PSD3 and the Payment Services Regulation: A Regulatory Research Guide for 2026

PSD3 and PSR research must connect the evolving legal texts to concrete payments topics and implementation questions.
The proposed Third Payment Services Directive (PSD3) and Payment Services Regulation (PSR) are intended to modernize the European Union’s payment-services framework. The package addresses payment fraud, consumer protection, open banking, competition between banks and non-bank payment service providers, and more consistent enforcement.
As of the European Parliament Legislative Train update dated 1 August 2026, the files were described as close to adoption. Parliament and Council reached a provisional political agreement on 27 November 2025, and the agreed text was approved by the Parliament’s ECON committee on 5 May 2026. Formal adoption remained necessary before entry into force.
That status matters. Teams should distinguish the Commission’s original 2023 proposals, Parliament and Council positions, the provisional agreement and the final adopted texts when available. Treating these versions as interchangeable is a common source of research error.
What are PSD3 and PSR?
The Commission proposed the package on 28 June 2023 as part of its review of PSD2.
PSD3 is a proposed directive addressing authorization and supervision of payment institutions and electronic money institutions, among other matters. As a directive, it requires implementation through national law.
PSR is a proposed regulation containing directly applicable conduct requirements for payment and electronic money services, including transparency and the rights and obligations of providers and users.
The split is intended to support more consistent conduct rules across the EU while retaining a directive for institutional and supervisory elements requiring national implementation.
Why the package matters to payments organizations
Fraud prevention and liability
The provisional agreement places significant attention on fraud prevention. According to the Parliament’s August 2026 summary, the agreed PSR text includes responsibilities relating to fraud-prevention mechanisms, verification of payee information, strong customer authentication, risk assessment and customer controls.
The exact operational effect depends on the final legal text, associated standards and implementation timeline. Payments organizations should avoid designing controls from summaries alone.
Impersonation fraud
The agreed framework addresses cases in which a fraudster impersonates a payment-service provider employee and manipulates a customer into authorizing a payment. This raises detailed research questions about eligibility, reporting, evidence, reimbursement and the relationship with a customer’s conduct.
Verification of payee
Requirements concerning the match between a payee’s name and unique identifier can affect payment journeys, exception handling, customer messages and operational processes. Teams should map the final PSR text against other applicable verification-of-payee obligations and implementation programs.
Open banking
The package seeks to improve the functioning of open banking, including access, interfaces and the relationship between account-servicing payment service providers and third-party providers. Product, legal and API teams will need a shared interpretation of the final rules and technical standards.
Transparency and charges
The Parliament’s summary highlights information about charges, including currency-conversion and certain cash-withdrawal fees. Compliance research must follow requirements from the legal provision through customer journeys, disclosures and testing evidence.
Access to payment accounts
The framework also addresses the conditions under which payment institutions obtain and maintain access to accounts with credit institutions. This is relevant to competition, de-risking and the operational relationship between banks and non-bank providers.
The research questions teams should prepare now
Scope and entity mapping
Which group entities and services fall within each instrument?
Which requirements apply directly and which require national transposition?
How do rules apply to branches, agents and cross-border services?
Fraud and customer protection
Which controls are required before liability consequences apply?
What evidence must be retained for an impersonation-fraud claim?
How do customer notification and investigation timelines interact?
What exceptions or allocation rules appear in the final text?
Authentication
How does the final package change strong customer authentication requirements?
Which exemptions and transaction-risk processes remain available?
What changes are needed in customer interfaces and monitoring?
Open-banking interfaces
What performance and availability expectations apply?
How will permission dashboards and customer controls work?
Which obstacles to third-party access are prohibited?
What standards will be defined through later technical measures?
Implementation
When do the regulation and national transposition requirements apply?
Which delegated acts, regulatory technical standards or guidelines are still pending?
Which policies, contracts, controls and product journeys need change?
A source hierarchy for PSD3 and PSR research

Researchers should label each source by authority and status instead of flattening final rules, negotiating positions and guidance into one corpus.
Source | What it establishes | Research caution |
|---|---|---|
Final Official Journal text | Adopted legal requirements | Check application and transition provisions |
Provisional agreement text | Political compromise before formal adoption | May still receive legal-linguistic changes |
Parliament and Council positions | Negotiating positions | Not the final combined rule |
Commission proposals | Original policy design and drafting | Later negotiations may change provisions |
Regulatory technical material | Detailed implementation | Confirm mandate and legal status |
Speeches, briefings and commentary | Context and interpretation | Not a substitute for primary authority |
Every research answer should tell the reader which layer it uses.
Build a PSD3/PSR obligations map
A useful obligations map connects five elements:
Provision: the exact article, paragraph or recital.
Interpretation: the approved internal explanation of what it requires.
Applicability: affected entities, products, jurisdictions and dates.
Implementation: policies, systems, contracts and controls that operationalize it.
Evidence: records demonstrating that the control was designed and operates.
This turns regulatory research into a managed implementation process. It also makes later questions easier to answer because teams can move from a rule to the responsible owner and supporting evidence.
How source-grounded AI can help
Payments regulation is a strong use case for source-grounded research because the relevant material is extensive, versioned and interconnected.
An AI research layer can help teams:
compare versions of proposed and agreed text;
locate provisions relevant to a specific operational question;
create cited summaries for product and control owners;
compare external requirements with internal policy;
identify repeated questions and unresolved interpretation gaps.
The system should label source status and date clearly. It should also refuse to treat an unresolved proposal as a final obligation.
How Nouswise supports payments-policy research
Nouswise allows a team to build a curated library of regulations, legislative materials, supervisory publications and approved internal interpretation. Users can ask natural-language questions and inspect the evidence behind the answer.
For PSD3 and PSR, a pilot could begin with the Commission proposals, Parliament and Council materials, the provisional agreement and selected internal policies. A benchmark could test 30 representative questions across fraud, authentication, transparency and open banking.
As final texts and technical measures emerge, content owners can update the collection while preserving a controlled research workflow.
Frequently asked questions
Have PSD3 and PSR entered into force?
The European Parliament’s Legislative Train page, updated 1 August 2026, described the package as close to adoption and stated that formal adoption was still required. Always verify the current Official Journal and legislative files before relying on this status.
What is the difference between PSD3 and PSR?
PSD3 is a proposed directive focused substantially on authorization and supervision, while PSR is a proposed regulation containing harmonized conduct rules for payment services. Their final relationship must be read from the adopted texts.
Does PSR replace PSD2 immediately?
No immediate replacement should be assumed. Application and transition depend on final adoption, publication, entry-into-force provisions and, for PSD3, national transposition.
Can AI determine whether a payment-service provider is compliant?
AI can support research and evidence mapping. A compliance conclusion requires verified facts, qualified interpretation and accountable review.
Conclusion
PSD3 and PSR research is a version-control problem as much as a reading problem. Teams need to know which text they are using, how it changed and which operational decisions depend on it.
Nouswise can support a bounded PSD3/PSR research pilot using approved legislative sources, internal documents and an expert-reviewed question set.
Written by:
Ali Moezzi
CTO
Share with friends:

