HM Treasury opened its consultation on modernising payment services regulation on 14 July 2026. It closes on 6 October 2026.¹ The document covers the Payment Services Regulations 2017 (PSRs), the Electronic Money Regulations 2011 (EMRs) and connected legislation, with proposals and questions spanning tokenised payments, agentic payments and the long-term framework for Open Banking.²
For enterprise payment teams, the significant development is the level of detail. Earlier policy work established the direction of travel, which we examined in the next Open Banking operating model. This consultation now sets out an intended legislative approach and asks more than 40 questions about the division between statute and Financial Conduct Authority (FCA) rules, rights of access, commercial models, standards, governance, monitoring and enforcement.
The document remains a consultation. It has not changed the PSRs, created new FCA rules or settled a liability model for artificial intelligence (AI) agents. HM Treasury says any changes to existing regulation would be made through secondary legislation, with further implementation detail to follow after the consultation.²
That distinction should shape how firms respond. The immediate task is to identify where the proposals would affect product design, permissions, contracts, technical standards and control ownership, then provide evidence on the trade-offs. Implementation planning can begin, but it should preserve more than one outcome while policy remains open.
The consultation is a decision point before rule change
The reform programme addresses two related problems. The first is that detailed payment requirements are spread through legislation written before several current technologies and business models became prominent. The second is that Open Banking still depends on a combination of the PSRs and the Competition and Markets Authority's Retail Banking Market Investigation Order 2017.
HM Treasury is considering whether some detailed firm-facing provisions should move from legislation into FCA rules. The government argues that a regulatory rulebook could be updated more responsively and draw on the FCA's supervisory experience. It also expects some elements to remain in legislation, including the regulated perimeter, key definitions and provisions that establish important rights, obligations or protections.²
Open Banking has an additional route. The Data (Use and Access) Act 2025 already gives the government powers to establish Smart Data schemes through secondary legislation.³ The consultation therefore describes two connected tracks: modernising foundational Open Banking provisions in the PSRs, and creating an updated framework under the Act for the interfaces, standards and organisations through which access is delivered.
These tracks are related, but they are not interchangeable. A right to payment-account access may remain in statute, while the technical and operational conditions for delivering that access could sit in FCA rules and standards maintained by another body. An enterprise obligations map should therefore record the source, owner and implementation layer of each requirement rather than treating "Open Banking regulation" as one block.
Decision one: what belongs in legislation and what moves to FCA rules
The first consultation question asks which requirements should remain in legislation and which should be delegated to the FCA. That choice affects more than the speed of rule changes. It determines where firms must look for authoritative requirements, how regulatory change is governed and how much implementation detail may develop through later FCA consultations.
A useful internal assessment separates four categories:
- provisions that define whether an activity or instrument falls within the regulated perimeter;
- rights and protections that need a stable statutory basis;
- detailed conduct, prudential, safeguarding or authentication requirements that could sit in FCA rules;
- technical and operational standards that may be maintained through the Future Entity or commercial schemes under FCA oversight.
The list should be linked to systems and controls. If an authentication requirement moves from the PSRs into FCA rules, for example, the change could affect customer journeys, risk engines, exemptions, evidence retention and supplier contracts. If a definition remains in legislation, product teams still need a process for determining whether new functionality sits inside it.
This favours a versioned obligations model. Each obligation should have a legal or regulatory source, an effective date, an accountable owner, affected services and test evidence. Proposed rules can be recorded separately from current requirements so that scenario planning does not become premature compliance.
The consultation also asks whether existing definitions, including those for payment initiation services and account information services, remain fit for purpose.² Firms developing new data or payment propositions should test definitions against real service boundaries. Broad requests for flexibility are less useful than examples showing which activity is difficult to classify, what customer or market outcome is blocked, and which control would manage the resulting risk.
Decision two: how authority works for agentic payments
Question 15 asks how payment-services regulation needs to adapt for agentic payments, including whether provisions on authentication, consent and liability for unauthorised transactions need updating.² This is a policy question rather than a new agentic-payments rule.
The distinction matters because an agent can perform several roles. It may gather information, recommend a purchase, prepare a payment instruction, select a route or initiate an execution step. The authority required at each point is different. A customer approving the use of an AI service does not necessarily authorise every payment the service might later propose, and successful customer authentication does not by itself prove that a particular agent acted within a delegated mandate.
The Bank of England's July 2026 Financial Stability Report identifies the same group of unresolved issues: authorisation, traceability, fraud detection, liability, resilience and legal accountability. It also notes the tension between probabilistic AI systems and payment infrastructure that requires predictable outcomes.⁴
Enterprise teams should respond with operating detail. The strongest evidence will show how a proposed regulatory model behaves when intent is ambiguous, a beneficiary changes, the amount exceeds a mandate, an agent relies on manipulated context or a payment is accepted after an apparent timeout.
Our guide to agentic payments architecture sets out a practical separation between reasoning, deterministic authorisation and execution. For the consultation, that architecture creates a way to test policy options:
- the mandate record defines what the agent may do for a named principal;
- the authorisation decision binds amount, beneficiary, purpose and timing to a policy version;
- customer authentication provides the evidence required for the payment journey;
- the execution record links the approved instruction to submission, settlement, failure or reversal;
- liability analysis can follow the evidence chain instead of relying on the agent's later explanation.
None of those controls settles the legal allocation of liability. They help firms demonstrate where decisions occur and show which regulatory questions need a clear answer. Respondents should identify the point at which existing rules become uncertain, the consumer or business harm that could follow, and the evidence available to resolve a dispute.
Decision three: how Open Banking access and variable recurring payments scale
The consultation says the existing statutory rights that support payment initiation and account information access should remain in legislation. It also proposes a new right of access for variable recurring payments (VRPs), potentially requiring an Account Servicing Payment Service Provider (ASPSP), such as a bank or e-money institution holding a payment account, to allow a Payment Initiation Service Provider (PISP) to lodge a mandate for a series of payments. The scope remains open, including which ASPSPs and accounts should be covered.²
This is an important distinction between access and commercial participation. A statutory baseline could make a capability available, while commercial schemes coordinate rules, pricing and participant obligations for particular products. HM Treasury currently expects voluntary scheme participation to be supported by the new right of access and fair commercial arrangements. It does not propose a new FCA power to mandate ASPSP participation in commercial Open Banking schemes, although it says adoption will be monitored.²
The position may change after consultation. Enterprise plans should avoid assuming either universal voluntary participation or a future mandate. Coverage models should identify which accounts, banks, use cases and scheme agreements a proposition needs to reach a viable service level.
Pricing is equally unsettled. The government wants to protect fintech business models that rely on existing free access, while asking whether high-volume access could move to a fair commercial basis in some circumstances. It also says access under the proposed new VRP right would not have to be free, apart from sweeping where the existing free requirement may be maintained.²
That extends the questions considered in our analysis of the interim UKPI pricing position. The FCA confirmed that the UK Payments Initiative (UKPI) commercial VRP scheme launched on 2 June 2026 (Wonderful is a shareholder and participant) and said it expects competition between commercial schemes.⁵ The current scheme and enforcement position should not be mistaken for the final statutory and regulatory model now under consultation.
Product owners should model at least the access baseline, scheme coverage, per-transaction or usage pricing, dispute costs and operational obligations separately. Combining them into one assumed "Open Banking fee" would conceal which cost comes from law, FCA rules, a scheme agreement or a provider contract.
Decision four: who governs standards, schemes and pricing
The consultation expects both the Future Entity and operators of commercial Open Banking schemes to be treated as interface bodies under the Data (Use and Access) Act framework. The Future Entity is intended to become the central standard-setting body. Open Banking Limited is currently facilitating an industry-owned design process, with decision-making held by industry participants.⁶
HM Treasury proposes giving the FCA powers over how the Future Entity delivers application programming interface (API), security and operational standards. The possible powers also cover minimum API requirements, performance monitoring, information sharing, governance, funding and a dispute process. The consultation states that the Future Entity would monitor adherence but would not take enforcement action.²
Commercial schemes would occupy a different role. They would define multilateral arrangements between participants, including practical operating rules and pricing. The government proposes FCA powers to set governance and operational-resilience guardrails, require dispute resolution and information sharing, and intervene in access pricing where necessary. It also intends to provide a power under which the FCA could require a centralised pricing model within a scheme.²
This distribution of responsibility needs precise control ownership. A standards body can define an interface and monitor performance. A scheme can define participation and commercial rules. The FCA can supervise and, subject to the eventual framework, enforce regulatory requirements. A payment firm still owns its compliance, service management and contractual obligations.
A sensible architecture keeps regulatory policy outside core product logic. Scheme-specific rules and standard versions can be applied through policy and adapter layers, with effective dates and test evidence. That allows a team to support more than one commercial scheme or interface version without scattering assumptions across payment orchestration, customer journeys and reporting.
Procurement should reflect the same boundaries. Contracts with providers need to specify responsibility for standard changes, scheme rule updates, performance data, incident reporting, dispute evidence and exit support. A claim that a service is "compliant with Open Banking" is too broad for a framework in which the source and owner of requirements may differ.
Decision five: how firms preserve resilience through transition
Regulatory reform and infrastructure renewal are proceeding at the same time. The Retail Payments Infrastructure Board is separately consulting on the design of future retail payments infrastructure, a workstream covered in our analysis of the next decade's payment foundations. The FCA is also moving from Open Banking towards a staged Open Finance programme, beginning with evidence and prioritisation in 2026.⁷
These programmes have different status, scope and delivery bodies. Joining them into one transformation plan may be efficient, provided each dependency remains visible. A change in an Open Banking access rule should not be treated as confirmation of a future clearing design. An industry scheme launch does not create a statutory obligation. A government proposal does not become an FCA expectation until the relevant powers and rules exist.
Transition architecture should support parallel states. Firms may need to maintain current PSR and CMA Order obligations while preparing for secondary legislation, FCA rules, Future Entity standards and commercial scheme requirements. The timing of each layer may differ.
Practical controls include a regulatory change register connected to service maps, compatibility testing across current and proposed interface versions, and an evidence store that preserves which rule and standard applied to each transaction. Change gates should cover customer communications, consent records, fraud controls, reconciliation, incident response and supplier readiness.
The discipline in our Open Banking operational resilience playbook remains relevant. Firms should map the end-to-end service, set impact tolerances where required, test severe but plausible disruption and ensure that a standards or scheme transition does not weaken recovery or evidence.
What enterprise teams should prepare before 6 October
A useful consultation response does more than state support or opposition. It gives HM Treasury evidence about a defined provision, its operational effect and a proportionate alternative.
Architecture, product, compliance, risk and commercial teams should prepare a shared response pack covering:
- a map of which current PSR or EMR provisions affect each service and which should remain stable in legislation;
- examples where current definitions, access rights, status information or contract restrictions block a valuable use case;
- an agentic-payment authority model showing consent, authentication, mandate, execution evidence and dispute handling;
- VRP coverage and pricing scenarios, including the effect of voluntary scheme participation and different access baselines;
- governance boundaries between the FCA, Future Entity, commercial schemes, ASPSPs, PISPs and Account Information Service Providers (AISPs);
- operational data on API performance, failure states, fraud controls, complaints and the cost of changing standards;
- competition evidence showing how pricing or contracting options affect smaller and larger participants;
- a transition plan identifying which decisions need long lead times and which can remain configurable.
Each submission should label its assumptions. If a cost estimate depends on universal ASPSP participation, say so. If a liability proposal assumes a particular agent mandate, define the mandate. If an implementation risk arises only when a provision moves to FCA rules, explain the change mechanism that creates it.
Teams that do not submit a formal response can still use the 42 questions as a design review. They expose where a proposition depends on free access, bilateral contracts, a particular standards body, fixed authentication rules or an unclear allocation of liability.
The next milestones
The consultation closes on 6 October 2026. HM Treasury says it will provide further implementation detail after considering responses. The document also repeats the government's commitment to lay a statutory instrument under the Data (Use and Access) Act by the end of 2026 to support the long-term Open Banking framework.²
Further FCA work will be required before proposed powers become detailed rules. Firms should monitor the government response, secondary legislation, any FCA consultation on Open Banking interface rules, the Future Entity design process and evidence on commercial scheme adoption.
The present opportunity is to improve the quality of those decisions. Enterprise teams already have enough detail to identify affected services, document trade-offs and design for more than one outcome. They do not yet have enough certainty to present the consultation's proposals as the final rulebook.
Modernising payment services regulation will succeed for Open Banking if stable rights, adaptable rules, technical standards and commercial arrangements fit together without obscuring accountability. The consultation gives firms a defined period to show how that can work in operating systems rather than only in policy language.
Footnotes
- HM Treasury, Modernising Payment Services Regulation consultation page, published 14 July 2026, accessed 23 July 2026.
- HM Treasury, Modernising Payment Services Regulation: Consultation, July 2026, accessed 23 July 2026.
- UK Parliament, Data (Use and Access) Act 2025, accessed 23 July 2026.
- Bank of England, Financial Stability Report, July 2026, published 7 July 2026.
- Financial Conduct Authority, Open banking takes next step forward with launch of UK Payments Initiative scheme, published 2 June 2026.
- Open Banking Limited, Supporting the Industry-led Design of the Future Entity for UK Open Banking, published 8 May 2026.
- Financial Conduct Authority, Open finance roadmap: our vision for a smart data future, published 14 April 2026.