Key Impact of Open Banking In EU
Updated: 4 days ago

AI Summary: Open banking in EU markets began with PSD2 in 2018, requiring banks to share customer data with licensed third parties through regulated APIs. In 2026, the EU is mid-transition to PSD3 and the Payment Services Regulation (PSR), with a provisional agreement reached in November 2025 and applicability expected around 2027–2028. A separate regulation, FiDA, aims to extend the same model to investments, pensions, insurance, and loans, though trilogue talks on it paused in early 2026. For fintechs — including US-based teams building for European users — this means API performance, fraud liability, and licensing rules are all shifting at once, and fintech software development teams need to build for standards that are still being finalized. |
What Is Open Banking, and Why Did the EU Lead on It?
Open banking in EU financial services refers to a regulated framework requiring banks to give licensed third parties secure, API-based access to customer account data and payment initiation — with the customer's explicit consent. It's not a product; it's a legal mandate that turned banks from closed data silos into regulated API providers.
The EU got here first through the second Payment Services Directive (PSD2), adopted in 2015 and applicable from 2018. PSD2 had two core goals: strengthen payment security and open the market to competition and innovation. It created two licensed service categories that still define the space today:
Account Information Services (AIS): Third parties that can view account data — balances, transactions — with consent.
Payment Initiation Services (PIS): Third parties that can trigger a payment directly from a customer's bank account, without routing through a card network.
The Impact of Open Banking in the EU Since PSD2
Impact on Consumers
For everyday users, open banking is largely invisible infrastructure behind visible convenience: account aggregation apps that show every bank balance in one screen, budgeting tools that categorize spending automatically, and faster account switching between providers. It also enabled "pay by bank" — account-to-account payments that skip card networks entirely, which has slowly chipped away at card dependency for online checkout in several EU markets.
Impact on Banks
Banks went from being the sole gatekeepers of customer financial data to regulated API providers with compliance obligations attached to every data request. That shift wasn't smooth. One of PSD2's most persistent criticisms is uneven API quality and performance across member states — some banks built genuinely good APIs, others built the legal minimum, and third parties had to build around a patchwork of inconsistent implementations rather than one standard.
Impact on Fintechs
PSD2 is arguably the single regulation most responsible for the last decade of EU fintech growth. It enabled a wave of AIS- and PIS-licensed providers, embedded finance products, and lending platforms that use transaction data for real-time underwriting instead of static credit reports.
PSD2 Objective | Real-World Outcome |
Increase competition in payments | Strong — hundreds of licensed AIS/PIS providers now operate across the EU |
Improve payment security | Partial — SCA rollout reduced fraud but added friction, addressed further under PSR |
Standardize API access | Weak — API quality and reliability still vary significantly by bank and country |
Give consumers control over their data | Strong — consent-based data sharing is now a normal, expected feature |
Where EU Open Banking Regulation Stands in 2026
PSD3 and the Payment Services Regulation (PSR)
The European Parliament and Council reached a provisional political agreement on PSD3 and the new Payment Services Regulation (PSR) on November 27, 2025 — the most significant overhaul of EU payments rules since PSD2 itself.
PSR is a regulation, not a directive — meaning it applies directly across all member states with no national transposition required. It covers Strong Customer Authentication refinements, authorized push payment (APP) fraud liability, IBAN-name matching checks, and binding open banking API performance standards.
PSD3 is a directive covering licensing and supervision. It merges Payment Institutions (PIs) and E-Money Institutions (EMIs) into a single authorization regime, replacing the separate PSD2/EMD2 frameworks.
Timeline: Publication in the EU's Official Journal is expected in 2026, with PSR taking effect roughly 20 days after publication. PSD3, as a directive, requires national transposition within 18 months — putting most binding requirements on track for late 2027 into 2028.
FiDA — the Open Finance Expansion
FiDA (the Financial Data Access regulation) was proposed alongside PSD3 and PSR in June 2023, but it goes much further. Where PSD2/PSD3 cover payment accounts, FiDA extends the same open-data principle to investments, pensions, insurance, and mortgages, under a new regulated category called the Financial Information Service Provider (FISP).
Unlike PSD3, FiDA's path hasn't been smooth. Trilogue negotiations paused in early 2026, reportedly over unresolved questions about how the rules would apply to large non-EU platforms. That's pushed FiDA's realistic timeline out further than PSD3/PSR — most legal analysts now expect political agreement sometime in 2026 at the earliest, with actual applicability landing closer to 2028–2029.
PSD2 vs. PSD3/PSR vs. FiDA at a Glance
PSD2 (current) | PSD3 / PSR | FiDA | |
Scope | Payment accounts | Payment accounts | Investments, pensions, insurance, mortgages, loans |
Legal instrument | Directive | Directive (PSD3) + Regulation (PSR) | Regulation |
Status (2026) | In force since 2018 | Provisional agreement reached Nov 2025 | Trilogue paused early 2026 |
Expected applicability | Live now | ~2027–2028 | ~2028–2029 (best case) |
Key change | Established AIS/PIS licensing | Merges PI/EMI licenses, adds fraud liability + API performance standards | Creates new FISP category, extends access beyond payments |
Why This Matters for Fintechs Building for the EU
For any fintech — including US companies serving European customers — this regulatory shift changes what "compliant" actually means, in real time.
API reliability is moving from a best-effort expectation to a binding performance standard under PSR, which means integrations that were "good enough" under PSD2 may not clear the new bar. Fraud liability rules are also shifting: APP fraud provisions redistribute risk between banks and payment service providers in ways that affect how onboarding and authorization flows need to be built.
This is where fintech software development decisions made now matter more than usual, because teams are effectively building for a moving target. Firms offering fintech software development services to companies expanding into EU markets are increasingly designing integrations against the incoming PSD3/PSR standard rather than the current PSD2 baseline — so the API layer doesn't need a rebuild the moment the new rules apply. That's the same logic behind FintegrationFS's fintech software development approach: building account and payment integrations, including open banking API connections, to standards that hold up as the regulatory floor rises.
For companies specifically evaluating vendors, a comparison of the best open banking API providers for developers in 2026 is a useful starting point before committing to a single integration path — as is understanding options like the Tink and Visa open banking API for EU account connectivity specifically.
Infrastructure choices matter here too. Banks and fintechs weighing cloud banking software against legacy systems — see this breakdown of cloud banking vs. on-premise banking software — are generally better positioned to adapt to binding API standards than teams running on on-premise cores that require custom middleware for every regulatory change. The same applies to consumer-facing products: a mobile banking app built on a flexible open banking layer can absorb PSD3-driven changes without a front-end rebuild.
What Most Open Banking Coverage Overlooks
Most articles on EU open banking stop at "PSD2 enabled competition and innovation" and move on. Two things get consistently underexplained:
Inconsistent API quality wasn't a rollout hiccup — it's a structural gap PSR is specifically trying to close. PSD2 never mandated a single technical standard, which is exactly why performance varied so much bank to bank. PSR's binding API performance requirements exist because self-regulation didn't fully work the first time.
FiDA's delay is political, not procedural. Coverage often frames the pause as routine legislative friction. It isn't — the sticking point is a genuine disagreement over how open-data obligations should apply to non-EU platforms, which means the outcome could reshape FiDA's scope, not just its timeline. Companies planning around a fixed FiDA date are planning around a moving target.
Open Banking in the EU: Quick Reference
Question | Answer |
What is open banking in the EU? | A regulatory framework requiring banks to share customer data with licensed third parties via secure APIs, with consent |
Founding regulation | PSD2, applicable since 2018 |
Current transition | PSD3 and PSR, provisional agreement reached Nov 2025 |
Next expansion | FiDA — extends access to investments, pensions, insurance, loans |
PSD3/PSR expected applicability | ~2027–2028 |
FiDA expected applicability | ~2028–2029 (uncertain — trilogue paused in 2026) |
Challenges and Open Questions
Timeline uncertainty, particularly around FiDA's paused negotiations
Cross-border inconsistency in API standards that PSR aims to fix but hasn't yet been tested at scale
Data-sovereignty tension over how obligations apply to large non-EU platforms
Compliance cost, especially for smaller Payment and E-Money Institutions absorbing a license-regime merger
The Road Ahead for EU Open Banking
PSD3 and PSR represent the near-term compliance priority, with most binding requirements landing between 2027 and 2028. FiDA is the longer-term shift — from open banking to full Open Finance — but its realistic timeline now stretches toward 2028–2029, contingent on resolving the political questions still stalling trilogue talks. Even with that uncertainty, the EU's model remains the global reference point for regulation-driven open banking, in contrast to the more market-led approaches seen in the US (FedNow/RTP) and elsewhere — and companies building fintech solution development roadmaps for European markets are increasingly treating PSD3 compliance as a floor to build on, not a finish line to hit and stop.
Building or expanding open banking integrations for European markets? See how FintegrationFS's fintech software development services and open banking API connections are built to hold up as PSD3 and PSR phase in — or compare vendors first in our guide to the best core banking software providers in 2026.
FAQ: Open Banking in the EU
1. What is open banking in the EU, in plain terms?
It's a legal requirement that banks give licensed third-party apps and services secure access to a customer's account data and payment capabilities, but only with that customer's explicit consent. It's what lets a budgeting app see your bank balance or a checkout page pay directly from your account.
2. What's the actual difference between PSD2, PSD3, and PSR?
PSD2 is the current rule, in force since 2018. PSD3 and PSR are its replacement, with PSR handling day-to-day conduct rules (fraud, authentication, API performance) as a directly applicable regulation, and PSD3 handling licensing and supervision as a directive that each country still has to transpose into national law.
3. Is FiDA the same thing as PSD3?
No. PSD3/PSR update the existing open banking rules for payment accounts. FiDA is a separate, broader regulation that would extend the same data-sharing model to investments, pensions, insurance, and loans — effectively "Open Finance" rather than just open banking.
4. When do PSD3 and PSR actually take effect?
PSR is expected to apply roughly 20 days after publication in the EU's Official Journal, likely sometime in 2026. PSD3 requires each member state to transpose it into national law within 18 months, so most binding requirements are expected to land in late 2027 into 2028.
5. Does a US-based fintech need to worry about EU open banking rules?
Yes, if it serves EU customers or connects to EU bank accounts. Any company processing payments or account data in the EU needs its integrations built to PSD2 today and PSD3/PSR standards as they phase in — which is why many US fintechs work with a fintech software development company experienced in EU compliance rather than retrofitting integrations after the rules change.





