Open Banking Trends 2026: Data Access, Payments, and What Comes Next

Infographic titled Open Banking Trends 2026 showing one billion UK open banking payments, 2.81 billion API calls in June 2026, variable recurring payments at 16% of transactions, and 95-plus jurisdictions with open banking frameworks, plus regional status for the UK, EU and US.

Open banking has stopped being a promise and started being infrastructure. But not evenly, and not everywhere. In July 2026, the UK ecosystem passed one billion cumulative payments and 100 billion API calls, roughly eight years after launch. In the EU, the current rulebook (PSD2) is being replaced by a tougher one. In the United States, the rule that was meant to turn data sharing into a legal right has been blocked in court and sent back for a rewrite.

That split matters for you. If you build, buy, or sell financial products, the question in 2026 is no longer whether open banking will happen. It is which version of it you will have to operate in, and who pays for it.

This guide covers where the numbers actually stand, why data access suddenly has a price tag, how account-to-account payments became the fastest-moving part of the market, and what belongs on your roadmap this year.

Key Takeaways

  • The UK crossed one billion open banking payments and 100 billion API calls in mid-2026, with 2.81 billion API calls in June 2026 alone.
  • Variable recurring payments (VRPs) are the growth engine: nearly one in five UK open banking payments in June 2026, and still climbing while one-off payments flatten.
  • The EU is moving from PSD2 to PSD3 and the PSR. The broader open finance regulation (FiDA) is still being negotiated and will land later.
  • In the US, the CFPB’s Section 1033 rule is blocked by a court and under reconsideration. It exists on paper but is not being enforced.
  • Free data access is over: JPMorgan Chase now charges data aggregators, and Plaid, Yodlee, Morningstar and Akoya have all signed paid agreements.
  • Open banking activity now spans 95 jurisdictions, with binding rules in 60 of them, which makes market-by-market planning unavoidable.

What Open Banking Actually Means in 2026

Open banking is a simple idea wrapped in complicated rules. With your explicit consent, your bank shares account data with a licensed third party through a standardised API (an application programming interface, the technical doorway one piece of software uses to talk to another). Or the bank lets that third party start a payment from your account. The bank still holds the account. The third party builds something new on top: a budgeting app, a lending decision, a checkout button.

Two things have changed since the early hype years.

First, the centre of gravity shifted from data to payments. Account aggregation, meaning the pulling together of balances and transactions from several banks into one view, is now table stakes. The commercial energy is in account-to-account transfers. Second, the conversation moved from access to economics. For years the assumption was that data access would be free because regulation required it. In 2026 that assumption is being tested in court, in contract negotiations, and on pricing pages.

Neon-lit fintech showroom illustration where people use touchscreen terminals under a large Open Banking sign

If you want the wider context around this shift, our overview of fintech trends shaping the industry sets out how open banking fits alongside embedded products, digital wallets and AI-driven underwriting.

Open Banking Trends 2026: The Numbers That Matter

Market-size forecasts for open banking vary wildly. Depending on which analyst you ask, the 2026 market is worth tens of billions of dollars more or less, and the projected growth rates are just as far apart. Treat those figures as direction, not precision. The useful numbers are the operational ones.

The UK: the most measurable market

The UK publishes monthly performance data through Open Banking Limited, the body that runs the UK standard. That makes it the clearest window into real adoption. The June 2026 figures:

  • 2.81 billion API calls, a record month and up 4.4% on May.
  • 40.16 million payments, of which 32.43 million were single domestic payments (down 1.2%) and 7.73 million were sweeping VRPs (up 6.7%).
  • 18.81 million user connections, down 4.2% month on month. That is a reminder that consent renewal and churn are real friction points.
  • 99.80% weighted availability and a 349ms average response time, 50ms faster than the previous period.

Read those together and the story is clear. Traffic and reliability are rising, one-off payments have plateaued, and recurring payments are carrying the growth. Sweeping VRPs made up around 19% of all UK open banking payments in June 2026, up from roughly 16% at the end of 2025.

Europe: PSD2 is being replaced

The EU is mid-transition. PSD2, the Payment Services Directive that created open banking in Europe in 2018, is being replaced by a two-part package. Parliament and Council reached provisional political agreement on it in late November 2025.

PSD3 is a directive that handles licensing and supervision of payment firms. The Payment Services Regulation (PSR) applies conduct rules directly across member states. It covers fraud liability, strong customer authentication, confirmation of payee (checking that the account name matches the account number before money moves), permission dashboards that show customers which apps can access their data, and, importantly, enforceable API performance standards.

Formal adoption and publication in the EU’s Official Journal were still pending as of mid-2026. The PSR then applies after a transition period of well over a year, which puts most of the real-world impact in 2028. The separate Financial Data Access Regulation (FiDA) would extend open banking logic to pensions, insurance, investments and mortgages. It is further behind: trilogue talks (the three-way negotiation between Parliament, Council and Commission) were still running in mid-2026 without a final deal. Because FiDA phases in sector by sector after adoption, most of its obligations will not bite before the end of the decade.

The United States: a rule on paper

The CFPB (Consumer Financial Protection Bureau, the US consumer finance regulator) finalised its Personal Financial Data Rights rule under Section 1033 of the Dodd-Frank Act in October 2024. Phased compliance was due to start on 1 April 2026 for the largest data providers. That deadline came and went without becoming a binding trigger.

A federal court in the Eastern District of Kentucky blocked enforcement. The CFPB told the court it now considers the rule unlawful, opened an advance notice of proposed rulemaking in August 2025, and sent a revised proposal to the White House’s regulatory review office (OIRA) in August 2026. As of September 2026, that proposal has not been published. Among the questions reopened: who counts as an authorised third party, whether banks may charge for access, what data security is required, and what privacy protections should apply.

The practical takeaway for US teams is that the live regulatory state matters more than the rulebook. Several states have started legislating in the gap, which raises the prospect of a patchwork rather than a single national standard. That dynamic will feel familiar if you have dealt with data localization laws across jurisdictions.

Futuristic city of bank buildings linked by glowing network lines in the sky, symbolising connected digital banking

Regional snapshot

RegionStatus in 2026What to watch
United KingdomMature, mandated, measured monthlyCommercial VRP rollout under the UK Payments Initiative; new FCA rule-making powers
European UnionPSD2 in force, PSD3/PSR agreed and awaiting formal adoptionAPI performance obligations; FiDA timeline
United StatesSection 1033 blocked by court and under rewriteRevised CFPB proposal; state-level rules; access fees
Rest of world95 jurisdictions with open banking activity, 60 with binding rulesMarket-by-market standards, not one global spec

Who Pays for Data Access? The New Economics

This is the most consequential shift of the past 18 months, and it barely existed as a topic in earlier coverage of open banking.

In mid-2025, JPMorgan Chase announced it would start charging data aggregators for API access. Aggregators are the middlemen, such as Plaid, that connect thousands of apps to thousands of banks so each app does not have to build every connection itself. The bank’s argument was volume and cost. It reported 1.89 billion data requests in June 2025 alone, with only a small fraction tied to a customer actively doing something in an app. Serving that traffic securely, it argued, is a real infrastructure expense.

The fintech industry pushed back hard. Its position: charging for consumer-directed data access is anti-competitive and contrary to the law. Then Plaid signed. In September 2025 the two companies announced an agreement, and JPMorgan went on to sign updated contracts with Yodlee, Morningstar and Akoya as well. Together those four handle more than 95% of the data requests hitting the bank’s systems. Contract terms were not disclosed. Fees reportedly vary by use case and grow with data volume.

Three consequences worth planning around:

  • Cost moves into your unit economics. If your product calls bank APIs on a schedule, polling frequency is now a line item, not a technical detail. An app that refreshes every account four times a day pays four times as much as one that refreshes when the user opens it.
  • Scale becomes an advantage. Large aggregators can absorb fees; smaller ones may not, which points toward consolidation.
  • Data minimisation pays. Pulling only what you need, only when you need it, is suddenly a cost strategy as well as a privacy one. It is the same logic behind a well-run first-party data strategy.

City skyline at sunset with a large glowing padlock and security icons on digital billboards, representing fintech security

From Data to Payments: A2A, Pay by Bank and VRPs

The original open banking pitch was better budgeting apps. The commercial reality in 2026 is payments.

Account-to-account (A2A) payments move money directly between bank accounts, skipping the card networks. For merchants, the appeal is cost. Every card payment carries an interchange fee, a percentage the merchant’s bank pays to the cardholder’s bank, and A2A avoids it. For consumers, the appeal is speed and fewer stored card details. At checkout, this usually appears as a “pay by bank” button.

Variable recurring payments are the piece that makes this useful for everyday billing. A VRP lets you authorise a third party to take payments within limits you set upfront: a maximum per transaction, a maximum per month, a defined purpose. Compared with a direct debit, control sits with you rather than the biller, and cancelling does not require the biller’s cooperation.

Most of today’s UK VRPs are “sweeping”: automated transfers between your own accounts, such as moving surplus cash into savings or paying down an overdraft. The commercial version, where a VRP replaces a card-on-file subscription or a direct debit, launched in June 2026 under an industry-owned scheme called the UK Payments Initiative. Its 31 founding members include major banks such as Nationwide and NatWest alongside fintechs like GoCardless, TrueLayer and Plaid. The first wave covers energy, utilities, telecoms, regulated financial services, government and charities. General e-commerce is expected to follow in late 2026.

If you run recurring billing, this is worth watching closely. Card declines and expired cards are a quiet source of involuntary churn. Giving customers visible, revocable control over recurring charges addresses one of the trust problems behind subscription fatigue. It also sits alongside the broader shift toward flexible payment options such as buy now, pay later at checkout.

Neon-lit financial district at night with bank signage and finance data on large screens above busy streets

Mobile checkout is where most of this plays out in practice. That is why A2A adoption tracks closely with the patterns covered in our guide to mobile commerce trends.

How Open Banking APIs Actually Work

Underneath the policy debate, the plumbing is straightforward. Three broad API families do most of the work:

  • Account information APIs read balances, transaction history and account details.
  • Payment initiation APIs trigger a transfer from the customer’s account with their authorisation.
  • Product APIs expose terms, rates and eligibility for the bank’s own products.

What separates a good implementation from a frustrating one is rarely the endpoint list. It is availability, response time, consent duration, and how gracefully re-authentication is handled. The UK’s 99.8% availability and sub-350ms response times set a benchmark that many markets have not yet reached. The EU’s PSR is explicitly trying to close that gap by making API performance a regulated obligation rather than a best effort.

Neon network diagram with a central bank icon linked to smaller bank, house and padlock icons over a city skyline

For banks, exposing these APIs is also a business model decision, not just compliance. That framing, infrastructure as a product, is the same one explored in our piece on the API economy. It increasingly overlaps with embedded finance, where non-financial brands surface banking services inside their own products.

What It Changes for Customer Experience

The consumer-facing benefits of open banking are real but narrower than early marketing suggested. Three hold up well:

  • Faster onboarding. Verifying an account and its balance through an API takes seconds instead of days of micro-deposits or document uploads.
  • Better affordability decisions. Lenders reading real cash-flow data can approve people that traditional credit files miss. That is the strongest financial-inclusion argument open banking has, and it is reshaping peer-to-peer lending as much as bank lending.
  • Consolidated views. Aggregated dashboards let people see accounts across institutions in one place.

What has not materialised is mass consumer demand for “open banking” as a concept. People adopt the product, not the plumbing. That is worth remembering when you plan messaging, and it is the same lesson that runs through current customer experience trends.

On the back end, the value depends on what you do with consented data once you have it. Feeding it into a single customer view is where most of the return sits. Our guide to customer data platforms makes that case in detail.

Security, Consent and Trust

Sharing account data through APIs concentrates risk, and 2026 has not made that easier. The core controls have not changed:

  • Strong customer authentication to confirm identity with multiple factors, such as a password plus a code on your phone.
  • Tokenisation, which replaces your real login details with a substitute code so credentials are never handed to third parties.
  • Encryption in transit and at rest.
  • Scoped, time-limited consent with a clear revocation path.

What has changed is scrutiny of the consent layer itself. Regulators on both sides of the Atlantic are asking harder questions about how long access lasts, how clearly it is explained, and what happens to data after a user disconnects an app. Building a defensible answer now is cheaper than retrofitting one. It maps directly onto the governance work described in our privacy compliance framework and the wider data privacy trends for 2026.

Open vault door with a glowing orange padlock against a blue circuit-board background, symbolising data security

Identity is the adjacent problem. If open banking makes account verification instant, the weak link becomes proving the person behind the account is who they claim to be. That is the gap that decentralized identity and biometric payment systems are both trying to close.

Challenges and Limits

Open banking still has structural problems that eight years of iteration have not solved.

Awareness stays low. Most consumers who use open banking do not know they are using it. That is fine for adoption but bad for trust: people cannot meaningfully consent to something they cannot name.

Consent churn is real. The UK’s declining user-connection count alongside rising API traffic suggests re-authentication cycles are dropping people out. Every re-consent prompt is a chance to lose a customer.

Economics are unsettled. Until the fee question resolves, anyone building on aggregated data is exposed to pricing they do not control.

Fragmentation is the default. With frameworks in dozens of jurisdictions and no shared global standard, multi-market products need per-market work. Compliance tooling helps (see our overview of regtech solutions), but it does not eliminate the effort.

Smaller institutions are stretched. Meeting API performance obligations takes engineering capacity that community banks and credit unions often do not have spare.

What to Do Now: A Practical Checklist

If open banking touches your roadmap, these five moves hold up regardless of how the regulation lands:

  1. Audit your data calls. Know how often you poll, why, and what it would cost if every request carried a fee. Cut anything that is not tied to a user action or a real business need.
  2. Treat consent as a product surface. Design the grant, the dashboard and the revoke flow properly. Re-consent friction is a churn driver you can measure.
  3. Pilot A2A before you need it. Even a single low-risk flow (refunds, account funding, invoice payment) builds the operational knowledge you will want when commercial VRPs reach your sector.
  4. Diversify aggregator exposure. Depending on a single provider is a concentration risk while pricing and coverage are still moving.
  5. Track the live state, not the rulebook. In the US especially, what is enforceable differs from what is written. Assign someone to own that watch, and connect it to your data governance strategy so decisions are documented.

Finance teams should also fold this into wider automation planning, since consented bank data feeds reconciliation and forecasting directly. That is the ground covered in our guide to finance automation trends.

Conclusion

Open banking in 2026 is a story of divergence. The UK has a working, measurable ecosystem where recurring payments are pulling growth. The EU has agreed a stricter framework that will bite in 2028 and beyond. The US has a rule that exists on paper and a live fight over who pays for access.

The strategic point is the same in all three. The technology question is settled; the economics and the consent experience are not. Whoever gets those two right (clear permission, minimal data, sensible cost) will own the products people actually use. Everything else is plumbing, and plumbing has a way of becoming invisible right at the moment it becomes essential. Trust is the differentiator, which is exactly why digital trust keeps surfacing as a business model question rather than a technical one.

Last reviewed: September 2026. Regulatory status changes quickly. Confirm current requirements with qualified counsel before acting.

Found this useful?

Make SmartKeys a preferred source on Google, and our articles will surface more often in your Top Stories, AI Overviews, and AI Mode.

Add as Preferred Source

FAQ

What is open banking in simple terms?

Open banking lets you authorise a licensed third party to access your bank account data, or to start a payment from your account, through a secure API. Your bank still holds the account and the money. The third party builds a service on top of it, such as a budgeting app that shows all your accounts in one place, a lender that reads your real cash flow before deciding, or a pay-by-bank button at checkout. You decide what to share, with whom, and for how long, and you can withdraw that permission at any time.

Is the US open banking rule in force in 2026?

No. The CFPB finalised its Section 1033 rule in October 2024 with compliance due to start in April 2026, but a federal court in Kentucky blocked enforcement and the CFPB is rewriting the rule. A revised proposal went to the White House regulatory review office (OIRA) in August 2026 and had not been published as of September 2026. The rule exists on paper but is not currently enforceable. In practice, US data sharing runs on private contracts between banks and aggregators, and several states are drafting their own rules.

What are variable recurring payments (VRPs)?

A VRP lets you authorise a third party to take multiple payments within limits you set in advance, such as a cap per transaction and per month. Unlike a direct debit, control stays with you and you can revoke it without the biller’s involvement. In the UK, sweeping VRPs (transfers between your own accounts) reached 7.73 million transactions in June 2026. Commercial VRPs, which let a business collect recurring payments from customers as an alternative to direct debit or card-on-file, launched in June 2026 under the UK Payments Initiative scheme.

Do banks charge for open banking data access?

In the US, increasingly yes. JPMorgan Chase began charging data aggregators in 2025 and has signed paid agreements with Plaid, Yodlee, Morningstar and Akoya, which together handle more than 95% of the data requests to the bank. Contract terms were not disclosed, but fees reportedly vary by use case and grow with volume. Whether fees are permitted at all is one of the open questions in the CFPB’s rewrite of the Section 1033 rule. Under current UK and EU rules, banks must provide regulated open banking access without charging third parties.

How is Europe replacing PSD2?

PSD2 is being succeeded by two texts. PSD3 is a directive that covers licensing and supervision of payment firms. The Payment Services Regulation (PSR) applies conduct rules directly across member states, including API performance obligations, fraud liability, confirmation of payee and permission dashboards for customers. Political agreement was reached in November 2025. Formal adoption and publication in the Official Journal were still pending in mid-2026, and the PSR applies only after a transition period, so most obligations bite in 2028.

What is open finance and how is it different?

Open finance extends the same consent-based access model beyond payment accounts to savings, investments, pensions, insurance and mortgages. Where open banking lets an app see your current account, open finance would let it see your whole financial picture, with your permission. In the EU this is the goal of the Financial Data Access Regulation (FiDA), which was still under negotiation in mid-2026 and is expected to phase in sector by sector after adoption, with most obligations arriving toward the end of the decade.

What are the biggest risks for businesses using open banking?

The main risks are unsettled data-access pricing, dependency on a single aggregator, consent churn when users have to re-authenticate, and regulatory fragmentation across the dozens of jurisdictions with their own frameworks. Data minimisation reduces exposure to pricing, multi-provider coverage reduces dependency risk, and a well-designed consent flow reduces churn. For the regulatory patchwork, the practical answer is to assign someone to track the live state of the rules in each market you serve.

Author

  • Felix Römer

    Felix is the founder of SmartKeys.org, where he explores the future of work, SaaS innovation, and productivity strategies. With over 15 years of experience in e-commerce and digital marketing, he combines hands-on expertise with a passion for emerging technologies. Through SmartKeys, Felix shares actionable insights designed to help professionals and businesses work smarter, adapt to change, and stay ahead in a fast-moving digital world. Connect with him on LinkedIn