The Consumer Financial Protection Bureau’s Section 1033 open banking rule, originally finalized in October 2024 with a compliance deadline of April 1, 2026 for the largest institutions, is now enjoined by a federal court. The CFPB itself moved to withdraw the rule in early 2026, with its chief legal officer Mark Paoletta filing a motion stating that under new leadership the agency considered the rule to be unlawful and should be set aside.
The reversal is significant. Section 1033, which would have required banks and financial institutions to make consumer financial data available to authorized third parties in standardized electronic formats, represented the most consequential data-sharing mandate in US financial regulation. Its suspension creates a vacuum that the industry must now navigate without clear federal guidance.
What the Rule Would Have Required
Under the finalized rule, covered entities including depository institutions with 850 million dollars or more in assets and certain nonbanks would have been required to make consumer financial data available upon request. Covered data included transaction histories from the past 24 months, account terms and conditions, and personal account information. The data had to be provided in machine-readable formats through developer interfaces, effectively mandating API access.
The compliance timeline was staggered. The largest institutions faced an April 2026 deadline, with smaller covered entities given until April 2030. The rule also established standards for authorized third parties, requiring them to limit data collection to what was reasonably necessary and to allow consumers to revoke access.
The Legal and Political Context
The rule’s withdrawal reflects the broader policy shift at the CFPB under the current administration. The agency initiated an Advance Notice of Proposed Rulemaking in August 2025 to reconsider the rule, signaling that a wholesale rewrite rather than minor amendments was under consideration. Key issues flagged for reconsideration include the definition of authorized representatives, fee structures for data access, data security requirements, and privacy protections.
Banking industry groups, particularly the Bank Policy Institute, supported the reconsideration. Their objections centered on the cost of building and maintaining APIs, the liability framework for data breaches by third parties, and the argument that the original rule exceeded the CFPB’s statutory authority under Dodd-Frank.
Fintech companies and consumer advocacy groups opposed the withdrawal, arguing that screen scraping, the existing method for accessing bank data without APIs, creates greater security risks than the standardized interfaces the rule would have mandated.
What Happens in the Absence of Federal Rules
Without a federal mandate, open banking in the United States reverts to its current state: a patchwork of bilateral agreements between banks and data aggregators, governed by contract law rather than regulation. Plaid, MX, Finicity, and other aggregators will continue operating under existing agreements, but the path to universal, standardized access is now indefinite.
Some market participants are proceeding as though open banking standards will eventually apply. The Financial Data Exchange, an industry consortium, continues developing technical specifications for data sharing. Banks including JPMorgan Chase, Wells Fargo, and Capital One have built API-based data access portals that function independently of regulatory mandates. But these are voluntary, and their terms can be changed unilaterally.
For fintechs that built business models on the assumption of mandated data access, the injunction introduces strategic risk. Companies in the account aggregation, personal financial management, and lending verification spaces now face the possibility that banks could restrict or price data access without regulatory constraint.
The International Contrast
The US pause stands in contrast to accelerating open banking implementation globally. The UK’s Open Banking framework, now in its seventh year, has enabled over 11 million consumer and business users to connect accounts to third-party services. The EU’s PSD3 proposal would expand data-sharing requirements beyond payments to investment accounts and insurance. Australia, Brazil, and India all have operational open banking frameworks.
This divergence creates complexity for global fintechs operating across jurisdictions. A company building data-driven financial products must now maintain different technical and legal architectures depending on whether it operates in markets with mandated API access or markets where access depends on bilateral negotiation.
Strategic Considerations for Financial Institutions
For banks, the injunction provides temporary relief from compliance costs but does not eliminate the underlying market pressure. Consumers increasingly expect to connect their financial accounts to third-party tools, and refusing access creates friction that drives customers toward institutions with more permissive data policies.
The more forward-looking strategic response is to treat data access as a competitive capability rather than a regulatory burden. Banks that build robust, well-governed APIs now position themselves for whatever framework eventually emerges, whether federal regulation, state-level mandates, or continued voluntary standards. Those that use the regulatory pause to defer investment may find themselves at a disadvantage when clarity returns.