Open banking regulations have entered their second generation as jurisdictions worldwide move beyond mandating basic account data sharing to enabling full-spectrum financial data portability. The shift is creating new revenue opportunities for banks willing to embrace the API economy and existential threats for those that treat open banking purely as a compliance exercise.
From Compliance to Commerce
The United Kingdom’s Open Banking Implementation Entity, which oversaw the rollout of the original open banking framework, transitioned its functions to the new Open Banking Ltd regulatory body in January 2026. The reorganization reflects the framework’s evolution from a competition remedy imposed on the UK’s nine largest banks to a commercially viable ecosystem serving over 10 million active users.
API call volumes in the UK open banking ecosystem exceeded 13 billion in Q1 2026, with variable recurring payments emerging as the fastest-growing use case. The feature allows consumers to authorize ongoing payments directly from their bank accounts, offering merchants a lower-cost alternative to card-on-file arrangements.
US Consumer Financial Data Rights
The Consumer Financial Protection Bureau’s Personal Financial Data Rights rule, which took effect for the largest financial institutions in April 2026, has brought open banking to the United States at scale. The rule requires banks with over $250 billion in assets to provide consumers with machine-readable access to their financial data through standardized APIs.
The Financial Data Exchange, an industry-led standard-setting body, has seen its membership grow to over 100 financial institutions as banks race to build compliant data-sharing infrastructure. Plaid, MX, and Akoya are competing to become the dominant intermediary layer in the US open banking stack.
Screen Scraping Phase-Out
The transition to API-based data access is finally ending the era of screen scraping, where third-party apps accessed bank data by storing and using consumers’ login credentials. The practice, long criticized for its security implications, is being explicitly prohibited under most new open banking frameworks.
Revenue Models Emerge
Banks are discovering that open banking APIs can generate meaningful revenue. BBVA’s API marketplace processes over 200 million monthly API calls from third-party developers, generating fees that the bank describes as a material and growing revenue stream. Standard Chartered has launched a premium API tier that offers enhanced data granularity and higher rate limits for commercial partners.
The concept of premium APIs, where banks charge third parties for access to enriched financial data, analytics, and account initiation services, is gaining traction as a sustainable business model. Goldman Sachs’ Transaction Banking division has built its entire small business banking proposition around API-first delivery.
The Privacy Tension
As financial data becomes more portable, privacy concerns are intensifying. Consumer advocacy groups have raised alarms about the potential for data brokers to aggregate financial information across multiple institutions, creating detailed financial profiles without meaningful consumer oversight.
Regulators are responding with stricter consent management requirements. Australia’s Consumer Data Right framework now requires explicit re-authorization every 12 months and allows consumers to request deletion of shared data. The challenge for regulators is balancing data portability’s competitive benefits against the privacy risks inherent in a more open financial data ecosystem.




