Regulatory News · May 5, 2026

On April 23-24, 2026, the Council of the EU published the final compromise texts for the Payment Services Regulation (PSR) and the third Payment Services Directive (PSD3). Publication in the Official Journal is expected by end of Q2 2026 with entry into force after a 21-month transition — realistically mid-to-late 2027.

What just happened

The European Parliament and Council reached provisional political agreement on the PSD3/PSR package on November 27, 2025. Five months later, on April 23-24, 2026, the Council published the final compromise texts (ST-8221-2026-INIT for PSR and ST-8222-2026-INIT for PSD3), clearing the path to formal adoption. Once published in the Official Journal and after the 21-month transition, the PSR — a directly applicable Regulation — will bind every payment service provider across all 27 EU member states without national transposition.

Five hard fraud requirements

The PSR extends IBAN-name verification, already mandatory on instant euro payments since October 9, 2025 under the Instant Payments Regulation, to every credit transfer including standard SEPA. Where the payer's input does not match the verified account holder name, the PSP must inform the customer of the mismatch within seconds — and if the customer proceeds anyway, liability shifts. PSPs must also share fraud data through a dedicated cross-institution platform; obligations extend to social media operators and telecoms providers. Transaction monitoring becomes mandatory, with block obligations on likely-fraudulent activity. Strong Customer Authentication is upgraded to require adaptive, risk-sensitive processes that reflect user behaviour, transaction patterns and emerging fraud typologies.

The AI language, direct not implied

Practitioner analysis of the compromise texts consistently identifies encouragement of AI in fraud detection as a headline change. This is unusual for EU financial services regulation, which has historically preferred principles-based language on technology. The PSR breaks that convention because authorised push payment fraud volumes have outrun what rule-based systems can catch. Behavioural biometrics inside the authentication flow and machine-learning risk scoring on inbound flows are, in practice, the only way to meet the accuracy the block-obligation and liability framework require.

Book a Demo

The UK precedent — what happens when you go first

The UK's Payment Systems Regulator launched mandatory APP fraud reimbursement on October 7, 2024. First-six-month results: 87% of eligible losses reimbursed, £66 million returned to victims, 86% of cross-firm reports made within two business hours. Two operational realities emerged that every EU PSP now faces: receiving PSPs have a real financial stake in fraud detection under a 50/50 split model, and inbound real-time detection is no longer optional. The UK also just layered on more pressure via the Fraud Strategy 2026-2029 (published May 6, 2026) and the Online Crime Centre, extending fraud accountability into telecoms and social media — exactly what PSR is now mandating across the EU.

What EU PSPs must do now

Assess your current fraud stack against the five PSR requirements. Confirm whether your transaction monitoring handles inbound flows in real time or only outbound. Plan for integration with the shared fraud intelligence platform. Upgrade SCA to adaptive risk-based authentication with behavioural biometrics. Rework internal liability and reimbursement processes to match the split-loss model. Most legacy TM systems were built for batch outbound scoring, not real-time inbound decisioning under block-obligation liability — the practical procurement window closes well before the mid-2027 deadline.

How UMCA helps

Aurora runs real-time bidirectional monitoring under 30ms per transaction, with ML-based fraud scoring, behavioural biometrics and a no-code rule builder that lets compliance teams adapt to new fraud typologies without engineering cycles. Our architecture is designed to consume shared fraud intelligence signals as first-class field sources — ready for the cross-institution platform PSR mandates. For EU-based Payment Institutions, E-Money Institutions and non-EU banks with EU operations, Aurora arrives with the operational shape that PSR requires already deployed at scale.

Book a Demo