Skip to main content

Europe Agreed on Its New Payment Rules Ten Months Ago. Not One of Them Applies Yet.

2026 was supposed to be the year fintech got its new rulebook. Most of it is agreed, delayed or stuck, while the rules already in force quietly do the work.

Europe Agreed on Its New Payment Rules Ten Months Ago. Not One of Them Applies Yet.

If you spent any time on LinkedIn this week, you probably saw two kinds of regulatory posts. The first kind announces that something has been agreed. The second kind, usually written by people who build payment systems, asks when any of it will actually apply. For most of 2026's big fintech files, the honest answer is: not yet.

That gap between "agreed" and "applicable" has become the defining feature of fintech regulation on both sides of the Atlantic. It matters because product roadmaps are being planned around rules that are not yet law, while the rules that already are law are quietly reshaping how money moves today.

Agreed, but not applicable

The clearest example is Europe's payments package. EU negotiators reached a provisional political agreement on PSD3 and the new Payment Services Regulation on 27 November 2025. The European Parliament's ECON committee approved the text on 5 May 2026. As of late summer, the package was still waiting for its final votes and publication in the Official Journal. Until that happens, PSD2 remains the law.

What sits in the agreed text is substantial: refunds for victims of impersonation fraud, name-to-IBAN checks extended to all credit transfers, dashboards that let customers revoke open banking permissions, and performance requirements for bank APIs. Most of these rules are expected to apply around 21 months after publication. A package agreed in November 2025 may therefore not bite before 2028.

The digital euro is moving through the same pipeline, one stage further back. In July, the European Parliament voted 416 to 169 to open negotiations with the Council, backing both online and offline versions with holding limits. Trilogues have only just begun. Even on an optimistic path, the ECB has spoken of testing in 2027 and a possible launch in 2029.

Delayed by design

Then there are the rules that were agreed, scheduled and then moved. The EU's AI Digital Omnibus, which entered into force on 27 July 2026, pushed the AI Act's high-risk obligations under Annex III from August 2026 to 2 December 2027. That category includes credit scoring. Lenders that had been preparing their underwriting models for an August 2026 deadline now have 16 more months.

The transparency rules in Article 50 were not delayed. They apply from August 2026, with a grace period until 2 December 2026 for the labelling duty on systems that were already on the market. For a fintech running a customer-facing assistant, that is the AI Act rule that applies today, not the high-risk regime that dominates most conference panels.

Stuck

Some files have simply stalled. The Financial Data Access Regulation, meant to extend open banking into open finance, saw trilogue talks paused earlier this year, largely over whether the largest US technology platforms should be allowed to use it. The Commission has not withdrawn the proposal, but nobody is building to a FiDA deadline.

In Washington, the CLARITY Act, the market structure bill for crypto, failed a Senate cloture vote 49 to 50 on 15 September, well short of the 60 votes it needed. The fight has moved to the agencies. The SEC proposed its Regulation Crypto Assets on 2 September, with comments due by 20 October. Meanwhile the GENIUS Act, the US stablecoin law that did pass, takes effect on 18 January 2027.

What already applies

While attention goes to the waiting room, a handful of rules that are already in force are doing most of the work.

  • Verification of Payee. Since 9 October 2025, payment service providers in the euro area have had to check the payee's name against the IBAN before a credit transfer is executed. It is arguably the most visible regulatory change for European bank customers in years, and it arrived through the Instant Payments Regulation, not through PSD3. For corporates sending bulk files, including over EBICS, it changed how payment runs are prepared, a topic we looked at in EBICS vs. PSD2.
  • Instant payments. The same regulation pushed instant euro transfers into the mainstream. According to the European Payments Council, SEPA Instant reached 35.6% of SEPA credit transfer volumes in the first quarter of 2026, after 10.1 billion instant transactions in 2025, up 73% year on year.
  • MiCA. The transitional period for crypto-asset service providers ended on 1 July 2026. Firms without an authorisation may now only wind down their EU business. The ESMA interim register lists more than 360 authorised providers, with Germany alone accounting for 96. Europe's central banks are already debating the next round of rules, as we reported on the ESCB's push on stablecoin reserves.
  • DORA. The Digital Operational Resilience Act has applied since 17 January 2025 and is reshaping cloud and vendor contracts across the sector, as our piece on data sovereignty showed.

What this means for builders

  • Plan for what is in force, not for what is announced. Verification of Payee, instant payments, MiCA and DORA create obligations and customer expectations today. They deserve more roadmap space than a directive that has not been published yet.
  • Treat PSD3 as a direction, not a deadline. The fraud liability shift and the extension of name checks are very likely to come. Building good payee-check data and fraud signals now pays off under both regimes.
  • Use the AI Act delay to document, not to pause. The high-risk deadline moved, the documentation effort did not. Model inventories and explainability work take longer than 16 months in most banks.
  • Watch three dates. 20 October 2026 for comments on the SEC proposal, 2 December 2026 for the end of the AI Act labelling grace period, and 18 January 2027 for the GENIUS Act.
  • Do not wait for FiDA. Open finance use cases that work under PSD2 access rules, or through bilateral agreements, will not be overtaken by a regulation that is currently not moving.

2026 was supposed to be the year the new fintech rulebook arrived. Instead it became the year the rulebook was written and left in the waiting room. The companies that do well in this phase will be the ones that read the rules already in force more carefully than the headlines about the ones still to come.

This article was researched and written with AI assistance for FinTech Weekly. All facts are linked to their sources in the text.