The EU’s new payment services rulebook is now locked in on substance. The political deal struck in trilogue on November 27, 2025 became a final compromise text on April 22, 2026, when the PSD3 directive and the Payment Services Regulation (PSR) cleared Coreper, the committee of member states’ ambassadors to the EU. What remains is procedure: formal adoption, legal-linguistic review and signature. Most law firms consider publication in the Official Journal of the EU realistic for summer 2026. For compliance teams, the countdown has already started.
A directive for licensing, a regulation for conduct
The package splits today’s PSD2 into two instruments. PSD3 keeps the rules on licensing and supervising payment institutions and e-money institutions. It also absorbs the second E-Money Directive (EMD2), which ceases to exist as a separate law. The PSR applies directly in all 27 member states, with no national transposition, and takes over most of the conduct rules: strong customer authentication, user rights and obligations, open banking, fee transparency and fraud prevention. That is a structural shift. The divergent national readings that undermined PSD2 will no longer be legally possible on the operational core.
| Topic | Instrument | Legal effect |
|---|---|---|
| Authorization, capital and supervision of PIs and EMIs | PSD3 (directive) | National transposition |
| SCA, exemptions, liability | PSR (regulation) | Directly applicable |
| Open banking (interfaces, dashboards) | PSR (regulation) | Directly applicable |
| Refunds for manipulation fraud | PSR (regulation) | Directly applicable |
| E-money (formerly EMD2) | PSD3 (directive) | Folded into the payment institution regime |
Fraud rules make up the bulk of the new obligations
- Refunds for spoofing victims: when a fraudster impersonates the bank, using its phone number, name or email, to trick a customer into a credit transfer, the PSP will have to refund the customer, provided the victim has filed a police report and was not grossly negligent.
- Payee name checks against the IBAN extend to all credit transfers, building on the Verification of Payee (VoP) already required under the Instant Payments Regulation.
- Fraud data sharing between PSPs: a legal basis to exchange fraudulent IBANs and risk signals through shared arrangements.
- Customer awareness and staff training requirements, with supervisors tracking fraud indicators.
Open banking loses its workarounds
- Dedicated interfaces (APIs) become mandatory for account information and payment initiation providers, with published performance and availability requirements.
- Permission dashboards in the customer’s online banking, where users can see and revoke the access they have granted to third parties.
- An explicit ban on the obstacles that dogged PSD2, such as unnecessary re-authentication and degraded user journeys.
- The general requirement for a fallback interface goes away, replaced by remedial measures when an API fails.
Wider access to payment systems, bank accounts and cash
The package gives non-bank payment institutions the right to join designated payment systems directly, through an amendment to the Settlement Finality Directive (SFD). It also sets rules for their access to safeguarding accounts at banks, which will have to give reasons for any refusal. On cash, merchants will be able to offer cash withdrawals without a purchase, capped at €150 per transaction, and independent ATM operators get a lighter regime. Both measures aim to keep cash available outside major cities.
Eight years after PSD2, the PSD3/PSR package is less a conceptual overhaul than a demanding consolidation: fewer gray areas, more measurable obligations and a clear tilt toward protecting the payer. Firms that treated PSD2 as a compliance chore will see more of the same. Those that used it as a competitive edge will finally get a harmonized playing field.