Insights & Opinions

Regulation Opened the Door But it Didn't Build the Market: an Interview with Gijs Boudewijn, Chairman of the European Payments Council

Tue, 01 Sep 2026

assets/site/Rik-Coeckelbergs-400x400.jpg
Rik Coeckelbergs Founder and CEO The Banking Scene

Regulation Opened the Door but didnt build the market featured

As I continue my exploration of the current and future state of Open Banking across the Benelux region, I sat down with Gijs to get a broad, industry perspective on what PSD2 achieved, where it fell short, and why open banking has been slower to turn regulation into real market momentum.

The full transcript of the interview follows; please bear in mind that Gijs expressed his personal views, which are not necessarily official views of the EPC:

Gijs Boudewijn, welcome to my virtual studio. Let me give a brief intro for those listening to us (better: reading this). Gijs is the Chairman of the Board of EPC, the European Payments Council. But I have known you much longer, of course, from the time you were the General Manager of the Dutch Payment Association.

Today you're not just working for EPC. I just opened your LinkedIn profile to make sure I'm not missing anything. On top of your role at EPC, you're a Member of the Curatorium, Chair by special appointment in FinTech and Law, at Erasmus School of Law. You are an Independent Member of the Supervisory Board of CCV and EMS, and Editor and Member of the Editorial Board of the Journal of European Payments Strategy and Systems.

Quite impressive, and it proves you are the right person to ask all my questions about the current and future state of Open Banking and Embedded Finance.

Thanks a lot for making time for me.

It’s a pleasure, Rik.

Let’s start with a very general question. We're now ten years past PSD2 and have probably been discussing PSD2 and Open Banking for much longer. Looking at the topic today, do you consider it a success?

Well, of course, that depends on the definition of success. Looking back, my overall view is that PSD2, building on the original PSD, effectively opened up the payments market. Nevertheless, it alone did not create a complete European Open Banking ecosystem throughout the continent.

It did change, of course, the structure and mindset of the industry, with progress towards a harmonised infrastructure, and probably also the SPAA scheme in that context, and let's say compelling customer propositions and sustainable business models have been more gradual, to put it mildly.

I agree. If you look at the European Commission's ultimate ambitions back in the day to stimulate innovation and create more competition, I'm not so sure that succeeded, except in exceptional cases like Wero. But ultimately, I think a lot of people from the community will agree with you.

I said it depends on what you define as success. I think yes, it was a success, but not necessarily the success that the commission intended when they drafted it.

Looking back, what do you think we got right? And what did we ultimately get wrong? What made it not so successful in the end?

I've said many times, and as I get older, you always say I've said many times. One of the biggest successes of PSD2, I believe, was that it served as a significant wake-up call to the established banking sector, signalling that change was imminent, even before it officially took effect.

Let's say the gap between what fintech said they could do and what the incumbents offered in the early days was, of course, huge. And what people sometimes underestimated was that it wasn't just fintechs that could improve what was there; the incumbents could do that too. So I really believe, from my own customer experience, that this giant wake-up call to the incumbents, this massive wake-up call, was that “guys, we really need to do something; we need to do a better job”.

They finally understood that message and significantly improved their services for retail customers. This reduced the gap between what FinTech promises and what incumbents offer; perhaps not completely, but substantially. The disruptive impact people anticipated from a major move to Open Banking, expecting better services similar to those from incumbent banks, did not occur. I believe this is kudos to the incumbent industry, even if they didn't consciously recognise it. That's truly what happened.

What made it not so successful? I had this conversation before with other banks, including Rabobank recently. I also gave feedback on the interviews I conducted back in 2019-2020, especially in Belgium. Quite a lot of banks saw the disruptive potential of PSD2, and all saw opportunities. But if I look back six years later, none of them actually built the premium APIs to create the disruptive future they envisioned back then, except for one or two. So, for some reason, it never took off. But why was that?

That's a good question. There probably isn't a single success or failure factor. Perhaps there was some misunderstanding about the true nature of the problem. Was it really about the customer wanting to use their data and open it to third parties for better services?

I mean, for plain old payment initiation services, I don't think the average customer even realises they are directly instructing their bank to make the payment via a PSP. For the end user, that doesn't really make a difference. And we all know, of course, that customer behaviour is very slow to change.

Most consumers typically have one primary banking relationship where they receive their funds, along with multiple outlets and payment methods via various parties. However, they are unlikely to switch banks just because a TPP offers an attractive pay-by-bank solution for certain merchants. This slow shift in customer behaviour raises the question: is it really a problem for the consumer that is being solved?

Payment experts, industry players, and regulators all believe there’s a major issue with the market structure that requires resolution. However, this perceived problem differs from what consumers might see as problematic.

And then, of course, you cannot simply create a market through regulation. While it once seemed impossible, we now see examples like Pix in Brazil or UPI in India working effectively. I would describe this as creating network effects through brute force: using regulation to achieve this, as we might observe with the digital euro.

I refer to that as creating networks through brute force. However, relying on market participants and their cooperation to develop network effects and effective solutions is much more complex because, ultimately, all these participants are commercial institutions.

When someone introduces a good idea, managers typically ask, "Okay, but show me the money." They want to know where the revenue will come from and why they should invest in good APIs. The main issue is the lack of a clear business case, especially among incumbents and account servicing institutions. They need to see where the profit is. While compliance is essential, that should be where the discussion ends.

This lack of financial incentive is a recurring topic and one reason it didn't meet initial expectations. However, another factor that favours PIX is its focus on just one jurisdiction. In contrast, PSD2 was a Directive that required implementation into national laws, which led to fragmentation, not only in how the Directive was interpreted but also in how APIs were developed and quality was managed. Banks I interviewed often cited this fragmentation as a key reason PSD2 didn't succeed as expected.

That, of course, is one of the fundamental advantages or disadvantages of EU regulation: it depends on one's perspective. It must be technology-neutral. We discussed this back in the day: this is the API, unwrap it, install it, and we have a PSD2 API. But then, we have to leave that up to the market.

I can recall vivid discussions: which API standards to choose: Berlin Group, STET, PolishAPI, Slovak Banking API, UK APIs, or others. Unfortunately, none of these became the overall European standard API or a common implementation basis. For example, the Berlin Group doesn't have its own API but provides specifications instead.

And indeed, across all these various customer journeys, you can still observe different implementations today.

I have several payment accounts across Europe just to see what happens, and I still see different strong customer authentication and customer journeys. I won't name any countries or banks, but I still see different strong customer authentication and customer journeys. I'm used to my Dutch banks' customer journeys because I'm Dutch, and then I have this funny, fully compliant customer journey from a very large bank in a Southern European country. They are both compliant yet completely different.

I completely agree that the main issues were not just the banks' implementations but also the lengthy process to clarify what compliance actually entailed. This included the European Banking Authority's regulatory technical standards, which were neither actual regulations nor clear standards, and it took a long time to reach a firm opinion.

Eventually, everyone agreed on a common understanding, particularly between third-party payment providers and traditional banks, defining what we now call the PSD2 baseline. Reaching this consensus through the EBA's opinion was a slow process.

And finally, once the compliance framework was understood, the question was what we could build on it. And we probably get to that. That was necessary to move forward. I think we've held each other hostage way too long to get clarity for various reasons.

Despite all the conferences and dialogues, etc., the next chapter in Open Banking after PSD2 will be PSR, a regulation. Do you think that PSR would solve what went wrong, or at least a couple of the things that went wrong with PSD2?

Absolutely. Absolutely, yes.

Yes, at least this will resolve the institutional issue you mentioned, Rik. Directives can sometimes be, well, sometimes even gold-plated, but there are different interpretations, different supervisory interpretations of their meaning. This has been a key lesson for the Commission: we should avoid using directives this way again.

Instead, a regulation would be more effective, as it addresses one of the main advantages. While it will probably be helpful, it alone cannot improve the overall situation or establish the market. Market participants still need to see viable business cases and use cases for it to work. Therefore, legal clarity will be increased.

Well, have less discussion, hopefully move on, but you still need to agree on what problem we are going to solve, what the real market demand is, what the use cases are, and what the business is. By the end of the day, this serves as another lesson learned. I believe the commission also, in the FiDA context, recognised that there's no such thing as a free lunch. Everything has a cost, and even if something seems free, it isn't. The expense must be recovered somehow.

Under PSR, using the example of a large South European bank, consent and authentication processes will remain different from those in the Netherlands due to local customs and habits, such as how people are accustomed to giving consent. These differences probably won't change or become so detailed as to specify exact banking behaviours, I suppose.

It will probably also depend on what the EBA is going to say or do. And I don't think the aim is to harmonise a single pan-European customer journey. There's still a lot of freedom, of course, so there will be more structure, but the customer journeys themselves may still look quite different. And that doesn't have to be a problem, but it's more of a philosophical question. Why do we want one pan-European customer journey?

Yes, exactly, it's a free market.

It's totally fine that the Italian customer has the Italian customer journey and the Dutch customer has the Dutch customer journey. For ninety per cent of the customers, that is not a problem because they don't have multiple accounts both in the Netherlands and Italy.

A couple of years ago, you and I spoke a lot about SPAA (SEPA Payments Account Access Scheme). Recently, I have the impression that it has become quieter in that respect. Could you give a bit more context? I think you were one of the main drivers back then in pushing SPAA forward. How did it start? Where are we today? And what can we expect from it in the near future?

The journey of SPAA began around 2019-2020.

I described how the account-servicing institutions and the third-party payment providers vigorously disagreed on what was mandatory under PSD2. What should banks expose for free from a compliance perspective? I call that the PSD2 compliance baseline. I already said it took a very long time to clear that one. It had to wait for the regulatory technical standards and, finally, an opinion of the EBA to convince.

And even then, some party said, but this is just an opinion of the EBA. By the end of the day, it's the Court of Justice in Luxembourg that will tell us what the compliance baseline is. But that would have been ten years from then.

In the end, everybody accepted that the EBA opinion made it clear what the PSD2 baseline was.

The viewers, whether listeners or readers, may not be familiar with the Euro Retail Payments Board, a multi-stakeholder forum overseen by the European Central Bank that addresses retail payments in Europe. One particular issue was the slow implementation of PSD2. While working for the ERPB, we authored a report to take action, as it became evident what the baseline for PSD2 was.

How can we ensure success and effectively utilise PSD2? A working group issued a report emphasising the need for additional rules beyond PSD2. While we understand what compliance entails, the current baseline is insufficient for developing key functionalities.

In particular, third-party payment providers have highlighted the importance of building strong customer propositions, such as an API for variable recurring payments, which is not mandated by PSD2.

The idea was to include that in a scheme as an example, and for the ASPSP, to look for a business model. It was agreed that, to leverage PSD2, we decided we needed a new set of agreements, call it the scheme, describing premium functionality on top of PSD2, and a remuneration model for the incumbents on the other side. It is quite unique that, in a multi-stakeholder environment, we created that scheme. The ERPB asked the European Payments Council, which was long before I became Chair there.

They inquired with the European Payments Council whether it could take this on and develop the SPAA scheme. After some research, the EPC agreed, and that led to the creation of SPAA.

The initiative still exists, driven by the SPAA multi-stakeholder group. However, the scheme has been gathering dust on the shelves of EPC. So, why hasn't it been successful? There are many reasons. Are the business cases or use cases strong enough? Is the business model sufficiently robust?

One reason, especially among incumbents, is that they say, 'We may support SPAA, but not right now.' They point out that new legislation, like PSD2 transforming into PSR, will require them to upgrade their APIs for PSR anyway. So we will wait for those changes before making updates. This means delaying API upgrades for two or three years, waiting for the right moment.

If you need to open the street to install a new phone line for PSR, consider installing an additional line for SPAA while it's open. Since opening the street can be costly, it makes sense to do both installations at once to avoid opening it twice.

In a way, we could argue that despite the European Commission's ambitions to stimulate more innovation, those regulations intended to stimulate innovation may have pushed innovation away simply because banks don't have the time or the resources to invest in something that's market-driven like SPAA.

Yes. Compliance alone is insufficient to achieve good results. I understand, from the bank's perspective and given the regulatory pressures they face, that if I were a bank CEO, my top priority would be addressing my backlog and focusing on the most critical tasks. That could be compliance requirements or more lucrative business projects.

On the other hand, if you're realistic, compliance is unavoidable. You have to follow PSR regulations anyway, so it makes sense to do both if you're already implementing something. For example, if you're deploying Wero or other pan-European solutions at the front end, outside Open Banking, why not extend the same approach to APIs within Open Banking? That was the main idea; since the investment is likely limited, it seems practical to do both. However, I understand it may not be a top priority; compliance, however, remains essential.

Is it publicly known how many people signed up for the SPAA scheme?

More information on scheme adherence is on the EPC website (the most recent status (dd 2026/08/20) can be found here). It's a handful of members, mainly the TPPs (Third-Party Providers), because these payment initiators and account information service providers have the most interest in getting good information and good customer journeys from ASPSPs.

This indicates a readiness among users to invest in higher-quality data.

Absolutely, yes. That was one of the milestones we believe we achieved. At that time, I was still working at my previous job, representing the banks in the multi-stakeholder group. We faced intense battles between the banks and the TPPs. Depending on your view of success, I think the whole process was successful.

Even if SPAA may not be flying sky high yet, it proved that cooperation was possible, moving us away from constant conflict. We also realised, and continue to recognise, that regulation alone cannot create the desired change.

Regulation can open up a market, but it cannot create one. So you will always need a set of arrangements on top of regulation, a set of arrangements among market participants based on mutual understanding.

There's no such thing as a free lunch, but we need good information, and we need cooperation and agreement. The Commission has realised that. That's why, and that might be a good bridge to FiDA, why the systematic approach, with regulation and a set of private arrangements built on top of it, should together create a good market.

Indeed, there's also FiDA, which may or may not appear on the agenda again. I have the impression that it's been incredibly quiet from that corner. For a couple of years now, I've expected it to be the main topic at my conferences, yet every time it's a challenge to find enough speakers for a panel. Which makes me wonder whether we need FiDA, and if so, whether we need it in its current form.

The SPAA model is structured with regulation at the bottom, including arrangements and multilateral agreements. Above that is a scheme layer that combines the institutional framework and PSPs. True innovation and competition occur above this scheme layer.

The Commission has used the model as an example for FiDA. We have FiDA in place, but additional schemes would be needed for various non-payment financial services. I'm not an expert on these non-payment elements, such as pensions or mortgages, so my insights are limited.

Personally, I believe focusing on payments is more feasible since everything is already established, including the SEPA standards and the framework. That part is straightforward. However, I don't know how much harmonisation exists in areas like insurance, mortgages, or pensions; it seems less developed than in payments. Creating pan-European schemes from scratch would be nearly impossible, likely leading to a lengthy period of fragmentation similar to what we experienced with SEPA since the late 1990s.

Additionally, I'm uncertain about the specific problems or use cases we aim to address. Going all-in may not be the best approach, but targeted use cases might have potential.

I believe the core idea of FiDA is quite valid, although I recognise that there’s significant resistance from financial institutions because of its scope. This is a different discussion worth exploring, involving more stakeholders interested in and Embedded Finance. Currently, a key topic in debates about Open Banking and Embedded Finance is artificial intelligence (AI), which relies on proper data.

If not immediately, I believe AI will become much more prominent in shaping the Open Banking agenda in the future. What’s your perspective on this? People could read on our website that recently, there was a General Assembly where Andrew had the chance to moderate a panel that was also on AI, so it's definitely high on your strategic agenda as well at the EPC.

How do you look at that intersection between Open Finance and AI?

AI is not a top priority for EPC, but it does impact the industry at large. Our main goal at the General Assembly was to raise awareness among members who might not be fully informed. The pace of change is rapid. As EPC, a scheme manager, we need to consider whether AI, in any form, requires us to modify our schemes. This is an open question, likely not inherently. However, it's more about the strategic implications, not AI itself, since it's a broad topic. AI is mainly a productivity tool, a back-end utility, or similar and doesn't fundamentally alter our core functions.

But all these things need to be fed with data, of course, often from a current account.

Yes, and then there's the aspect of bots and AI, which can extract much more information via AI or AI agents. This has significant implications, including issues like deepfakes and fraud, affecting the entire spectrum of technology. From a retail payments perspective, strong customer authentication and consent are crucial, and we've considered these aspects as well. Ultimately, the key question is how to demonstrate accountability because liability matters. Both you and I may have payment accounts, and our AI agents, operating according to our instructions, even while we sleep, can make purchases and perform actions on our behalf.

The key question is how to demonstrate accountability by the end of the day, given that both you and I are responsible for our agent's actions. This introduces the concept of verifiable consent and raises the question of how to provide proof. The focus is on a technical layer that still recognises the natural person as the liable party, not the AI itself, which has no agency or substance. It remains a legal issue: how can AI, especially in the context of agentic commerce, ensure compliance with the existing legal framework?

Fraud is an ongoing challenge, with endless ways to deceive people of their money. AI will assist criminals, but it will also aid in fighting them, which is nothing new. Those who have been around know that each crisis is just another chapter in a continual struggle. Criminals develop new tools, and we respond with new countermeasures. It's an ongoing cycle, not the end of the world.

Some argue that this time is different, but I have seen many situations like this before. While it may seem different, the core issues remain unchanged: a regulated industry attempting to safeguard people's wealth and an unregulated, criminal sector trying to exploit that wealth by any means. There's nothing fundamentally new there. Hopefully, as in the past, despite the inevitable damage, we will survive and adapt, forging a new path forward.

We have just a few minutes remaining, but there's one question I especially want to ask. Based on your previous response, I think I already know the answer. How likely do you think it is that a major AI company will set the standards for future Open Finance developments, perhaps by partnering with a large bank to influence others to follow suit?

I haven't really thought about that. Why would they?

Imagine one of these entities collaborating with a major bank like Societe Generale, BNP Paribas, or another prominent European bank. They establish detailed protocols to ensure robustness, enabling data collection. By partnering with a leading bank, they effectively set standards that encourage other banks to adopt, rather than relying on industry-wide negotiated standards. This approach accelerates the overall process.

Potentially as the new journey of Open Finance.

The common saying about standards is that the problem lies in there being too many to choose from. Therefore, your scenario isn't necessarily a negative aspect. Standards are needed, and as I mentioned, regulation should be technology-neutral and not impose any specific standard. Of course, we're accustomed to ISO 22000, but it's more a philosophical question.

If a good standard is being mandated as you describe, it isn't necessarily a bad thing, but if it's only intended to extract a lot of money from European customers in a nasty way, it would be a bad thing. I don't see that happening, to be honest. So I wouldn't say yes or no to that question. It could either be good or bad.

We see many developments in AI, but not quite in the way you think. Existing protocols from Stripe, Google, Visa, and MasterCard already cover much of this. How will we function in the agentic commerce space? I believe it’s important. We need protocols rooted in the concept of verifiable consent, but what you described probably dives much deeper into philosophical questions. Not necessarily a bad thing, I’d say.

If, despite my initial thoughts, your scenario were to become true, it would be ideal if a major European company collaborated with a large European bank on this instead of non-European entities.

We're running out of time, so I have a few more questions, but I won't ask them now. Thank you very much for your time and for your openness during the conversation. It has been very interesting, and I have learned a lot from it, despite our previous discussions. Thanks again, and I look forward to seeing you at The Banking Scene Payments BBQ Night (September 10, 2026).

The Banking Scene: Director's Cut

If you prefer to watch or listen to hear the insights from Gijs directly, you can find the full interview below or follow along on your favourite podcast platform here (and don't forget to SUBSCRIBE for future insights from industry experts!).

Share this via
© Copyright 2026 The Banking Scene - All rights Reserved.