How do open banking regulations work?
Open banking regulations force banks to share customer data with authorized third parties via standardized APIs, with consumer consent. The EU PSD2 (2018) and UK CMA Order (2018) created the legal infrastructure but adoption diverged sharply: the UK delivered measurable usage while continental Europe largely disappointed. PSD3 aims to fix the friction points exposed during 2018-2023.
In this article
The short answer
Open banking is a regulatory regime that gives consumers a right to share their bank-held financial data with authorized third-party providers. The data flows via standardized APIs rather than screen-scraping. Two roles emerged: account information service providers (AISP), which read data, and payment initiation service providers (PISP), which initiate transfers from a customer’s account.
The regulatory architecture combines mandatory data access (banks must provide it), strong customer authentication (consent must be verifiable), and a licensing regime for third parties. The economic theory is that lower data switching costs increase competition and innovation.
The empirical record is mixed. The UK’s CMA Order produced visible AISP and PISP traffic. Continental Europe’s PSD2 implementation suffered from inconsistent API quality, weak monetization paths and limited consumer awareness.
→ New to financial regulation? Financial education hub
What the data shows
Open banking adoption metrics diverge significantly across jurisdictions, though precise figures are subject to definitional choices.
Key figures (UK Open Banking Implementation Entity, EBA, EU Commission, 2018-2024):
- The UK reported around 13 million active open banking users by mid-2024, compared to a population of approximately 67 million
- Open banking payment volume in the UK was reported at over 22 million payments in a single month by 2024
- The European Banking Authority documented persistent issues with PSD2 API quality, including downtime, latency and inconsistent data formats during 2020-2023
- The European Commission’s PSD2 review (2022-2023) led to the PSD3 and Payment Services Regulation proposals, targeting application around 2026-2027
- Around 600 third-party providers had been authorized under PSD2 across the EU by 2024, but actual usage concentrated among a fraction of them
The exception that nuances the headline: even in the UK, where open banking is most mature, it remains an enabler for specific use cases (variable recurring payments, account aggregation, lending decisioning) rather than a wholesale replacement of card rails or bank apps.
→ Dataset: Financial conditions index
Why it happens — the macro mechanism
Open banking outcomes depend on three interacting channels.
Channel 1 — Mandated data access. The legal core of open banking is forcing banks to provide a standardized API to third parties. The UK regulator centralized API standards through the Open Banking Implementation Entity, producing one technical specification. The EU left implementation to each bank, generating dozens of API variants of uneven quality. The single-standard design proved a stronger enabler of competition than the harmonized-but-distributed model.
Channel 2 — The monetization gap. The most underdiscussed feature is that PSD2 created a right of access without a clear monetization model for either banks or third parties. Banks were required to provide APIs at no charge, removing any incentive to make them performant. Third parties had access but struggled to build sustainable revenue from low-margin payment initiation in a card-dominated environment. The regulation created supply without demand, then waited for demand to emerge.
Channel 3 — Variable recurring payments and the next frontier. The UK’s introduction of variable recurring payments (VRP) — pre-authorized, capped, repeatable payments — opened a use case that PSD2 did not cover. VRP allows account-to-account transactions to substitute for card-based recurring billing, with lower fees and higher consent granularity. PSD3 proposals signal European intent to follow.
Synthesis by regime: in the implementation regime of 2018-2020, open banking was a compliance project with little adoption; in the post-COVID 2021-2023 phase, UK PISP volumes accelerated as consumers became more comfortable with API authentication; the post-2024 regime, with PSD3 in legislative pipeline and VRP-style mechanisms spreading, is the first where open banking enters policy debates as a serious payment alternative rather than a niche.
Open banking gave consumers a right of access; what is still being designed is the right of monetization that makes the access matter.
→ Framework: Financial innovation and systemic risk
What it means for different economic actors
Banks face a tension between compliance and strategic positioning. Compliance requires functional APIs at zero direct revenue. Strategic positioning involves either competing as an aggregator (consuming data from other banks) or accepting commoditization of basic account services.
Fintech aggregators built their products on PSD2 access, but the unit economics depend heavily on jurisdiction-specific API quality. Plaid, Tink and similar aggregators thrive where APIs work and struggle where they do not.
Consumers theoretically benefit from data portability and lower-cost payment alternatives. In practice, consumer awareness of open banking remains limited, and the products built on top often look like ordinary mobile apps without a visible “open banking” label.
A common error is treating open banking as a single global phenomenon. Australia’s Consumer Data Right, the UK’s CMA Order and the EU PSD2 differ structurally and produce different outcomes.
Practical observation
What the data suggests for understanding open banking dynamics:
- Question to ask yourself: What use case in my financial life would benefit from cross-bank data sharing — and is there an authorized provider serving it?
- Data to monitor: Open banking payment volumes published by national regulators, and the count of active third-party providers (level matters; rate of change indicates ecosystem health)
- Historical parallel: The 1990s deregulation of telecom number portability followed a similar trajectory: mandate first, slow adoption, then a use case (mobile portability) that triggered mass behavioural change
- What the literature documents: The EBA’s PSD2 implementation reports and the UK Open Banking Implementation Entity quarterly statistics provide the most reliable data series
This is descriptive information to help you frame your own analysis. Eco3min does not provide investment advice.
Go deeper
📊 Full study: Artificial intelligence as systemic financial risk
📁 Datasets: Financial conditions index · US bank lending standards
📖 Related analysis: Markets without signal — dispersion and risk
Related questions
Frequently asked questions
How does open banking differ from screen-scraping aggregators that existed before?
Screen-scraping required users to share login credentials with aggregators, a security model that broke under modern authentication. Open banking replaces credential sharing with consent-based API access using OAuth-style authorization. The difference is meaningful: open banking access can be revoked at the bank level, audited, and limited in scope. The trade-off is that open banking only delivers what the API exposes; richer data sometimes remained accessible only through screen-scraping in the transition period.
What is PSD3 and how does it differ from PSD2?
PSD3, proposed by the European Commission in 2023 and expected to apply around 2026-2027, addresses the operational shortcomings of PSD2 identified during its first five years. The package includes the Payment Services Regulation, which moves several technical rules from directive (national transposition) to regulation (direct application). Targeted improvements include API performance standards, fraud liability adjustments, and clearer scope for variable recurring payments.
Does the United States have an open banking framework?
The CFPB issued a final personal financial data rights rule in October 2024, creating a US framework with substantive similarities to the UK and EU approaches. Implementation is phased through the late 2020s. Compared to PSD2, the US rule places greater emphasis on consumer data portability across financial institutions and explicitly addresses screen-scraping deprecation. The early adoption trajectory will depend on which standard-setting body emerges to coordinate technical implementation.
Last updated — 30 July 2026
Disclaimer – Financial Information: The analyses, commentary, and content published on eco3min.fr are provided for informational and educational purposes only. They do not constitute investment advice or a solicitation to buy or sell financial instruments. Past performance is not indicative of future results. All investment decisions involve risk and are the sole responsibility of the reader.
