📊 Full opportunity report: The mandate. Why the US conversational- finance surface does not translate to Europe. on ThorstenMeyerAI.com — validation score, market gap, and execution plan.
TL;DR
The US introduced a permissionless, API-driven personal-finance surface in May 2026, while Europe’s regulatory framework requires licensing and consent, fundamentally altering the market structure. This difference impacts who can build and operate such surfaces in Europe.
On May 15, 2026, OpenAI launched its personal-finance surface in the United States using a permissionless approach, allowing companies to connect accounts across thousands of institutions without licensing or regulatory approval. In contrast, Europe’s regulatory environment prohibits such permissionless access, requiring licensed, consent-based systems governed by complex regulations. This fundamental difference means the US model cannot simply be replicated across the Atlantic.
In the US, the launch was straightforward: firms used existing APIs, like Plaid, to aggregate financial data without needing licenses or regulatory approval. This permissionless model allowed rapid deployment and a flexible user experience.
Europe’s approach is governed by a layered regulatory regime. The PSD2 directive, enacted in 2018, made account access a licensed activity, requiring third-party providers to obtain licenses and adhere to strict API standards. The upcoming PSD3 and the FIDA regulation will extend these requirements to encompass investments, pensions, and loans, creating a comprehensive licensing framework that is still in development, with operational dates around 2029-2030.
Additionally, the EU AI Act, effective August 2, 2026, classifies AI systems used in credit scoring and financial assessments as high-risk, supervised by financial regulators such as Germany’s BaFin. This regulatory overlay makes deploying a general-purpose, AI-driven conversational finance surface more complex and tightly controlled.
As a result, the European market favors licensed, consent-native firms that can navigate these regimes. The architecture shifts from a permissionless, product-first approach to a mandate-driven, compliance-first model, where licensing, consent dashboards, and conformity assessments are integral to the product design.
The mandate.
Why the US conversational-
finance surface does not
translate to Europe.
data, AI — vs zero in the US build
maximum penalty
mandate — is likely operational
bank data · it is a licensed activity
- Access built by private aggregators — Plaid, Yodlee, MX, Finicity
- No banking license required to read bank data
- Read-only design sidesteps money-transmission rules
- No single federal open-banking statute · the surface ships as a product
- Access is a licensed activity — AISP / PISP under PSD2
- Regulator authorization required; no permissionless route
- Explicit, revocable, SCA-governed consent regime
- A directly-applicable rulebook (PSR) · the surface must be licensed
The architecture diverges at the foundation: the American surface treats account access as a product you buy and consent as a button you tap, while Europe treats both as mandates you are licensed and supervised to fulfill. In the US, you ship a finance surface. In Europe, you license one.Thorsten Meyer · The Mandate · Agentic Commerce 03
Implications of Regulatory Architecture on Market Entry
This difference in regulatory architecture fundamentally alters the competitive landscape. In the US, permissionless access enables rapid innovation and the emergence of new entrants leveraging open APIs. In Europe, the requirement for licensing and consent-based frameworks raises entry barriers, favoring established incumbents and licensed specialists.
The shift from a permissionless to a mandate-based model may lead to slower deployment, increased compliance costs, and a more concentrated market structure. While it could enhance consumer protection and data security, it also risks reducing innovation speed and increasing market dominance by firms with existing licenses.
Ultimately, this architectural divergence impacts consumer outcomes, innovation trajectories, and the competitive dynamics of financial technology in Europe versus the US.
API-driven personal finance aggregator
As an affiliate, we earn on qualifying purchases.
As an affiliate, we earn on qualifying purchases.
European Regulatory Foundations and Market Structure
The US’s permissionless approach to open banking was enabled by private-sector initiatives like Plaid, which built APIs allowing companies to access financial data without regulatory approval. This facilitated rapid product launches and a flexible ecosystem.
Europe’s landscape is shaped by the PSD2 directive of 2018, which mandated licensed third-party access to bank data, requiring firms to obtain licenses and meet technical standards. The upcoming PSD3 and FIDA regulations are expanding this framework to include broader financial data, but they are still in legislative development, with operational implementation expected around 2029-2030.
The EU’s AI Act further complicates the landscape by imposing high-risk classifications on AI systems used in credit assessments, supervised by financial regulators rather than tech authorities. This layered, regulatory approach creates a fundamentally different environment from the US permissionless model, emphasizing compliance and licensing at every step.
“The American permissionless finance surface is built on a private, API-driven substrate, whereas Europe’s system is mandate-based, governed by complex, layered regulation.”
— Thorsten Meyer
European consent-based financial data platform
As an affiliate, we earn on qualifying purchases.
As an affiliate, we earn on qualifying purchases.
Uncertainties in European Market Adoption
It remains unclear how quickly European firms will adapt to the new licensing and AI regulations and whether the market will favor incumbents or foster new entrants under this mandate-driven architecture. The exact timeline for full implementation of FIDA and PSD3 is still uncertain, as is the impact on consumer choice and innovation speed.
PSD2 compliant banking API
As an affiliate, we earn on qualifying purchases.
As an affiliate, we earn on qualifying purchases.
Next Steps for European Financial Technology Development
Regulators are expected to finalize PSD3 and FIDA regulations by 2026-2027, with operational requirements likely phased in by 2029-2030. Firms are preparing for compliance, and some incumbents may leverage their existing licenses to expand services. Monitoring how new entrants navigate the licensing landscape and how AI classification impacts product deployment will be key in the coming years.

The Mechanics of Investment Banking: Execute Strategic Financial Analysis, Risk Assessment & Company Valuations — Includes Case Studies, Professional Excel Models & AI-Powered Deal Intelligence Suite
As an affiliate, we earn on qualifying purchases.
As an affiliate, we earn on qualifying purchases.
Key Questions
Why can’t the US permissionless finance surface be directly used in Europe?
Because European regulation mandates licensing, consent, and conformity assessments, making the permissionless, API-driven model incompatible without significant re-architecture.
How does the EU’s AI regulation impact financial services?
The AI Act classifies certain financial AI systems as high-risk, requiring supervised compliance and detailed AI classification, which increases complexity and oversight.
Will the European market see the same rapid innovation as the US?
Likely not in the short term, due to the higher compliance costs and licensing requirements, which favor established players and slow down new entrants.
What does this mean for consumers in Europe?
Consumers may experience slower rollout of new services but potentially benefit from higher data security and more robust oversight.
Source: ThorstenMeyerAI.com