Seven years after the UK's Open Banking Implementation Entity forced the nine largest retail banks to open their APIs to third-party providers, not one of those institutions has built a revenue line worth reporting from that connectivity. The infrastructure exists, and the adoption numbers are undeniably impressive, yet the money is completely absent. The open banking revenue model is structurally broken because the regulators who designed it have no incentive to fix what they do not consider a problem. Conventional wisdom holds that this is a long-cycle infrastructure play, suggesting that monetization will follow adoption the way app stores followed the smartphone. That argument has been made for eight years now, and the evidence says otherwise. The entities that actually captured the economics include Plaid, Tink before its Visa acquisition, and Finicity before Mastercard absorbed it. These companies generated returns by building toll booths between the banks and the fintechs, rather than by changing underlying banking economics. The banks that opened their APIs got nothing, which means they are trapped maintaining systems they cannot monetize. On top of that, the regulatory framework governing this ecosystem was explicitly designed to prevent them from charging for the access they provide, leaving them with pure cost exposure.
The Consensus Treats Infrastructure as Strategy
The dominant narrative in institutional fintech coverage assumes that banks investing in API connectivity are positioning for a future where data becomes a monetizable asset. In this scenario, banks sit at the center of a financial data ecosystem and clip coupons on every account verification ping, credit decisioning call, and payment initiation request. Estimates from major consultancies cluster around massive ecosystem potential, with McKinsey and Accenture projecting that open banking could unlock up to $1 trillion in global value by 2030. The argument is seductive for banking executives looking to justify massive IT budgets to their boards. It is also almost entirely wrong about who actually captures that value.
Take JPMorgan Chase as the primary example of this disconnect. The bank built one of the most sophisticated API connectivity programs in the market, striking bilateral data-sharing agreements with dozens of fintechs to replace legacy screen-scraping. The stated rationale was to control data flows, reduce fraud, and eventually monetize that connectivity. As of early 2026, Chase's API program generates no disclosed API revenue. What it actually does is reduce the cost of data breach liability and keep regulators satisfied, which makes it a risk management exercise dressed up as a revenue strategy.
The situation is even more stark in Europe. Look at NatWest in the UK, one of the nine banks mandated into compliance in 2018. NatWest has invested materially in its API infrastructure, resulting in a developer portal that is genuinely well-built. But PSD2 and its UK equivalent explicitly prohibited banks from charging third-party providers for access to payment initiation and account information services. The regulation handed fintechs a free pipe into the banking system, and NatWest built that pipe. Because it cannot charge for the access, this outcome is not a strategy failure. It is a structural failure baked into the legislation from the start. The analyst houses predicting massive monetization are confusing ecosystem value with captured value, which leaves banking CFOs funding utility infrastructure while expecting software margins.
Four Facts That Settle the Argument
The debate over whether banks can monetize raw API access is resolved by looking at where capital has actually accumulated over the past half-decade. First, the aggregator layer captured the economics rather than the banks themselves. Plaid reached a $13.5 billion valuation when Visa attempted to acquire it in 2020, before the Department of Justice blocked the deal on antitrust grounds. Plaid's entire business model relied on charging fintechs for connectivity to banks that were legally required to allow that connectivity for free. The banks built the rails, while Plaid built the ticket machine. Plaid secured the multibillion-dollar valuation, leaving the banks with compliance costs and zero API revenue. This is the predictable outcome of a regulatory structure that mandates supply without creating demand-side economics for the supplier.
Second, Visa's subsequent acquisition of Tink for approximately $2.1 billion in 2022 confirmed the exact same pattern in Europe. Tink operated as a Swedish open banking platform that aggregated access to over 3,400 banks across the continent and charged businesses for that access. The banks whose infrastructure Tink built upon received nothing from that transaction. Visa paid $2.1 billion for the aggregation layer, not the underlying banking infrastructure, meaning European banks watched billions in enterprise value transfer to a Stockholm-based intermediary built entirely on their mandatory compliance work.
Third, the regulatory environment is actively expanding this broken model rather than correcting it. The CFPB's Section 1033 rulemaking in the United States, finalized in late 2024, followed the European model almost exactly. The rule mandated that banks provide consumer-permissioned data access at no charge to authorized third parties. Banks spent years lobbying for the right to charge reasonable access fees, and the final rule gave them nothing on that front. The Consumer Bankers Association estimated compliance costs running into the hundreds of millions of dollars across the industry. Revenue from that massive capital expenditure remains zero, which guarantees that American banks will repeat the European experience of funding infrastructure for third-party benefit.
Fourth, high usage does not equal financial traction. The UK's user base crossed seven million active users in 2023 and has continued to grow, with one billion API calls per month flowing through the ecosystem. The banks processing those calls have not disclosed a single basis point of net revenue attributable to access fees. The volume is undeniably real. The monetization is completely absent. High API call volume without a pricing mechanism is pure cost exposure driven by server loads and compute requirements that yield no direct financial return.
Why the Open Banking Revenue Model Fails the Banks
The fundamental flaw in the open banking revenue model is the assumption that data access naturally translates into data monetization. When regulators force the primary data custodians to provide access at zero marginal cost, the economic value of that data shifts entirely to the entities that process, analyze, and distribute it. Banks are operating under a framework where their primary role is utility provision. Utilities in other sectors, such as telecommunications or power generation, are allowed to charge wholesale rates to offset their heavy infrastructure investments. The current regulatory framework explicitly denies banks this mechanism. Without the ability to charge wholesale rates for API access, financial institutions are trapped in a cycle of perpetual infrastructure maintenance with no direct financial upside.
This dynamic explains exactly why the aggregator layer consolidated so quickly and at such high valuations. Companies like Plaid and Tink recognized that the banks were legally paralyzed. By positioning themselves directly above the free banking APIs, these aggregators created a synthetic wholesale market. They packaged the free banking data and sold it to fintechs, effectively capturing the revenue that a normal market structure would have allocated to the institutions generating the data. For a bank CFO, this means watching third parties build high-margin software businesses on top of cost centers that the bank is legally required to fund.
Indirect Benefits Are Real But Insufficient
The most serious counter-argument from banking strategists is that institutions are monetizing this connectivity indirectly. This theory suggests banks generate returns by retaining customers who might otherwise leave, by reducing fraud costs through verified data connections, and by building credibility with younger digital-native customers. Goldman Sachs made a version of this argument when discussing its Marcus platform's API connectivity strategy. The indirect benefits, the argument goes, are harder to measure but genuinely impact the bottom line.
This deserves a serious answer rather than a simple dismissal. The problem is that indirect monetization through retention and fraud reduction is precisely what every failed enterprise technology investment claims when direct revenue does not materialize. It is the exact argument made for core banking modernization projects that ran over budget and under-delivered for a decade, and it is the same justification used for bank mobile app investments in 2012. Sometimes the indirect benefits are real. Retaining customers who would have otherwise been lost is a valid business objective, but it is not a revenue model. It is a cost justification. Cost justifications do not fund the next generation of API infrastructure, and they rarely survive the scrutiny of the next CFO budget cycle when margins compress.
The data that would change this analysis is highly specific. The market needs a major bank to publicly disclose that connectivity contributed more than $100 million in net new annual revenue through premium API tiers, data analytics products sold to third parties, or payment initiation fees structured outside PSD2's free-access mandate. That disclosure has not happened in any jurisdiction. Until it does, the counter-argument remains theoretical, and the underlying economics remain structurally broken.
Who Pays for the Broken Open Banking Revenue Model
The failure of this economic structure does not affect everyone equally. The financial pain distributes differently across the ecosystem, and the near-term decisions of three specific stakeholder groups will determine whether this market finds a sustainable structure or continues to function as an expensive regulatory compliance exercise that benefits everyone except the institutions bearing the cost.
Institutional Investors
Investors who allocated capital to pure-play infrastructure businesses on the premise that bank API monetization would eventually drive revenues need to revisit those models immediately. The aggregator layer has already been consolidated, with Plaid, Tink, and Finicity absorbed by Visa, Mastercard, and the private markets respectively. The obvious venture exits are gone. What remains are second-tier aggregators and regional players competing on price in a market where the underlying product is legally required to be free.
The more interesting opportunity is in companies building value-added services on top of this data, such as credit risk analytics, cash flow underwriting, and fraud detection. Experian and TransUnion have both made acquisitions in this space, signaling where the actual enterprise value lies. The investment thesis should focus entirely on the analytics layer rather than the connectivity layer. The connectivity layer is a utility, and utilities do not get venture multiples.
The near-term trigger to watch is any secondary transaction in the pure-play connectivity space at a sub-5x revenue multiple. This would confirm that the market has repriced this category appropriately. Distressed sales in the UK and Benelux markets are the most likely signal, and that signal could arrive before the end of 2026.
Enterprise Buyers
For banks evaluating their technology investments, the rational strategy is to stop treating API infrastructure as a potential revenue center and start treating it explicitly as a cost-reduction and compliance tool. The banks that have done this clearly, such as HSBC and Barclays in the UK, have restructured their teams under technology and risk rather than product and revenue. They are making more honest resource allocation decisions than their peers who are still writing strategy documents about data monetization.
The product question that actually matters is whether banks can build premium data products that sit above the free-access mandate. Account aggregation for wealth management, cash flow analytics for SME lending, and verified identity for mortgage origination represent product lines where banks can charge because the value-add is in the analysis, not the data pipe itself. BBVA has been the most aggressive European bank in this direction, building analytics products that price the interpretation of the data rather than access to it.
The trigger for this segment will be the first major bank to publicly price a data analytics product at scale, with disclosed revenue above $50 million annually. That will confirm this is the right structural path, and that announcement will likely happen before the end of 2026 or the window closes as non-bank data providers consolidate the analytics layer too.
Product and Engineering Teams
For the engineers and product managers building this infrastructure inside banks, the message is uncomfortable but clear: stop optimizing for API call volume and start building for billable outcomes. The teams measured on developer portal signups and raw API call counts have been measuring the wrong things for years. Plaid understood this from day one, which is why it priced on use cases like account verification, income verification, and payment initiation rather than on raw access. That is why Plaid has a business and the banks it connects to have a compliance budget line.
The build-versus-buy question is now settled. Banks still maintaining proprietary connectivity infrastructure instead of using established aggregators are burning engineering resources on solved problems. The smarter allocation is on the analytics and decisioning layer where competitive differentiation is still possible and defensible. Monzo's data team, one of the most technically sophisticated in European retail banking, has consistently prioritized product outcomes over infrastructure optimization, and its unit economics reflect that choice.
The first bank to publicly break from the free-access model will likely be a mid-sized European institution rather than one of the global giants, operating in a jurisdiction where regulators are actively revisiting PSD2's successor framework. That bank will announce a tiered API pricing structure for commercial third parties within twelve months, citing long-term ecosystem sustainability. The EU's Financial Data Access regulation, currently in legislative negotiation, is the most likely mechanism to create that opening. If FIDA's final text preserves PSD2's free-access mandate intact, both predictions hold. If FIDA introduces commercial API terms, the distressed consolidation accelerates and the pricing announcement comes faster.
The story is not over. But its first chapter, the one where everyone benefits and data flows freely and banks somehow get paid, closed without a resolution. The next chapter belongs to whoever controls the analytics layer and is willing to charge for it.
If banks cannot charge for API access, why did so many of them invest so heavily in open banking infrastructure?
Because the alternative was worse. Screen-scraping, the practice fintechs used before open banking APIs existed, created genuine security and liability risks for banks. JPMorgan Chase estimated that managing screen-scraping relationships cost the bank tens of millions of dollars annually in fraud investigation and account security overhead alone. The investment in API infrastructure was a cost-reduction decision dressed up as a strategic positioning decision. The positioning narrative made the budget requests easier to approve internally, but that does not make it a revenue model.
Is Plaid's continued survival proof that there is a viable revenue model somewhere in open banking?
Plaid's model is viable precisely because it sits between the regulated entities and the market, charging the fintechs while the banks get nothing. Plaid's most recent reported valuation, around $6 billion following the collapsed Visa deal and subsequent private funding rounds, is less than half its 2020 peak. The market has already discounted the model significantly. Plaid survives because it owns the developer relationships and the use-case pricing structure. That is a distribution business built on top of the ecosystem. It is not monetization for the financial institutions providing the data, and the distinction matters entirely for institutional investors evaluating the space.
Will the EU's Financial Data Access regulation finally create a pricing mechanism that fixes this?
FIDA might create the legal framework for premium API tiers if the final text allows it, but it will not create market demand. The history of this regulation is a history of mandates that solve access problems and ignore economic sustainability for the access providers. The UK's Payment Systems Regulator acknowledged the sustainability concern explicitly in its 2024 roadmap. Acknowledgment is not resolution. Until a regulator mandates that commercial third parties contribute to infrastructure costs, the banks building that infrastructure will keep absorbing the cost alone, and the economics will stay broken.
Related MarketIntel briefing: read Open Banking Revenue Model Remains Broken for a connected view on this market signal.
Source context: readers can compare this market signal with broader data from S&P Global.
