What Would a Geolocation Affidavit Have to Show a Judge?

Court orders usually tell a company what result to reach and leave the method to the company. The amended preliminary injunction that King County Superior Court entered against KalshiEX on 12 August 2026 does something less common. Paragraph 2 names the method, names the vendor that will supply it and sets a date: IP address and residency based geofencing by 19 August, then "a multi-source geofencing solution provided through GeoComply" by 2 September 2026. If the second milestone slips, the exchange either pays 120,000 dollars a day or files a sworn affidavit from a Kalshi or GeoComply representative explaining why. The judge then decides whether the exchange acted with sufficient diligence. Location checking stopped being a settings page at that moment. It became a product layer that someone may have to describe under oath to a stranger. This piece is about what that description would need to contain, and why a venue should be able to write it before any court asks.

The clause was drafted in Nevada first

The Washington wording did not originate in Washington. On 23 July 2026 the Nevada Gaming Control Board and Kalshi filed a joint stipulation in Carson City, Case No. 26 OC 00050 1B, signed by the court on 24 July. Its paragraph 4 commits Kalshi to "a multi-source geofencing solution provided through GeoComply" by 12 August 2026. Paragraph 5 contains the same choice that later appeared in King County: 120,000 dollars a day, or a sworn affidavit from a Kalshi or GeoComply representative, followed by a judicial finding on diligence. Paragraph 6 gives Nevada the same implementation updates that Kalshi gives Michigan, and the right to talk to the vendor with Kalshi's counsel present.

Washington's order copies that architecture almost clause for clause, moves the dates and widens the information parity to cover both Michigan and Nevada. The Board's own press release of 24 July 2026 describes the agreement as the alternative to a contempt hearing. Read together, the two documents show a template travelling from one state court to another in under three weeks. Whatever a venue tells the first regulator about its location checks is now, by court order, available to the next. That is Directive 05 of our manifest working mechanically: standards get set against the jurisdiction that regulates next.

The first layer failed in the documented case

The Nevada stipulation also records why a second layer was needed. In paragraph 3 Kalshi acknowledges that, notwithstanding its implementation of IP based and residency based trading blocks, the State's investigators had successfully placed trades in sports, election and entertainment contracts while the Nevada injunction was in force. The stipulation adds that Kalshi does not concede those trades amount to contempt. Still, it is a rare thing: a court record in which an exchange accepts that its first location control was bypassed.

It is not hard to see why. An IP address describes a network connection, not a person, and it changes with a VPN, a mobile carrier or a hotel network. Residency is what the account holder declared when the account was opened. The Washington order makes the point without meaning to: paragraph 4 refers to consumers "who identified or self-reported as Washingtonians." A control built on those two inputs answers the question where the account says it lives. The orders ask a different one, namely where the device is standing at the moment of the trade.

Multi-source is a requirement neither order defines

Neither the Nevada stipulation nor the Washington order defines "multi-source." Both name a vendor instead. The closest public description of what that vendor's product collects is the vendor's own. GeoComply's product page for GeoComply Core says it gathers GPS, GSM, WiFi and IP data from the user's device and checks for location spoofing methods including VPNs, data centres, anonymisers, proxies, Tor exit nodes, remote desktop tools, WiFi emulators and GPS spoofing. Those are the company's statements about its product in general. Neither GeoComply nor Kalshi has published the parameters of this particular deployment that we could find as of 7 October 2026: not the accuracy achieved, not how often a location is rechecked, not how many legitimate users are blocked by mistake.

We are not recommending a vendor, and the point of this piece does not depend on which one a venue uses. Michigan shows the alternative drafting. Gongwer News Service reporter Emma Kinery, in a story republished by Legal News on 7 September 2026, describes the Michigan preliminary injunction of 1 September as requiring Kalshi to use a third party geolocation provider licensed by the Michigan Gaming Control Board and able to meet the specifications in the Board's technical bulletin. That formulation names a standard and a licensing gate, not a company. For a venue, the practical difference is small. In both cases the control is judged by what it does, and in both cases the venue is the party that has to explain it.

A day after the Nevada deadline, nine trades went through

The most useful test of the new layer so far came from investigators, not engineers. Reuters reported on 15 August 2026, in a story by Rajveer Singh Pardesi and Rishabh Jaiswal carried by Yahoo Finance, that according to a court filing the Board's investigators placed nine trades on Kalshi's mobile application while connected to cellular networks in Nevada, a day after the 12 August deadline. Reuters also carried Kalshi's statement that it had hired GeoComply, a vendor licensed by Nevada's gaming regulator, at the state's request.

Kalshi's explanation is instructive, whether or not a court accepts it. Focus Gaming News reported on 17 August 2026 that, according to the regulator, Kalshi told agents the trades came from a previous version of its app that the geofencing did not cover, and that Kalshi's lawyers later argued the investigators had misrepresented their residence. We have not seen the outcome of the Board's penalty request. But both explanations point at the same engineering fact. A location control is only as complete as the oldest client still able to submit an order, and a residency field remains an input the user controls. An affidavit that says "the solution is live" without saying which app versions it covers, and what happens to a version that predates it, would not answer the question Nevada's investigators actually asked.

Gaming rulebooks wrote the checkpoints down years ago

None of this is new territory for regulated online gambling, and that is the useful part. Three rulebooks from states that license internet wagering already describe when a location has to be known:

  • New Jersey, N.J.A.C. 13:69O-1.2(e): the system must detect the patron's physical location on login and as often as the operator's approved submission specifies, and refuse wagers while the patron is outside an authorised area.
  • Michigan, Mich. Admin. Code R 432.731: the sports betting geofence must reasonably detect physical location, must dynamically monitor it and block unauthorised attempts throughout the betting session, and the Board approves all technical specifications.
  • Nevada, Regulation 5A.120(1): an interactive gaming operator must record and maintain the player's physical location, by state or foreign jurisdiction, while the player is logged in.

Notice what these texts do not contain. None of them puts a numeric accuracy figure, a border buffer or a recheck interval into the published regulation. Those numbers live in approved submissions and technical bulletins that a regulator reviews. The checkpoints are public, the thresholds are negotiated. A prediction market venue does not have that review relationship with a state gaming regulator, and the federal rulebook it does answer to has no equivalent. Commission Regulation 38.151 on access requirements speaks to impartial and non discriminatory access criteria, and the King County court held that sorting Washington users out of certain contracts did not breach it. It says nothing about how a venue should know where a participant is.

What a diligence affidavit would have to show

The penalty clauses make diligence the only defence, which turns engineering records into evidence. We discussed that shift briefly in our reading of the Washington order. Here is what we think the document would have to contain to be worth anything, written as a list a venue can prepare in advance:

  • Who holds the contract. The date the vendor agreement was signed, which entity signed it, and the scope: which states, which products, which platforms.
  • Which signals are used, and when. Whether location is checked on login only, before each order, or continuously through a session, in the terms New Jersey and Michigan use.
  • Client coverage. Every app version and web client able to submit an order, the date each one began enforcing the check, and how older versions were forced to update or cut off.
  • Spoofing handling. What happens when a VPN, proxy or emulator is flagged: a block, a manual review, or an account action, and how many such flags occurred.
  • False positives. How a legitimate user near a border who is wrongly blocked can appeal, how long it takes, and how often it happened.
  • Open positions. The Washington order lets users exit positions they already hold. The control must block new entries without trapping existing ones, a distinction we covered in our piece on geoblocking and open positions.
  • Retention. Paragraph 1 of the Washington order requires preservation of "geolocation/location determinations." Each check therefore has to produce a record that can be retrieved later, not just a pass or fail in memory.
  • Measured results. Pass rates, block rates and the results of the venue's own tests from inside and just outside the boundary, dated.

A venue that has these records writes the affidavit in an afternoon. A venue that does not is asking a judge to accept that it tried hard, with nothing to show for it.

Naming a vendor does not move the responsibility

It would be easy to read the orders as outsourcing the problem: name a recognised provider and the location question is closed. The documents point the other way. The affidavit can come from a Kalshi or a GeoComply representative, but the penalty attaches to the exchange. Nevada's investigators tested the venue's app, not the vendor's product page. Michigan judges the provider by licence and specification, and Washington wired itself into the reporting channel Kalshi already runs for two other states. In every version, the venue owns the explanation.

That is why we think the category should not wait for the next order to define the layer for it. Directive 02 of our manifest asks signatories to state fees, settlement sources and conflicts in plain language where the trade happens. Where a venue checks a user's location, how often, what it does with the result and how a wrongly blocked user gets help belong on the same list. They affect who can trade, and users who cross a state line every day deserve to know the rule before they hit it. Directive 05 covers the rest: the strictest live order in any state, Nevada's checkpoint language, Washington's retention clause, Michigan's licensing gate, is the floor a venue should already meet everywhere it operates.

As of 7 October 2026 there is no public record of whether the Washington deployment was completed on 2 September, whether an affidavit was filed, or whether any penalty was sought; the Attorney General's office has issued no release on the case since 13 August 2026. The absence of news is not the same as compliance, and it is not the same as failure either. What the two orders establish is narrower and more durable. Location is now a regulated layer of a prediction market product, and the venue has to be able to describe it as precisely as it describes its order book.

Share X LinkedIn Email