Mon, 28 Sep 2026
In a candid discussion following our Payments BBQ Night, Karl Illing, Executive Partner, msg for banking ag, unpacks the true legacy of PSD2 from his perspective. While the regulation successfully created a market and accelerated the internal “APIfication” of banking infrastructure, it fell short of delivering a revolutionary shift for consumers. In this interview, Karl reflects on why the search for a single "killer use case" was flawed from the start, how connectivity providers stepped in to bridge technical gaps, and how banks can transition from broad API portals to targeted B2B ecosystem partnerships.
Last week at our Payments BBQ Night, you shared “PSD2 created a market, but not necessarily a game-changing one.” Could you explain what you meant by that?
You often hear that PSD2, specifically the open banking part, has “not worked”. I think that is not true. It has had a series of visible and perhaps less visible effects. One of them is that we have seen a multitude of new players enter the market, building on the PSD2 APIs that banks were required to build. These players focus on licensing-as-a-service, connectivity and data provisioning, data enrichment and specific use-case offerings, or on any combination of those.
In the end, it is all about adding value for customers. Looking around, you find plenty of examples where AIS/PIS-based services enable new solutions, provide added-value functionality, or help optimise previously cumbersome processes. Some examples include a quick liquidity check when applying for a new rental apartment (or a loan), spending analyses to optimise personal finances (or to show how many miles you would have earned had you used “our” co-branded credit card instead), or powering an SME business cockpit with billing and reconciliation functions.
So yes, PSD2 created a market and fueled innovation.
At the same time, expectations were certainly higher. Payment initiation is in a difficult position overall, needing to compete with established payment methods and new schemes like Wero at the online checkout, and its use as embedded payment functionality in, e.g., personal finance management solutions is limited. Likewise, we have not seen an explosion of new, successful business models or a revolutionary shift in how customers deal with finances in general. In that sense, PSD2 has not been a game changer. Consequently, some of the new players mentioned above have not survived or have been subject to significant market consolidation.
Looking back, what did we get right, and what did we get wrong?
I still believe that introducing Open Banking at a regulatory level was the right move. Not only because of the market dynamics and growth in open banking-based offerings mentioned above, but also because it has forced banks to focus on improving connectivity, both externally and internally.
I agree with many others that PSD2 has had significant drawbacks. Some of its requirements, such as the 90-day renewal period for TPP consents, have negatively affected user experience and various use cases. The lack of performance requirements and a mandated standard has resulted in a highly heterogeneous API landscape, both in quality and in technical design. Some institutions have certainly not put much effort into making the dedicated TPP interface very attractive to use. Lastly, PSD2 was a directive, i.e. each member state had to transpose it into national law, leading to significant differences between countries, adding to the difficulty of scaling offerings across borders.
That said, here’s an important BUT: I don’t believe these shortcomings were decisive in the perceived success or failure we observe today. Connectivity providers quickly stepped in to compensate for the lack of standardisation and made it easy for any business with an attractive use case to connect, including by using their existing licence. Even in an ideally standardised PSD2 world, these connectivity providers would still exist, as it would make little sense for most businesses to implement their own API connection to thousands of banks. The “lack of success” (if you want to call it that) of PSD2 lies in the fact that we have not found the game-changing use cases that some expected, and maybe that was the wrong expectation all along.
I frequently hear that Open Banking’s key achievement is shifting banks’ mindset. This might also relate to your point on our stage: “PSD2 modernised banks, even if the commercial Open Banking strategy didn’t succeed.” What are your thoughts on that observation?
Both statements are broad generalisations, so I will take this opportunity to clarify them further.
The obligation to introduce open APIs was new to some banks, not to others. A range of large banks had already started working on APIs, both internal and external, before PSD2, so XS2A was just another piece of the puzzle.
Other institutions had not dealt with exposing data or functionality before. Some picked the “easy” (or sensible) way to outsource XS2A interfaces to an open banking compliance provider or a mutualised service, but even those had to do technical work internally.
Others chose to implement XS2A themselves, at significant cost. Numerous banks we have worked with or spoken to in the past have considered this investment at some point and used the opportunity to go beyond regulation; for example, by offering premium APIs.
Overall, I believe that PSD2 has accelerated the "APIfication" of banking, including internal systems communicating with each other. That makes bank infrastructure more competitive and resilient in a world where moving and exchanging data efficiently is indispensable.
As regards commercial Open Banking strategy, we need to look deeper as well. The first wave of Open Banking strategies typically consisted of publishing a series of premium APIs on a developer portal and hoping the external world would pick them up and develop killer applications based on them, which in turn would drive both direct API revenue and use of underlying banking services. This turned out to be difficult.
The next wave of strategies focused more on specific use cases and dedicated partner strategies. API business owners within banks began to work closely with the business lines to identify applications, use cases, or customer problems that could be solved or improved using APIs. This approach proved more fruitful, even though it is harder to observe from the outside.
Frequently, the focus shifts from retail to wholesale banking. In retail, you typically need to scale a use case across the market, whereas in B2B you can work with a dedicated set of customers and partners/intermediaries to develop specific API functionality suited to their needs. Note that I’m not talking about PSD2 here: In the business/corporate banking context, plain-vanilla PIS/AIS functionality is typically not needed alongside existing connectivity such as EBICS (Electronic Banking Internet Communication Standard) and other existing protocols.
A key lesson here is that exposing APIs alone doesn’t build an ecosystem; instead, it enables and strengthens the ecosystems you're already involved in or developing.
The topic of discussion at The Banking Scene Payments BBQ Night was regulation vs innovation: what’s shaping the future of payments. In that context, you explained that Regulation should establish principles and infrastructure, not prescribe the mechanics. Do you think the European Commission understood this when writing PSR?
I’m pretty sure they understand the principle, but getting it right is, admittedly, difficult. We are currently analysing the impact of PSR on a range of banks and, by now, can pinpoint where the regulatory text clashes with reality.
You can get it wrong in both ways: either a particular requirement is “one-size-fits-all” when it was written with a particular scenario in mind and makes little sense in others. In other cases, you could ask: why is this requirement so specific when there are obviously a range of different ways to reach the intended goal?
This highlights the need for further clarification, e.g. through EBA Regulatory Technical Standards, an endless number of Q&As and interpretations at European and national levels.
While I believe PSR tends to overshoot in some areas, I don’t intend to bash the regulation; it includes many important aspects that make payments safer and improve Open Banking.
Overall, I would advocate a more principles-based approach: state the regulatory objective and introduce framework criteria, then let the market or individual banks implement them in a way that reflects their business model, internal set-up and particular risk profile.
Europe is now debating FiDA. Do we need it? And if so, do we need it in its current form?
It’s an easy answer: 99% of market participants will tell you we don’t need it. I think we do, but not in its current form. Nobody wants it because regulated institutions see the immense investment attached to it, at best expect little actual impact (extrapolating from Open Banking), and at worst see it as a threat. Maybe not so much because of new market entrants, but out of fear that your next-door competitor will use FiDA to have potential customers share their current contract conditions and make a better offer, leading to price pressure without any innovative value.
To be precise, the latter argument is one I hear more from insurers than from banks. The argument remains the same: high investment with little, or even negative, return. As a consequence, even many TPPs are sceptical: such forced and unwanted regulation will not result in the infrastructure conducive to building scalable new business models.
Why do I still believe we need some form of FiDA? What will happen with FiDA will also happen without it. Maybe not as fast, maybe differently, but probably independently of whether FiDA comes or not, because Open Finance will progress faster than the regulation. The question is, do we give it a structure, or will it grow “in the wild”?
FiDA, in its current form, is not feasible, already because of the imbalance I described above. It needs to be introduced in a way that is supported by the market. Admittedly, I don’t have a perfect recipe for that. One way to go might be to work closely with a “coalition of the willing” from day one, in a true partnership with the market.
Allow this coalition to establish key elements for a successful open data scheme and initiate a pilot program. Afterwards, expand it to the wider market and make participation mandatory at a specified time.
Is the emergence of AI making Open Finance more important—or exposing how far behind the industry really is?
AI will be the new reality that defines Open Finance in the future. This is what I implicitly referred to above. We will move away from the classical bank <–> licensed TPP <–> solution provider <–> customer scenario. Instead, we will increasingly see individual AI agents acting on behalf of customers, recommending and potentially deciding which financial products to buy, how to optimise the customer portfolio, or conduct payment transactions.
Banks will face similar challenges to online merchants in the wake of agentic commerce. In the worst case, banks won’t even know they are dealing with an agent. These agents will use the customer interface or whichever interface is most suitable.
This puts pressure on Open Finance to present a structured way to interact with future AI agents, enabling banks to provide optimised channels for agent interaction, increasing the findability and attractiveness of their products, as well as security and trust in these interactions.
Who is really driving Open Finance today: regulators, banks, fintechs, technology companies, AI providers or customers themselves?
AI will not be the only, but a defining, force driving Open Finance. All actors mentioned need to play their part in further shaping Open Finance. Bottom line, it will still be the customers who determine whether “Open Finance” will be considered a success a few years down the line.
A final note: FIDA, or whatever name a future Open Finance framework might have, should not mainly focus on fostering competition, innovation, and customer choice, as those are already well supported today. Instead, its core purpose should be to enhance the European financial sector's competitiveness and resilience against disruptive market forces. Use this as a guiding principle, and I believe it will help regulators and the market work together effectively on developing a new FIDA.
If you prefer to hear Karl's insights directly, you can watch the full interview below or follow along on your favourite podcast platform here. Whichever you choose, don't forget to subscribe to the platform of your choice to keep up with future insights from industry experts!