Open Banking 2027: US vs EU vs UK Reality Check
Three jurisdictions, three regulatory philosophies, and a widening gap in who's actually winning the open banking race in 2027.

[Open banking](/blog/open-banking-uk-vs-us-2027) was supposed to be a global revolution by now. The reality in mid-2027 is more fractured: the UK is consolidating a mature ecosystem, the EU is mid-migration through PSD3, and the United States is still arguing about whether screen-scraping counts as a data right. Each regime has produced genuinely different outcomes — in consumer adoption, third-party provider counts, monetisation models, and infrastructure quality. If you work in fintech, payments, or financial infrastructure, the differences are no longer academic.
This is a ground-level comparison. We'll cover where each jurisdiction stands today, what the next 18 months look like, and — critically — what the regulatory divergence means for platforms and developers building cross-border financial products.
The Starting Scoreboard: Who Actually Has Traction?
Numbers first. As of Q1 2027, the UK's Open Banking Implementation Entity (OBIE) — now operating under the Joint Regulatory Oversight Committee (JROC) framework — counts approximately 11.7 million active open banking users and over 1,000 regulated TPPs (third-party providers). Monthly API call volume exceeded 1.4 billion in March 2027, up from roughly 500 million in early 2023. That is real consumer adoption, not pilot-project statistics.
The EU picture is harder to aggregate because PSD2 implementation was always a patchwork of national competent authorities. Collectively, the eurozone and wider EEA hosted an estimated 6,200 licensed TPPs under PSD2 as of late 2026, per the European Banking Authority's register — but "licensed" is doing enormous work in that sentence. Active TPPs making meaningful API call volumes are a far smaller subset. The Berlin Group's NextGenPSD2 framework and STET in France created fragmented API standards, meaning a TPP licensed in Germany routinely needed custom integrations to access Spanish bank data.
The United States, operating without a true statutory open banking mandate until the CFPB's Section 1033 final rule (published October 2024), had an ecosystem built almost entirely on screen-scraping and bilateral data-sharing agreements brokered by aggregators like Plaid, MX, and Akoya. The CFPB reported in its 2026 consumer financial data access report that approximately 100 million Americans had connected a financial app to a bank account — impressive reach, but almost none of it via standardised, bank-permissioned APIs.
CFPB 1033: The US Finally Gets a Rule — Sort Of
Section 1033 of the Dodd-Frank Act gave the CFPB authority to require financial institutions to make consumer data available to authorised third parties. The final rule, published in the Federal Register on October 22, 2024, set a tiered compliance timeline:
- The six largest depository institutions (assets over $250 billion) had to comply by April 1, 2026.
- Institutions with $10 billion–$250 billion in assets face a deadline of April 1, 2027 — that deadline has just passed.
- Smaller institutions have deadlines extending to 2029 and 2030.
The rule mandates a "developer interface" — effectively a read API — for checking accounts, savings accounts, cards, and certain loan data. Critically, it does not mandate a specific API standard, instead requiring only that the interface be "commercially reasonable" and available without fees to authorised data recipients. The CFPB explicitly declined to endorse FDX (Financial Data Exchange) as the required standard, though FDX membership has grown to over 65 financial institutions representing roughly $29 trillion in assets as of early 2027.
The practical outcome: large US banks are live with developer interfaces, but the interfaces are not interoperable. A fintech connecting to JPMorgan Chase, Bank of America, and Wells Fargo is writing three separate integrations. The aggregator middleware layer — Plaid, MX, Finicity — remains essential, which is precisely what the rule's critics predicted.
"The United States has legislated the right to data portability without legislating the language in which that data must be spoken. The result is portability in principle and fragmentation in practice." — AtlasForge Financial research desk, May 2027
For a deeper breakdown of how 1033 affects account-linked spending tools, see our analysis at /blog/cfpb-1033-account-linking-guide.
PSD3: The EU's Attempt to Fix What PSD2 Broke
The European Commission published its PSD3 and Payment Services Regulation (PSR) legislative package in June 2023. As of mid-2027, PSD3 has passed the European Parliament and is in Council negotiation, with transposition into national law expected no earlier than late 2026 — meaning full national implementation is realistically a 2028–2029 story for most member states.
What PSD3 actually fixes matters enormously for the open banking comparison:
- Dedicated interfaces required, no fallback to screen-scraping. PSD2 allowed banks to offer a "contingency mechanism" (i.e., credential-sharing) if their dedicated interface underperformed. PSD3 removes that escape valve, forcing banks to maintain high-uptime, performant APIs or face supervisory action.
- Standardised API framework. The PSR delegates to EBA technical standards to define a common EU API standard — this is the interoperability that PSD2 never achieved.
- Liability clarification for SCA failures. Strong Customer Authentication disputes that left TPPs and banks pointing fingers at each other will have clearer allocation rules.
- Financial data access (FIDA) regulation. Running parallel to PSD3, the FIDA regulation extends data portability rights to investment accounts, insurance products, and pensions — a scope far beyond anything in CFPB 1033 or the UK framework.
The catch: until PSD3 is in force and EBA technical standards are finalised, EU open banking remains on PSD2 rails with all of PSD2's structural problems. TPPs building in the EU today are betting on a 2029 payoff. That timeline risk is not trivial; it has pushed several EU-headquartered fintechs to prioritise UK market depth over EU market breadth.
For authoritative PSD3 legislative tracking, the European Banking Authority's regulatory roadmap is the primary source.
UK Open Banking: Mature, Monetised, and Mid-Pivot
The UK's open banking story is the most instructive because it is the furthest along. JROC's April 2023 roadmap set out the transition from the OBIE's CMA9-mandate era toward a commercially sustainable, industry-led ecosystem. The key development in 2026–2027 is the Variable Recurring Payments (VRP) commercial framework — after years of VRPs being limited to "sweeping" (moving money between accounts owned by the same person), regulated VRPs for third-party payments are now commercially live with the major UK banks.
Commercial VRPs are significant for a simple reason: they give banks a revenue line for open banking infrastructure, which changes the incentive structure entirely. Under PSD2 and the original CMA order, banks were mandated to provide free API access — meaning they had no commercial reason to invest in API quality beyond regulatory compliance minimums. Commercial VRPs introduce a per-transaction fee model (typically in the 1–10 pence range depending on value and counterparty) that aligns bank incentive with infrastructure quality.
TPP counts in the UK tell an interesting story about market maturation. The OBIE registered over 1,000 TPPs by late 2026, but active TPPs — those making at least 10,000 API calls per month — number closer to 220. The market is consolidating around winners in four verticals: account aggregation, payment initiation, credit underwriting data, and business financial management. Survival of the fittest is working exactly as market logic would predict.
Open banking UK is also the regime most actively exporting its model. The UK's influence is visible in Australia's Consumer Data Right, Brazil's Open Finance framework (which already covers investments and insurance), and Singapore's SGFinDex. The UK did not win on speed — the EU mandated open banking first via PSD2 in 2018 — but it won on implementation quality.
TPP Economics: Where the Business Models Actually Work
The regulatory architecture shapes which business models are viable, and the three jurisdictions have produced three distinct economic structures.
UK: Payment initiation services (PIS) are becoming a genuine alternative to card payments for recurring billers, e-commerce, and P2P transfers. The economics are compelling: a commercial VRP costs roughly 0.1–0.15% of transaction value versus 0.3–1.5% for card interchange plus scheme fees. Two UK fintechs — Volt and Token.io — reported processing volumes exceeding £2 billion annually via open banking payment rails in their 2026 disclosures. Account information services (AIS) monetise through B2B data licensing: credit bureaux, lenders, and wealth managers pay per-enriched-data-call, typically £0.05–£0.30 depending on data depth.
EU: Monetisation is hampered by fragmentation. A TPP charging for enriched data across 12 EU markets needs 12 compliance programmes, integration with dozens of bank APIs of varying quality, and localised SCA flows. The unit economics only work at scale, which is why EU-native TPPs are overwhelmingly either large aggregators (Tink, now owned by Visa; Yapily; TrueLayer) or hyper-localised national players. Pan-EU payment initiation remains subscale — aggregate EU open banking payment volume was an estimated €18 billion in 2026, versus the UK's £87 billion (source: Mastercard Economics Institute, Q4 2026 report).
US: The business model is aggregation-as-infrastructure. Plaid's published pricing (as of its 2026 developer documentation) starts at $0.30 per connected account per month for its Identity and Balance products. MX and Akoya operate similar models. The economics work because US consumer finance is so product-rich — budgeting apps, robo-advisors, neobanks, BNPL lenders all need account connectivity and will pay for reliable, permissioned data. But there is no payment initiation equivalent in the US open banking ecosystem; ACH and RTP are the payment rails, and they are not controlled by the open banking framework.
What Cross-Border Builders Actually Face
If you are building a financial product that spans more than one of these jurisdictions — say, a cash flow management tool for SMEs with operations in both the US and UK — the operational reality is stark:
- You need separate legal entities or regulated agents in each jurisdiction.
- Your API integrations are non-transferable: FDX-aligned US bank APIs do not resemble NextGenPSD2 schemas, which do not resemble UK Open Banking API specs.
- Your SCA/2FA flows must be jurisdiction-specific — UK SCA exemptions do not apply in the EU, and the US has no statutory SCA requirement at all.
- Data residency requirements (UK GDPR, EU GDPR, state-level US privacy laws) may prohibit cross-border data movement that your product architecture assumes.
For developers navigating this complexity programmatically, the AtlasForge Financial API abstracts multi-jurisdiction connectivity into a single integration layer — normalising data schemas from UK Open Banking, FDX-compliant US institutions, and PSD2 European banks into a consistent response format.
A practical guide to normalising transaction data across regimes is available on our platform documentation at /platform.
The 18-Month Outlook: Convergence or Further Divergence?
Three forces will shape the open banking landscape through end-2028:
1. US standardisation pressure. The FDX is lobbying hard for CFPB to endorse its API standard in a forthcoming supplemental rulemaking. If that happens — estimated probability: moderate, contingent on political appetite at the CFPB — the US fragmentation problem gets meaningfully smaller by 2028. If it does not, the aggregator layer remains structurally necessary and extraction power stays with Plaid and MX.
2. PSD3 transposition speed. If a major EU member state — Germany or France — moves aggressively on early transposition, it could create a proof-of-concept for PSD3's interoperability vision and pull other members along. Slow transposition means the EU's competitive disadvantage versus the UK in open banking deepens through 2029.
3. UK commercial VRP scaling. The real test of the UK's model is whether commercial VRP volume reaches the £500 billion annual threshold — at which point open banking payments become a meaningful share of UK retail payment volume and trigger network effects. Current growth trajectories suggest that threshold is achievable by Q3 2028 if bank API reliability continues to improve.
For those tracking these developments, the Federal Reserve's FedNow data access working group papers offer useful signals on where US payment infrastructure modernisation is headed, which will intersect with CFPB 1033 implementation.
Building on the Right Foundation
The open banking comparison in 2027 is not a story of one jurisdiction winning — it is a story of how regulatory design choices compound over time into structural advantages or disadvantages for builders, consumers, and incumbents. The UK got the incentive structure right by combining mandate with commercial VRPs. The EU got scope right with FIDA but paid for it with timeline drag. The US got consumer reach right through market forces but is paying for the absence of a standard.
For teams building products that depend on financial data connectivity, the choice of which market to enter first — and in which order to expand — is one of the highest-leverage decisions you will make in the next 24 months.
If you're evaluating how to connect your product to permissioned financial data across these three regimes without rebuilding your data pipeline for each, Safe to Spend 365 and the AtlasForge Financial API are built precisely for this complexity — normalising multi-bank, multi-jurisdiction account data into a single developer experience so your team focuses on product, not regulatory plumbing. Explore the full capability set at /platform or reach out at /contact to discuss your specific integration requirements.
Ready to build on AtlasForge?
Get sandbox API keys in 60 seconds — or install the Safe to Spend 365 app.
