Current State of Open Banking: From Regulatory Access To Financial Infrastructure
Executive Summary – Open Banking is entering its next phase in the EU. PSD2 established regulated access to payment account data and payment initiation services, creating the foundation for a more open and competitive payments market. Since the framework became applicable in 2018, digital financial services, customer expectations, and fraud risks have continued to evolve.
PSD3 and the Payment Services Regulation (PSR) are now close to adoption and are intended to modernise this framework through stronger fraud prevention, improved consumer protection, and more consistent conditions for payment services across the EU. These reforms are expected to become important regulatory drivers of Open Banking 2.0.
At the same time, the proposed Financial Data Access Regulation, FiDA, points towards a broader Open Finance ecosystem in which customer consent could enable access to financial information beyond payment accounts. The market is therefore developing in two parallel directions: Strengthening the infrastructure created under PSD2 while expanding the range of financial data that can support future services and decisions.
From Open Banking to Open Banking 2.0
PSD2 created the legal foundation for Open Banking in the EU. It allows consumers and businesses to give consent for regulated third-party providers to access payment account information. It also enabled payment initiation services and introduced stronger security requirements.
These changes supported greater competition and allowed financial services to be developed beyond the interfaces of an individual bank. Open Banking has since developed from a regulatory initiative into an established part of the EU financial ecosystem, supporting payments, financial management, onboarding, income verification, and other data-driven financial processes.
Since PSD2 became applicable, Open Banking has developed significantly. Digital payments have expanded, embedded finance has become more established, customers increasingly expect real-time services, and fraud methods have grown more sophisticated.
At the same time, early challenges around API performance, authentication journeys, technical implementation and customer adoption shaped the first phase of Open Banking, while implementation under the directive-based framework developed differently across institutions and Member States.
This flexibility supported innovation, but also contributed to uneven conditions across Europe. The next phase is therefore about creating greater consistency, clearer operational rules and a more harmonised framework that reflects how the market works today. This is the context behind Open Banking 2.0.
The Next Regulatory Framework: PSD3 and PSR
The European Commission proposed PSD3 and PSR as part of a broader modernisation of the EU payment services framework. Together, they are intended to address payment fraud, strengthen consumer protection, improve competition, increase transparency, and create more consistent conditions for payment services and Open Banking across the EU.
What is PSD3?
PSD3 is the directive governing the authorisation, organisation and supervision of payment and electronic money institutions. It sets out which institutions require authorisation, which organisational and governance requirements they must meet, and how national competent authorities will supervise them. As a directive, PSD3 must be transposed into the national legislation of each EU Member State.
One important change is the move towards a more unified framework for payment institutions and electronic money institutions, which have historically operated under separate EU regimes. PSD3 also strengthens requirements around governance, safeguarding, outsourcing and cross-border activity.
What is PSR?
PSR is the regulation containing many of the operational rules governing how payment services are provided and used. Its scope includes rights and obligations, consumer protection, transparency, fraud prevention and the conditions under which account information and payment initiation services operate.
For Open Banking, PSR is intended to create clearer and more consistent conditions for regulated third-party providers accessing payment accounts, while addressing some of the operational barriers and differences that emerged under PSD2.
Unlike PSD3, PSR will be directly applicable across the EU once the relevant transition period has passed. This is intended to reduce differences in how operational payment rules are interpreted and implemented between the EU Member States.
How PSD3 and PSR Could Shape Open Banking 2.0
The PSD3 and PSR reform is expected to introduce stronger fraud controls, clearer responsibilities, more harmonised operational rules and improved conditions for regulated third-party providers across the EU. Together, these changes address several of the weaknesses that shaped the first phase of Open Banking, where API performance, authentication journeys and implementation often varied between banks and markets.
This could mark an important shift in the role of Open Banking. The next phase: Open Banking 2.0 is more about making access reliable enough to support services at scale. The new regulation creates the conditions for that transition, but financial institutions and technology providers still need to improve infrastructure, customer journeys, data quality and the integration of account information into real financial processes.
Open Banking 2.0 will therefore be defined by whether that access can become dependable, usable and embedded into everyday financial infrastructure.
Timeline: What Will Happen Next?
The Council and the European Parliament reached a provisional political agreement on PSD3 and PSR on 27 November 2025. The negotiated texts were subsequently approved by the European Parliament's Committee on Economic and Monetary Affairs on 5 May 2026. As of August 2026, the legislative package is classified as close to adoption, but still requires the remaining formal steps before publication and entry into force.
Under the current compromise text, most provisions of PSR would apply 21 months after the regulation enters into force. Certain requirements, including verification of the payee and the related liability framework, would apply after 27 months. The final calendar dates will therefore depend on when the legislation is formally adopted and published.
The Next Expansion of Financial Data Sharing
As Open Banking matures, financial data sharing is beginning to expand beyond payment accounts. Open Finance extends consent-based data sharing to a broader range of financial information, including savings, investments, mortgages, pensions, and insurance.
The distinction is significant. Open Banking may show that a customer pays an insurance premium each month, while Open Finance could provide information about the policy itself, including its coverage and terms.
This creates the potential for a more complete and current view of a customer's financial position. For financial institutions, broader financial data could support more personalised services, stronger financial planning, and more informed risk and affordability assessments.
The objective is not simply to collect more information, but to integrate relevant data, accessed, into core decision processes. At the same time, broader access increases the requirements for security, governance, consent management, and responsible use. Institutions must be able to demonstrate which data is being accessed, for which purpose, and how it contributes to the service or decision being provided.
FiDA: The Regulatory Framework for Open Finance
FiDA, the proposed Financial Data Access Regulation, is intended to establish the regulatory framework for this development. By defining the rights and responsibilities of data holders and data users, and by setting requirements for customer consent and technical access, FiDA aims to create the conditions required for Open Finance to develop in a secure, structured, and scalable way.
The European Commission presented the FiDA proposal alongside PSD3 and PSR on 28 June 2023. The European Parliament adopted its negotiating position in April 2024, the Council agreed its position in December 2024, and interinstitutional negotiations began in 2025.
Unlike PSD3 and PSR, FiDA has not yet reached a final political agreement. Its final scope, transition periods, and application date have therefore not yet been confirmed.
Conclusion
Open Banking is moving from regulatory access towards more mature financial infrastructure. PSD2 established the foundation, while PSD3 and PSR are intended to create more consistent conditions for Open Banking 2.0 across the EU. In parallel, FiDA and Open Finance could extend consent-based data sharing beyond payment accounts. For financial institutions, the opportunity is not simply to access more data, but to build the operational capability required to structure, verify, and integrate that information into reliable and traceable financial decisions.
References
European Commission, Proposal for a Regulation on a framework for Financial Data Access (FiDA), COM(2023) 360 final, 28 June 2023. https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:52023PC0360
EUR-Lex, Procedure file 2023/0209 (COD) – PSD3. https://eur-lex.europa.eu/procedure/EN/2023_209
European Parliament, Legislative Train Schedule – Revision of EU rules on payment services (PSD3/PSR). https://www.europarl.europa.eu/legislative-train/theme-an-economy-that-works-for-people/file-revision-of-eu-rules-on-payment-services
European Parliament, Legislative Train Schedule – New open finance framework (FiDA). https://www.europarl.europa.eu/legislative-train/spotlight-JD%2023-24/file-new-open-finance-frameworkb