Open banking has stopped being a promise and started being infrastructure. But not evenly, and not everywhere. In July 2026, the UK ecosystem passed one billion cumulative payments and 100 billion API calls, roughly eight years after launch. In the EU, the current rulebook (PSD2) is being replaced by a tougher one. In the United States, the rule that was meant to turn data sharing into a legal right has been blocked in court and sent back for a rewrite.
That split matters for you. If you build, buy, or sell financial products, the question in 2026 is no longer whether open banking will happen. It is which version of it you will have to operate in, and who pays for it.
This guide covers where the numbers actually stand, why data access suddenly has a price tag, how account-to-account payments became the fastest-moving part of the market, and what belongs on your roadmap this year.
Key Takeaways
- The UK crossed one billion open banking payments and 100 billion API calls in mid-2026, with 2.81 billion API calls in June 2026 alone.
- Variable recurring payments (VRPs) are the growth engine: nearly one in five UK open banking payments in June 2026, and still climbing while one-off payments flatten.
- The EU is moving from PSD2 to PSD3 and the PSR. The broader open finance regulation (FiDA) is still being negotiated and will land later.
- In the US, the CFPB’s Section 1033 rule is blocked by a court and under reconsideration. It exists on paper but is not being enforced.
- Free data access is over: JPMorgan Chase now charges data aggregators, and Plaid, Yodlee, Morningstar and Akoya have all signed paid agreements.
- Open banking activity now spans 95 jurisdictions, with binding rules in 60 of them, which makes market-by-market planning unavoidable.
What Open Banking Actually Means in 2026
Open banking is a simple idea wrapped in complicated rules. With your explicit consent, your bank shares account data with a licensed third party through a standardised API (an application programming interface, the technical doorway one piece of software uses to talk to another). Or the bank lets that third party start a payment from your account. The bank still holds the account. The third party builds something new on top: a budgeting app, a lending decision, a checkout button.
Two things have changed since the early hype years.
First, the centre of gravity shifted from data to payments. Account aggregation, meaning the pulling together of balances and transactions from several banks into one view, is now table stakes. The commercial energy is in account-to-account transfers. Second, the conversation moved from access to economics. For years the assumption was that data access would be free because regulation required it. In 2026 that assumption is being tested in court, in contract negotiations, and on pricing pages.

If you want the wider context around this shift, our overview of fintech trends shaping the industry sets out how open banking fits alongside embedded products, digital wallets and AI-driven underwriting.
Open Banking Trends 2026: The Numbers That Matter
Market-size forecasts for open banking vary wildly. Depending on which analyst you ask, the 2026 market is worth tens of billions of dollars more or less, and the projected growth rates are just as far apart. Treat those figures as direction, not precision. The useful numbers are the operational ones.
The UK: the most measurable market
The UK publishes monthly performance data through Open Banking Limited, the body that runs the UK standard. That makes it the clearest window into real adoption. The June 2026 figures:
- 2.81 billion API calls, a record month and up 4.4% on May.
- 40.16 million payments, of which 32.43 million were single domestic payments (down 1.2%) and 7.73 million were sweeping VRPs (up 6.7%).
- 18.81 million user connections, down 4.2% month on month. That is a reminder that consent renewal and churn are real friction points.
- 99.80% weighted availability and a 349ms average response time, 50ms faster than the previous period.
Read those together and the story is clear. Traffic and reliability are rising, one-off payments have plateaued, and recurring payments are carrying the growth. Sweeping VRPs made up around 19% of all UK open banking payments in June 2026, up from roughly 16% at the end of 2025.
Europe: PSD2 is being replaced
The EU is mid-transition. PSD2, the Payment Services Directive that created open banking in Europe in 2018, is being replaced by a two-part package. Parliament and Council reached provisional political agreement on it in late November 2025.
PSD3 is a directive that handles licensing and supervision of payment firms. The Payment Services Regulation (PSR) applies conduct rules directly across member states. It covers fraud liability, strong customer authentication, confirmation of payee (checking that the account name matches the account number before money moves), permission dashboards that show customers which apps can access their data, and, importantly, enforceable API performance standards.
Formal adoption and publication in the EU’s Official Journal were still pending as of mid-2026. The PSR then applies after a transition period of well over a year, which puts most of the real-world impact in 2028. The separate Financial Data Access Regulation (FiDA) would extend open banking logic to pensions, insurance, investments and mortgages. It is further behind: trilogue talks (the three-way negotiation between Parliament, Council and Commission) were still running in mid-2026 without a final deal. Because FiDA phases in sector by sector after adoption, most of its obligations will not bite before the end of the decade.
The United States: a rule on paper
The CFPB (Consumer Financial Protection Bureau, the US consumer finance regulator) finalised its Personal Financial Data Rights rule under Section 1033 of the Dodd-Frank Act in October 2024. Phased compliance was due to start on 1 April 2026 for the largest data providers. That deadline came and went without becoming a binding trigger.
A federal court in the Eastern District of Kentucky blocked enforcement. The CFPB told the court it now considers the rule unlawful, opened an advance notice of proposed rulemaking in August 2025, and sent a revised proposal to the White House’s regulatory review office (OIRA) in August 2026. As of September 2026, that proposal has not been published. Among the questions reopened: who counts as an authorised third party, whether banks may charge for access, what data security is required, and what privacy protections should apply.
The practical takeaway for US teams is that the live regulatory state matters more than the rulebook. Several states have started legislating in the gap, which raises the prospect of a patchwork rather than a single national standard. That dynamic will feel familiar if you have dealt with data localization laws across jurisdictions.

Regional snapshot
| Region | Status in 2026 | What to watch |
|---|---|---|
| United Kingdom | Mature, mandated, measured monthly | Commercial VRP rollout under the UK Payments Initiative; new FCA rule-making powers |
| European Union | PSD2 in force, PSD3/PSR agreed and awaiting formal adoption | API performance obligations; FiDA timeline |
| United States | Section 1033 blocked by court and under rewrite | Revised CFPB proposal; state-level rules; access fees |
| Rest of world | 95 jurisdictions with open banking activity, 60 with binding rules | Market-by-market standards, not one global spec |
Who Pays for Data Access? The New Economics
This is the most consequential shift of the past 18 months, and it barely existed as a topic in earlier coverage of open banking.
In mid-2025, JPMorgan Chase announced it would start charging data aggregators for API access. Aggregators are the middlemen, such as Plaid, that connect thousands of apps to thousands of banks so each app does not have to build every connection itself. The bank’s argument was volume and cost. It reported 1.89 billion data requests in June 2025 alone, with only a small fraction tied to a customer actively doing something in an app. Serving that traffic securely, it argued, is a real infrastructure expense.
The fintech industry pushed back hard. Its position: charging for consumer-directed data access is anti-competitive and contrary to the law. Then Plaid signed. In September 2025 the two companies announced an agreement, and JPMorgan went on to sign updated contracts with Yodlee, Morningstar and Akoya as well. Together those four handle more than 95% of the data requests hitting the bank’s systems. Contract terms were not disclosed. Fees reportedly vary by use case and grow with data volume.
Three consequences worth planning around:
- Cost moves into your unit economics. If your product calls bank APIs on a schedule, polling frequency is now a line item, not a technical detail. An app that refreshes every account four times a day pays four times as much as one that refreshes when the user opens it.
- Scale becomes an advantage. Large aggregators can absorb fees; smaller ones may not, which points toward consolidation.
- Data minimisation pays. Pulling only what you need, only when you need it, is suddenly a cost strategy as well as a privacy one. It is the same logic behind a well-run first-party data strategy.

From Data to Payments: A2A, Pay by Bank and VRPs
The original open banking pitch was better budgeting apps. The commercial reality in 2026 is payments.
Account-to-account (A2A) payments move money directly between bank accounts, skipping the card networks. For merchants, the appeal is cost. Every card payment carries an interchange fee, a percentage the merchant’s bank pays to the cardholder’s bank, and A2A avoids it. For consumers, the appeal is speed and fewer stored card details. At checkout, this usually appears as a “pay by bank” button.
Variable recurring payments are the piece that makes this useful for everyday billing. A VRP lets you authorise a third party to take payments within limits you set upfront: a maximum per transaction, a maximum per month, a defined purpose. Compared with a direct debit, control sits with you rather than the biller, and cancelling does not require the biller’s cooperation.
Most of today’s UK VRPs are “sweeping”: automated transfers between your own accounts, such as moving surplus cash into savings or paying down an overdraft. The commercial version, where a VRP replaces a card-on-file subscription or a direct debit, launched in June 2026 under an industry-owned scheme called the UK Payments Initiative. Its 31 founding members include major banks such as Nationwide and NatWest alongside fintechs like GoCardless, TrueLayer and Plaid. The first wave covers energy, utilities, telecoms, regulated financial services, government and charities. General e-commerce is expected to follow in late 2026.
If you run recurring billing, this is worth watching closely. Card declines and expired cards are a quiet source of involuntary churn. Giving customers visible, revocable control over recurring charges addresses one of the trust problems behind subscription fatigue. It also sits alongside the broader shift toward flexible payment options such as buy now, pay later at checkout.

Mobile checkout is where most of this plays out in practice. That is why A2A adoption tracks closely with the patterns covered in our guide to mobile commerce trends.
How Open Banking APIs Actually Work
Underneath the policy debate, the plumbing is straightforward. Three broad API families do most of the work:
- Account information APIs read balances, transaction history and account details.
- Payment initiation APIs trigger a transfer from the customer’s account with their authorisation.
- Product APIs expose terms, rates and eligibility for the bank’s own products.
What separates a good implementation from a frustrating one is rarely the endpoint list. It is availability, response time, consent duration, and how gracefully re-authentication is handled. The UK’s 99.8% availability and sub-350ms response times set a benchmark that many markets have not yet reached. The EU’s PSR is explicitly trying to close that gap by making API performance a regulated obligation rather than a best effort.

For banks, exposing these APIs is also a business model decision, not just compliance. That framing, infrastructure as a product, is the same one explored in our piece on the API economy. It increasingly overlaps with embedded finance, where non-financial brands surface banking services inside their own products.
What It Changes for Customer Experience
The consumer-facing benefits of open banking are real but narrower than early marketing suggested. Three hold up well:
- Faster onboarding. Verifying an account and its balance through an API takes seconds instead of days of micro-deposits or document uploads.
- Better affordability decisions. Lenders reading real cash-flow data can approve people that traditional credit files miss. That is the strongest financial-inclusion argument open banking has, and it is reshaping peer-to-peer lending as much as bank lending.
- Consolidated views. Aggregated dashboards let people see accounts across institutions in one place.
What has not materialised is mass consumer demand for “open banking” as a concept. People adopt the product, not the plumbing. That is worth remembering when you plan messaging, and it is the same lesson that runs through current customer experience trends.
On the back end, the value depends on what you do with consented data once you have it. Feeding it into a single customer view is where most of the return sits. Our guide to customer data platforms makes that case in detail.
Security, Consent and Trust
Sharing account data through APIs concentrates risk, and 2026 has not made that easier. The core controls have not changed:
- Strong customer authentication to confirm identity with multiple factors, such as a password plus a code on your phone.
- Tokenisation, which replaces your real login details with a substitute code so credentials are never handed to third parties.
- Encryption in transit and at rest.
- Scoped, time-limited consent with a clear revocation path.
What has changed is scrutiny of the consent layer itself. Regulators on both sides of the Atlantic are asking harder questions about how long access lasts, how clearly it is explained, and what happens to data after a user disconnects an app. Building a defensible answer now is cheaper than retrofitting one. It maps directly onto the governance work described in our privacy compliance framework and the wider data privacy trends for 2026.

Identity is the adjacent problem. If open banking makes account verification instant, the weak link becomes proving the person behind the account is who they claim to be. That is the gap that decentralized identity and biometric payment systems are both trying to close.
Challenges and Limits
Open banking still has structural problems that eight years of iteration have not solved.
Awareness stays low. Most consumers who use open banking do not know they are using it. That is fine for adoption but bad for trust: people cannot meaningfully consent to something they cannot name.
Consent churn is real. The UK’s declining user-connection count alongside rising API traffic suggests re-authentication cycles are dropping people out. Every re-consent prompt is a chance to lose a customer.
Economics are unsettled. Until the fee question resolves, anyone building on aggregated data is exposed to pricing they do not control.
Fragmentation is the default. With frameworks in dozens of jurisdictions and no shared global standard, multi-market products need per-market work. Compliance tooling helps (see our overview of regtech solutions), but it does not eliminate the effort.
Smaller institutions are stretched. Meeting API performance obligations takes engineering capacity that community banks and credit unions often do not have spare.
What to Do Now: A Practical Checklist
If open banking touches your roadmap, these five moves hold up regardless of how the regulation lands:
- Audit your data calls. Know how often you poll, why, and what it would cost if every request carried a fee. Cut anything that is not tied to a user action or a real business need.
- Treat consent as a product surface. Design the grant, the dashboard and the revoke flow properly. Re-consent friction is a churn driver you can measure.
- Pilot A2A before you need it. Even a single low-risk flow (refunds, account funding, invoice payment) builds the operational knowledge you will want when commercial VRPs reach your sector.
- Diversify aggregator exposure. Depending on a single provider is a concentration risk while pricing and coverage are still moving.
- Track the live state, not the rulebook. In the US especially, what is enforceable differs from what is written. Assign someone to own that watch, and connect it to your data governance strategy so decisions are documented.
Finance teams should also fold this into wider automation planning, since consented bank data feeds reconciliation and forecasting directly. That is the ground covered in our guide to finance automation trends.
Conclusion
Open banking in 2026 is a story of divergence. The UK has a working, measurable ecosystem where recurring payments are pulling growth. The EU has agreed a stricter framework that will bite in 2028 and beyond. The US has a rule that exists on paper and a live fight over who pays for access.
The strategic point is the same in all three. The technology question is settled; the economics and the consent experience are not. Whoever gets those two right (clear permission, minimal data, sensible cost) will own the products people actually use. Everything else is plumbing, and plumbing has a way of becoming invisible right at the moment it becomes essential. Trust is the differentiator, which is exactly why digital trust keeps surfacing as a business model question rather than a technical one.
Last reviewed: September 2026. Regulatory status changes quickly. Confirm current requirements with qualified counsel before acting.
Found this useful?
Make SmartKeys a preferred source on Google, and our articles will surface more often in your Top Stories, AI Overviews, and AI Mode.
Add as Preferred Source







