissioned.
A broker running this sequence is converting an operating programme into a set of dated, funded, documented obligations that will still be there when the last proceeding closes. That work happens in the ninety days around the shutdown or it does not happen at all. For adjacent payments exposures that often sit in the same group structure, see the payment aggregator crime and cyber post.