Open Banking Trends 2026: Data Access, Payments, and What Comes Next

Infographic titled Open Banking Trends 2026 showing one billion UK open banking payments, 2.81 billion API calls in June 2026, variable recurring payments at 16% of transactions, and 95-plus jurisdictions with open banking frameworks, plus regional status for the UK, EU and US.

Last Updated on August 11, 2026

Open banking has stopped being a promise and started being infrastructure — but not evenly, and not everywhere. In July 2026, the UK ecosystem passed one billion cumulative payments and 100 billion API calls, roughly eight years after launch. In the EU, PSD2 is being replaced by a tougher rulebook. In the United States, the rule that was meant to turn data sharing into a legal right has been blocked in court and sent back for a rewrite.

That split matters for you. If you build, buy, or sell financial products, the question in 2026 is no longer whether open banking will happen. It is which version of it you will have to operate in — and who pays for it.

This guide covers where the numbers actually stand, why data access suddenly has a price tag, how account-to-account payments became the fastest-moving part of the market, and what belongs on your roadmap this year.

Key Takeaways

  • The UK crossed one billion open banking payments and 100 billion API calls in mid-2026, with 2.81 billion API calls in June 2026 alone.
  • Variable recurring payments (VRPs) are the growth engine — around 16% of UK open banking transactions and still climbing while one-off payments flatten.
  • The EU is moving from PSD2 to PSD3 and the PSR, with the broader open finance regulation (FiDA) still unresolved and likely to land later.
  • In the US, the CFPB’s Section 1033 rule is enjoined and under reconsideration — it exists on paper but is not being enforced.
  • Free data access is over: JPMorgan Chase now charges aggregators, and Plaid, Yodlee, Morningstar and Akoya have all signed paid agreements.
  • Roughly 95+ jurisdictions now have some form of open banking framework, which makes market-by-market planning unavoidable.

What Open Banking Actually Means in 2026

Open banking is a simple idea wrapped in complicated rules. With your explicit consent, your bank shares account data with a licensed third party through a standardised API — or lets that third party initiate a payment from your account. The bank still holds the account. The third party builds something new on top: a budgeting app, a lending decision, a checkout button.

Two things have changed since the early hype years.

First, the centre of gravity shifted from data to payments. Account aggregation is now table stakes; the commercial energy is in account-to-account transfers. Second, the conversation moved from access to economics. For years the assumption was that data access would be free because regulation required it. In 2026 that assumption is being tested in court, in contract negotiations, and in pricing pages.

Open banking and digital transformation in banking in 2026

If you want the wider context around this shift, our overview of fintech trends shaping the industry sets out how open banking fits alongside embedded products, digital wallets and AI-driven underwriting.

Open Banking Trends 2026: The Numbers That Matter

Market-size forecasts for open banking vary wildly — analyst estimates for 2026 sit anywhere between roughly $26 billion and $43 billion, with projected growth rates from 15% to 28% a year. Treat those figures as direction, not precision. The useful numbers are the operational ones.

The UK: the most measurable market

The UK publishes monthly performance data, which makes it the clearest window into real adoption:

  • 2.81 billion API calls in June 2026 — a record month, up 4.4% on May.
  • 40.16 million payments in the month, of which 32.43 million were single domestic payments (down 1.2%) and 7.73 million were sweeping VRPs (up 6.7%).
  • 18.81 million user connections, down 4.2% month on month — a reminder that consent renewal and churn are real friction points.
  • 99.80% weighted availability and a 349ms average response time, 50ms faster than the previous period.

Read those together and the story is clear: traffic and reliability are rising, one-off payments have plateaued, and recurring payments are carrying the growth.

Europe: PSD2 is being replaced

The EU is mid-transition. Parliament and Council reached provisional political agreement on the payments package in late November 2025. PSD3 handles licensing and supervision as a directive; the Payment Services Regulation (PSR) applies conduct rules directly across member states, covering fraud liability, strong customer authentication, confirmation of payee and — importantly — enforceable API performance standards.

Formal adoption has been expected in 2026, with application after a transition period that puts real-world impact in late 2027 or 2028. The separate Financial Data Access Regulation (FiDA), which would extend open banking logic to pensions, insurance, investments and mortgages, is further behind. Trilogue talks stalled in early 2026, and realistic timelines now point to the end of the decade.

The United States: a rule on paper

The CFPB finalised its Personal Financial Data Rights rule under Section 1033 of Dodd-Frank in October 2024, with phased compliance starting 1 April 2026 for the largest data providers. That deadline came and went without becoming a binding trigger.

A federal court in the Eastern District of Kentucky enjoined enforcement. The CFPB told the court it now considers the rule unlawful, opened an advance notice of proposed rulemaking in August 2025, and sent a revised proposal to OIRA for review in August 2026. Among the questions reopened: who counts as an authorised representative, whether banks may charge for access, and whether the compliance timeline should move.

The practical takeaway for US teams is that the live regulatory state matters more than the rulebook. Several states have started legislating in the gap, which raises the prospect of a patchwork rather than a single national standard — a dynamic that will feel familiar if you have dealt with data localization laws across jurisdictions.

Open banking trends and adoption statistics for 2026

Regional snapshot

RegionStatus in 2026What to watch
United KingdomMature, mandated, measured monthlyCommercial VRP rollout; new FCA rule-making powers
European UnionPSD2 in force, PSD3/PSR agreed and pending applicationAPI performance obligations; FiDA timeline
United StatesSection 1033 enjoined and under rewriteRevised CFPB proposal; state-level rules; access fees
Rest of world95+ jurisdictions with some frameworkMarket-by-market standards, not one global spec

Who Pays for Data Access? The New Economics

This is the most consequential shift of the past 18 months, and it barely existed as a topic in earlier coverage of open banking.

In mid-2025, JPMorgan Chase announced it would start charging data aggregators for API access. The bank’s argument was volume and cost: it reported 1.89 billion data requests in a single month, with only a small fraction tied to a customer actively doing something in an app. Serving that traffic securely, it argued, is a genuine infrastructure expense.

The fintech industry pushed back hard, arguing that charging for consumer-directed data access is anti-competitive and contrary to statute. Then Plaid signed. In September 2025 the two companies announced an agreement, and JPMorgan went on to sign updated contracts with Yodlee, Morningstar and Akoya as well — together covering the large majority of data requests hitting its systems. Reported pricing works out to fractions of a cent per data pull, varying by use case and scaling with volume.

Three consequences worth planning around:

  • Cost moves into your unit economics. If your product calls bank APIs on a schedule, polling frequency is now a line item, not a technical detail.
  • Scale becomes an advantage. Large aggregators can absorb fees; smaller ones may not, which points toward consolidation.
  • Data minimisation pays. Pulling only what you need, only when you need it, is suddenly a cost strategy as well as a privacy one — the same logic behind a well-run first-party data strategy.

Financial technology trends driven by open banking in 2026

From Data to Payments: A2A, Pay by Bank and VRPs

The original open banking pitch was better budgeting apps. The commercial reality in 2026 is payments.

Account-to-account (A2A) payments move money directly between bank accounts, skipping card rails. For merchants, the appeal is cost: card interchange is a meaningful margin drag, and A2A avoids it. For consumers, the appeal is speed and fewer stored card details.

Variable recurring payments are the piece that makes this genuinely useful. A VRP lets you authorise a third party to take payments within limits you set upfront — a maximum per transaction, a maximum per month, a defined purpose. Compared with a direct debit, control sits with you rather than the biller, and cancelling does not require the biller’s cooperation.

Today’s UK VRPs are mostly “sweeping” — automated transfers between your own accounts, such as moving surplus cash into savings or paying down an overdraft. The commercial version, where a VRP replaces a card-on-file subscription, is the next frontier. A commercial VRP scheme backed by dozens of firms including the major UK retail banks was established in late 2025 to make that possible.

If you run recurring billing, this is worth watching closely. Card declines and expired cards are a quiet source of involuntary churn, and giving customers visible, revocable control over recurring charges addresses one of the trust problems behind subscription fatigue. It also sits alongside the broader shift toward flexible payment options such as buy now, pay later at checkout.

Open banking driving payment industry disruption and account-to-account payments

Mobile checkout is where most of this plays out in practice, which is why A2A adoption tracks closely with the patterns covered in our guide to mobile commerce trends.

How Open Banking APIs Actually Work

Underneath the policy debate, the plumbing is straightforward. Three broad API families do most of the work:

  • Account information APIs — read balances, transaction history and account details.
  • Payment initiation APIs — trigger a transfer from the customer’s account with their authorisation.
  • Product APIs — expose terms, rates and eligibility for the bank’s own products.

What separates a good implementation from a frustrating one is rarely the endpoint list. It is availability, response time, consent duration, and how gracefully re-authentication is handled. The UK’s 99.8% availability and sub-350ms response times set a benchmark that many markets have not yet reached, and the EU’s PSR is explicitly trying to close that gap by making API performance a regulated obligation rather than a best effort.

Diagram explaining how open banking APIs connect banks and third-party providers

For banks, exposing these APIs is also a business model decision, not just compliance. That framing — infrastructure as a product — is the same one explored in our piece on the API economy, and it increasingly overlaps with embedded finance, where non-financial brands surface banking services inside their own products.

What It Changes for Customer Experience

The consumer-facing benefits of open banking are real but narrower than early marketing suggested. Three hold up well:

  • Faster onboarding. Verifying an account and its balance through an API takes seconds instead of days of micro-deposits or document uploads.
  • Better affordability decisions. Lenders reading real cash-flow data can approve people that traditional credit files miss, which is the strongest financial-inclusion argument open banking has.
  • Consolidated views. Aggregated dashboards let people see accounts across institutions in one place.

What has not materialised is mass consumer demand for “open banking” as a concept. People adopt the product, not the plumbing. That is worth remembering when you plan messaging — the same lesson that runs through current customer experience trends.

On the back end, the value depends on what you do with consented data once you have it. Feeding it into a single customer view is where most of the return sits, which is the case our guide to customer data platforms makes in detail.

Security, Consent and Trust

Sharing account data through APIs concentrates risk, and 2026 has not made that easier. The core controls have not changed:

  • Strong customer authentication to confirm identity with multiple factors.
  • Tokenisation so credentials are never handed to third parties.
  • Encryption in transit and at rest.
  • Scoped, time-limited consent with a clear revocation path.

What has changed is scrutiny of the consent layer itself. Regulators on both sides of the Atlantic are asking harder questions about how long access lasts, how clearly it is explained, and what happens to data after a user disconnects an app. Building a defensible answer now is cheaper than retrofitting one, and it maps directly onto the governance work described in our privacy compliance framework and the wider data privacy trends for 2026.

Customer data security controls in open banking including encryption and tokenisation

Identity is the adjacent problem. If open banking makes account verification instant, the weak link becomes proving the person behind the account is who they claim to be — the gap that decentralized identity and biometric payment systems are both trying to close.

Challenges and Limits

Open banking still has structural problems that eight years of iteration have not solved.

Awareness stays low. Most consumers who use open banking do not know they are using it. That is fine for adoption but bad for trust: people cannot meaningfully consent to something they cannot name.

Consent churn is real. The UK’s declining user-connection count alongside rising API traffic suggests re-authentication cycles are dropping people out. Every re-consent prompt is a chance to lose a customer.

Economics are unsettled. Until the fee question resolves, anyone building on aggregated data is exposed to pricing they do not control.

Fragmentation is the default. With frameworks in more than 95 jurisdictions and no shared global standard, multi-market products need per-market work. Compliance tooling helps — see our overview of regtech solutions — but it does not eliminate the effort.

Smaller institutions are stretched. Meeting API performance obligations takes engineering capacity that community banks and credit unions often do not have spare.

What to Do Now: A Practical Checklist

If open banking touches your roadmap, these five moves hold up regardless of how the regulation lands:

  1. Audit your data calls. Know how often you poll, why, and what it would cost at a fraction of a cent per request. Cut anything that is not tied to a user action or a genuine business need.
  2. Treat consent as a product surface. Design the grant, the dashboard and the revoke flow properly. Re-consent friction is a churn driver you can measure.
  3. Pilot A2A before you need it. Even a single low-risk flow — refunds, account funding, invoice payment — builds the operational knowledge you will want when commercial VRPs land.
  4. Diversify aggregator exposure. Single-provider dependency is a concentration risk while pricing and coverage are still moving.
  5. Track the live state, not the rulebook. In the US especially, what is enforceable differs from what is written. Assign someone to own that watch, and connect it to your data governance strategy so decisions are documented.

Finance teams should also fold this into wider automation planning, since consented bank data feeds reconciliation and forecasting directly — the ground covered in our guide to finance automation trends.

Conclusion

Open banking in 2026 is a story of divergence. The UK has a working, measurable ecosystem where recurring payments are pulling growth. The EU has agreed a stricter framework that will bite in 2027 and beyond. The US has a rule that exists on paper and a live fight over who pays for access.

The strategic point is the same in all three. The technology question is settled; the economics and the consent experience are not. Whoever gets those two right — clear permission, minimal data, sensible cost — will own the products people actually use. Everything else is plumbing, and plumbing has a way of becoming invisible right at the moment it becomes essential. Trust is the differentiator, which is exactly why digital trust keeps surfacing as a business model question rather than a technical one.

Last reviewed: August 2026. Regulatory status changes quickly — confirm current requirements with qualified counsel before acting.

FAQ

What is open banking in simple terms?

Open banking lets you authorise a licensed third party to access your bank account data, or initiate a payment from it, through a secure API. Your bank still holds the account. The third party builds a service on top of it, such as a budgeting app, a lending decision or a pay-by-bank checkout.

Is the US open banking rule in force in 2026?

No. The CFPB finalised its Section 1033 rule in October 2024 with compliance starting April 2026, but a federal court enjoined enforcement and the CFPB is rewriting it. A revised proposal went to OIRA for review in August 2026. The rule exists on paper but is not currently enforceable.

What are variable recurring payments (VRPs)?

A VRP lets you authorise a third party to take multiple payments within limits you set in advance, such as a cap per transaction and per month. Unlike a direct debit, control stays with you and you can revoke it without the biller’s involvement. In the UK, sweeping VRPs reached 7.73 million transactions in June 2026.

Do banks charge for open banking data access?

In the US, increasingly yes. JPMorgan Chase began charging data aggregators in 2025 and has signed paid agreements with Plaid, Yodlee, Morningstar and Akoya. Reported pricing is fractions of a cent per data pull, varying by use case and volume. Whether fees are permitted at all is one of the open questions in the CFPB’s rewrite.

How is Europe replacing PSD2?

PSD2 is being succeeded by PSD3, which covers licensing and supervision, and the Payment Services Regulation (PSR), which applies conduct rules directly across member states — including API performance obligations, fraud liability and confirmation of payee. Political agreement was reached in late 2025, with application expected after a transition period.

What is open finance and how is it different?

Open finance extends the same consent-based access model beyond payment accounts to savings, investments, pensions, insurance and mortgages. In the EU this is the goal of the Financial Data Access Regulation (FiDA), which remains under negotiation and is expected to apply toward the end of the decade.

What are the biggest risks for businesses using open banking?

The main risks are unsettled data-access pricing, dependency on a single aggregator, consent churn when users have to re-authenticate, and regulatory fragmentation across the 95-plus jurisdictions with their own frameworks. Data minimisation and multi-provider coverage reduce exposure to all four.

Author

  • Felix Römer

    Felix is the founder of SmartKeys.org, where he explores the future of work, SaaS innovation, and productivity strategies. With over 15 years of experience in e-commerce and digital marketing, he combines hands-on expertise with a passion for emerging technologies. Through SmartKeys, Felix shares actionable insights designed to help professionals and businesses work smarter, adapt to change, and stay ahead in a fast-moving digital world. Connect with him on LinkedIn