Regulatory primer
PSD3 + PSR
Proposed PSD3 (COM(2023) 367) + PSR (COM(2023) 366) — Payment Services Directive 3 + Payment Services Regulation · European Union · Proposed — political agreement Nov 2025; OJ publication expected H1 2026
The PSD3 + PSR package is the proposed successor to PSD2. The PSR (regulation) carries the substantive operational articles — fraud prevention, transaction monitoring, strong customer authentication, exemption documentation. PSD3 (directive) covers licensing + supervision of payment institutions. Trilogue political agreement reached November 2025.
What it is
The Commission proposed the package in June 2023 as two instruments. The split: a Regulation (PSR, COM(2023) 366) directly applicable across member states, carrying the day-to-day operational obligations on payment service providers — fraud prevention, SCA, exemption documentation, dispute handling. A Directive (PSD3, COM(2023) 367) requiring transposition, covering licensing + supervision + market access for payment institutions + e-money institutions (which are merged into a unified 'payment institution' category).
Why two instruments? Regulations are directly applicable + harmonised; directives allow member-state transposition flexibility. The Commission chose regulation for operational rules (where divergence was a PSD2 pain point) + directive for licensing (where national supervisory practice retains relevance).
Drivers: an EBA review found the SCA exemption regime opaque, fraud prevention uneven across member states, dispute resolution inconsistent, the open-banking access layer underused. PSD3+PSR addresses each.
Status: political agreement reached November 2025 in trilogue. Formal Council + Parliament adoption + OJ publication expected H1 2026. PSR applies ~20 days after publication. PSD3 transposition typically 18 months → applicability ~2028.
Who's in scope
- Payment service providers: credit institutions, payment institutions, electronic money institutions (PSD3 merges PI + EMI), post-office giro institutions, central banks acting as payment processors.
- Account information service providers (AISPs) + payment initiation service providers (PISPs) — open-banking entities.
- Crypto-asset service providers offering fiat-related payment services interact with PSD3+PSR via MiCA + payment services overlap.
- Non-EU providers offering payment services in the EU through branches / representatives.
Key obligations
Proposed PSR Art. 83 — transaction monitoring + fraud detection
Payment service providers shall have transaction-monitoring mechanisms enabling the detection of unauthorised or fraudulent transactions, with obligations on explainability of fraud-detection decisions. Per-decision documentation expected for supervisor inquiries.
Proposed PSR Arts. 85-89 — strong customer authentication
SCA framework + risk-based / transaction-based exemption regime. Each exemption decision documented per transaction with risk score + exemption category + reproducibility on demand.
PSD2 Art. 95 — operational + security risk management (remains operative)
PSPs must establish a framework with appropriate mitigation measures + control mechanisms. Annual security-incident reporting. The PSR carries through + tightens these obligations.
Proposed PSR — open-banking access layer
Mandatory APIs for AISPs + PISPs replacing the screen-scraping fallback. SLA + uptime + fall-back requirements. PSR aims to make open banking actually work.
Proposed PSR — dispute + chargeback regime
Harmonised dispute-resolution timelines + liability allocation between consumer + PSP. Refund timing + investigation obligations.
Proposed PSD3 — payment-institution licensing + supervision
Unified payment-institution licence (merging PI + EMI). Capital + governance requirements. National competent authority supervision + cross-border passporting.
Timeline + applicability
- 28 Jun 2023Commission published the PSD3 + PSR proposal package (COM(2023) 366 + 367).
- Nov 2025EP + Council reached provisional political agreement in trilogue.
- H1 2026 (est.)OJ publication; PSR applies ~20 days later.
- ~2028 (est.)PSD3 transposition deadline (typically 18 months from OJ).
What's still being worked out
Areas where the regulation's interpretation is genuinely unsettled. Vendor pages skip this; we don't. Your counsel is the right venue for definitive guidance on your deployment.
- Final article numbering — political agreement reached but final text + numbering may shift in published version.
- Exact scope of the explainability requirement under Art. 83 — what 'reproducibility on demand' means for AI fraud-detection in practice is awaiting EBA technical standards.
- Liability allocation in authorised-push-payment fraud (APP fraud) — political compromise reached but national implementation may vary.
- How PSR's transaction-monitoring obligations interact with AMLD 6 risk-based approach — both apply but enforcement priority is unclear.
- Treatment of AI-driven decisioning in the open-banking access layer — PSR doesn't explicitly classify but supervisors are signalling concerns.
Sectors most affected
Primary sources
Where Promethean fits
Promethean's L12 chain operationalises the per-decision evidence demands across PSR Art. 83 (fraud-detection explainability) + Arts. 85-89 (SCA exemption documentation). Each fraud-classification or SCA-exemption decision is an L12 entry with the spec hash (model configuration), input hash (transaction context), output canonical hash (verdict + score), fallback flag, and (where applicable) reviewer verdict. A supervisor inspecting a flagged transaction can verify the inputs + configuration recorded match what the operator claims, via verify.mjs run air-gapped against the chain export.
What Promethean does NOT solve
- Fraud-monitoring system itself — Promethean is the audit-trail layer on top.
- Open-banking API implementation — that's the operator's PSR-compliant API layer.
- Dispute-resolution workflow — operator's customer-service + chargeback system.
- Licensing process under PSD3 — that's NCA + corporate work.
- AML/CFT obligations under AMLD — separate (but overlapping) regulatory regime.
FAQ
When does PSR apply?
OJ publication expected H1 2026 following the November 2025 trilogue agreement. The Regulation applies ~20 days after publication (no transposition period). The companion PSD3 directive requires transposition by member states (typically 18 months), with applicability ~2028. Best-estimate: PSR Art. 83 + 85-89 operational obligations bite from mid-2026; PSD3 licensing obligations from ~2028.
Why two instruments instead of one PSD3?
The Commission split operational rules (regulation, directly applicable, harmonised) from licensing + supervision (directive, member-state transposition, national-supervisor practice). The split addresses PSD2's main pain point — divergent member-state interpretations of operational rules — while preserving national-supervisor flexibility on licensing.
Are PSD2 obligations still operative?
Yes, PSD2 remains operative until PSD3 applies. The 2018-effective SCA RTS (Reg. (EU) 2018/389) continues to govern exemption practice. Most PSR provisions tighten what's already implicit in PSD2; supervisors aren't waiting for the new package before pushing on per-decision evidence demands.
Does PSR apply to my fintech SDK / SaaS vendor?
Directly: only if you're a licensed PSP (payment institution, e-money institution, etc.). Indirectly: every PSP using your SDK / SaaS carries PSR obligations that cascade to your evidence-generation capabilities. Practically, PSP customers will demand per-decision audit trails from AI-decisioning components as part of their PSR readiness programme.
What's the relationship between PSR + AI Act?
Concurrent regulation. PSR governs operational obligations on payment services; AI Act governs AI-system risk. Most fintech AI (credit scoring) is high-risk under AI Act Annex III §5(b); fraud-detection AI is carved out of Annex III but still subject to AI Act general obligations + PSR per-decision evidence demands. Per-decision audit log satisfies Article 12 AI Act (record-keeping) + PSR reproducibility simultaneously.