UK Payment Services Regulation 2026: What the Proposed Reforms Mean for PIs and EMIs
- 3 days ago
- 12 min read

UK Payment Services Regulation 2026: What the Proposed Reforms Mean for PIs and EMIs
UK payment services regulation is entering its most significant period of reform since the Payment Services Regulations 2017 came into force. In July 2026, HM Treasury launched a major consultation on modernising the rules governing Payment Institutions, Electronic Money Institutions and the wider payments market, with proposals covering traditional payment services, stablecoins, tokenised money, Open Banking and payments initiated by AI agents.
For existing PIs and EMIs, the reforms do not change current FCA permissions or regulatory obligations immediately. The Payment Services Regulations 2017 and Electronic Money Regulations 2011 remain in force, and firms must continue to comply with the existing regime. However, the proposals provide a clear indication of where UK regulation is heading and could materially affect firms planning new products, expanding their existing permissions or developing services involving stablecoins and other forms of tokenised money.
The commercial significance is therefore less about what firms must change today and more about what they are planning for the next 12 to 24 months. A PI or EMI developing a new payment product now may ultimately launch into a different regulatory framework, particularly where the model involves tokenisation, Open Banking or greater automation. The HM Treasury consultation on modernising payment services regulation closes on 6 October 2026.
What is changing in UK payment services regulation?
The Government is reviewing both the structure of the existing regulatory framework and how it should accommodate technologies that were not contemplated when the current legislation was written. This includes considering which requirements should remain in legislation, which should move into FCA rules, how regulated payment activities should be structured and how new forms of digital money should fit within the payments perimeter.
The main proposals can be summarised as follows:
Area | Proposed direction |
Payment Services Regulations and Electronic Money Regulations | Modernise the existing legal framework |
FCA rules | Give the FCA greater responsibility for detailed payment requirements |
Regulated payment activities | Review and potentially simplify the existing activities |
Stablecoins and tokenised money | Bring certain tokenised payment services within the payments framework |
Existing PIs and EMIs | Require a potential Variation of Permission before offering tokenised payment services |
Open Banking | Establish a more permanent regulatory and commercial framework |
AI and agentic payments | Review rules on consent, authentication and liability |
Senior management | Consider stronger accountability for financial crime and risk management |
The overall direction is towards a framework that regulates the economic activity being performed rather than creating a completely separate regime each time payment technology changes. In principle, that could make the UK more attractive for innovative payment firms. In practice, much will depend on whether the final rules make the regulatory perimeter clearer or introduce new overlaps between payments, electronic money and cryptoasset regulation.
Why are the Payment Services Regulations being reformed?
The existing framework has supported a large and innovative UK payments market, but the technology underpinning payment services has moved considerably faster than the legislation. Payment businesses increasingly combine traditional bank transfers and payment accounts with stablecoins, blockchain settlement, embedded finance, Open Banking and automated technology.
This creates regulatory questions that were far less common when the current rules were developed. A cross-border payment firm, for example, might receive GBP from a customer, use a stablecoin to settle value internationally and then arrange payment to the beneficiary in local currency. To the customer, that may simply be one international payment. From a regulatory perspective, however, the transaction could involve payment services, stablecoins, cryptoassets, custody and safeguarding depending on exactly how the model is structured.
HM Treasury’s objective is to create a framework that can accommodate both traditional and tokenised payments without requiring regulators to reinvent the rules for every new technology. That is particularly important as fintech firms increasingly use blockchain and digital assets as infrastructure rather than offering them as standalone investment products.
For founders and existing regulated firms, this means regulatory analysis needs to start with the actual customer journey and flow of funds. The fact that a business describes itself as a payment platform, digital wallet, stablecoin company or infrastructure provider does not determine which permissions it needs.
More detailed payment rules could move into the FCA Handbook
One of the most important structural proposals is to give the FCA greater responsibility for detailed payment regulation. Many requirements currently sit directly within the Payment Services Regulations and Electronic Money Regulations, which means changing them can require a legislative process even where the issue is relatively technical.
The Government is considering retaining core matters such as the regulatory perimeter, key definitions and important statutory protections in legislation while allowing more detailed firm-facing requirements to be set through FCA rules. This could make the regime more responsive as payment technology and business models evolve, while also bringing payment regulation closer to the model used across much of the wider UK financial services framework.
Strong Customer Authentication illustrates the direction of travel. The Government has already indicated that it wants to move away from some prescriptive legislative requirements and give the FCA greater scope to develop an outcomes-based approach. Similar changes could eventually affect other operational, conduct or prudential requirements.
For regulated firms, greater flexibility at FCA level may also mean more frequent regulatory change. Compliance teams will need effective processes for monitoring consultations, policy statements and Handbook changes, assessing their impact and ensuring that implementation is properly governed. A more agile regulatory regime is not necessarily a lighter one; it may simply allow the FCA to respond more quickly where it identifies new risks or weaknesses.
Stablecoins and tokenised payments could move into the mainstream payments framework
The treatment of stablecoins is likely to be one of the most commercially significant parts of the reforms. Stablecoins can operate as tradable cryptoassets, but they can also function as money-like instruments within a payment chain. The Government now intends to regulate the use of certain stablecoins for payments and create a framework in which traditional and tokenised payment services can operate alongside one another.
This matters particularly for cross-border payments, remittance, treasury platforms, wallets and fintech businesses using blockchain for settlement. A firm may use a stablecoin purely as an internal settlement mechanism, while another may allow customers to acquire, hold, transfer and redeem the stablecoin directly. Although both businesses may describe themselves as providing stablecoin payments, the regulatory analysis can be very different.
The key questions are who receives the customer’s funds, who owns or controls the stablecoin at each stage, whether the customer is exposed to the cryptoasset, who executes the payment and whether custody or exchange activities are being performed. The flow of funds and legal responsibilities matter more than the technology being used.
The Government’s proposed direction is that certain UK-issued qualifying stablecoins, and potentially some overseas stablecoins issued under recognised comparable regimes, could be treated as sufficiently money-like to sit within the payments framework when used for regulated payments. Other cryptoasset activities would continue to fall within the separate cryptoasset regime. Firms planning these models therefore need to consider both frameworks rather than assuming that a PI, EMI or cryptoasset permission alone will necessarily cover the complete service.
Existing PIs and EMIs may need a Variation of Permission
One of the clearest proposals in the consultation is that currently authorised or registered firms may need to obtain a Variation of Permission from the FCA before providing payment services using tokenised money. The Government recognises that a tokenised version of an existing payment service may introduce different risks even where the underlying customer proposition appears similar.
For an existing PI or EMI, this is particularly relevant where the firm is considering stablecoin settlement, blockchain-based cross-border payments, tokenised treasury services, programmable payments or other mixed fiat and digital-asset flows. Existing authorisation should not be treated as a blanket permission to introduce any new payment technology.
A firm considering a new product should assess whether the activity remains within its existing permissions, whether additional regulated activities arise and whether its safeguarding, financial crime, operational and governance arrangements remain appropriate. This assessment should take place before the product is launched and ideally before the technical and contractual structure becomes difficult to change.
Where the business is adding or materially changing regulated activities, our guide to FCA Variation of Permission applications explains the existing process in more detail.
The Government wants to reduce overlap between payments and cryptoasset regulation
A major challenge in regulating stablecoin payments is avoiding unnecessary duplication. Without careful drafting, one transaction could potentially engage the payments regime and the new cryptoasset regime at the same time, requiring firms to analyse multiple permissions for activities that form part of a single economic service.
The Government has signalled that it does not want firms to obtain two sets of permissions for the same activity unnecessarily. Its proposed approach would bring certain UK-issued qualifying stablecoins into the payments framework and remove some overlapping cryptoasset intermediary requirements where appropriate. Exchanges between qualifying UK-issued stablecoins and money, for example, are intended to be treated differently from exchanges involving other cryptoassets such as Bitcoin.
This does not mean that every business involving stablecoins will become a payment firm. A company providing cryptoasset custody, exchange, trading or broader digital-asset services may still require separate authorisation under the UK cryptoasset regime. The regulatory outcome will depend on the complete set of activities undertaken by the business.
For BCC’s core payment and e-money clients, the important point is that the regulatory boundary between payments and digital assets is becoming more relevant. Firms adding stablecoin functionality should establish that boundary before selecting infrastructure partners, designing customer contracts or committing to a particular operating model.
Open Banking is moving towards a permanent regulatory and commercial framework
Open Banking is also moving into its next phase. The current UK framework has developed through a combination of the Payment Services Regulations, CMA requirements and industry standards, but the Government now wants to establish a longer-term structure with clearer FCA powers and a more sustainable commercial model.
A central proposal concerns Variable Recurring Payments. These allow customers to authorise a series of future account-to-account payments within agreed parameters, rather than approving every transaction individually. The Government intends to create a new right of access to support their development, which could significantly expand Open Banking payments into subscriptions, recurring merchant payments, account sweeping and automated business payments.
The consultation also considers the future role of a central standards-setting body and commercial Open Banking schemes, alongside potential FCA powers over interfaces, standards and pricing. Existing statutory access rights remain important, but the Government wants to create commercial incentives for banks and payment firms to invest in new Open Banking products while preserving competition.
For PISPs, AISPs, banks, EMIs and payment institutions, the opportunity is potentially significant. Account-to-account payments could become a stronger alternative to cards and Direct Debits across a wider range of use cases, but firms will also need to understand how participation, access rights, commercial arrangements and FCA requirements develop as the new framework takes shape.
AI agents could create a new category of payment risk
The consultation also addresses agentic payments, where AI systems can act with a degree of autonomy on behalf of consumers or businesses. An AI agent might compare suppliers, select products, initiate purchases, approve transactions within agreed limits or manage recurring expenditure without requiring a person to make each individual payment decision.
Existing payment regulation was not designed around that model. If a customer gives an AI agent authority to manage purchases within a monthly budget, questions arise over when payment consent was given, when authentication should occur, what happens if the agent exceeds its mandate and who bears responsibility for an unauthorised transaction.
The Government is therefore considering whether existing rules on authentication, consent and liability need to be adapted. This is still an early-stage policy area, but it matters for fintech firms developing AI-driven treasury, procurement, commerce and payment products because the regulatory perimeter will continue to depend on what the system actually does.
Calling software an AI agent does not make the underlying payment activity unregulated. Where a platform initiates payments, controls the movement of customer money or performs another regulated payment service, existing or future FCA permissions may still apply.
Senior management accountability may also increase
The reforms are not solely focused on technology and innovation. HM Treasury has also highlighted risks within the payments and electronic money sector, particularly financial crime, and is asking whether enhanced ongoing responsibilities for senior managers could improve oversight and risk management.
No new senior management regime has been introduced for PIs or EMIs as a result of this consultation. However, the proposal is consistent with the broader direction of FCA supervision, where firms are increasingly expected to demonstrate clear ownership of regulatory risks and evidence that governance arrangements operate effectively in practice.
Boards and senior management should be able to show who owns safeguarding, financial crime, compliance and other material risks, how those risks are monitored and how weaknesses are escalated and addressed. Written policies and responsibility maps are necessary, but they are not enough on their own if management information, challenge and decision-making do not demonstrate effective oversight.
Existing firms should therefore view the consultation as another signal that regulatory governance is likely to become more important, particularly as business models become more complex and firms introduce new technologies or products.
What should existing Payment Institutions and EMIs do now?
Existing PIs and EMIs do not need to redesign their businesses simply because the consultation has been published. The current Payment Services Regulations and Electronic Money Regulations remain in force, and most of the proposals will require further legislation and FCA rule-making before they become operational.
Firms should, however, consider the reforms as part of product and regulatory planning where they intend to introduce stablecoin or tokenised payments, expand into Open Banking, change their acquiring or issuing model, introduce AI-driven functionality or materially alter the way customer funds move. A product expected to launch in the next 12 to 24 months should not be designed solely around assumptions about today’s regulatory framework.
The practical priority is to map the proposed product against the firm’s current permissions and identify potential regulatory gaps before significant investment is committed. Where the model changes the firm’s regulated activities, customer fund flows, safeguarding arrangements or risk profile, early analysis can determine whether a Variation of Permission or broader regulatory change may ultimately be required.
Firms should also remain focused on requirements that already apply. Safeguarding is an immediate FCA priority following the introduction of the strengthened PS25/12 and CASS 15 regime, including requirements relating to reconciliations, record keeping, audits, reporting and resolution arrangements. Our PS25/12 safeguarding guide covers the current requirements in detail.
What do the reforms mean for new FCA applicants?
Businesses currently seeking authorisation as an Authorised Payment Institution or Electronic Money Institution must continue to apply under the existing regulatory framework. The July 2026 consultation has not changed the current FCA application process or created new permissions that applicants can apply for today.
However, businesses whose plans include stablecoins, tokenised settlement, Open Banking or AI-driven payments should ensure their regulatory strategy reflects both the current model and the direction in which the business intends to develop. The FCA application should clearly explain how customer funds move, which entity performs each activity, who contracts with the customer, how safeguarding operates and which third parties are relied upon.
The mistake to avoid is beginning with a preferred licence and then trying to force the business into it. An EMI is not automatically the correct route because a business wants to offer digital accounts, just as a PI permission does not automatically cover every new method of moving value. The correct approach is to map the activities and flow of funds first, determine which activities are regulated and then identify the permissions required.
That discipline will become increasingly important as traditional payments, stablecoins, Open Banking and tokenised money converge. Regulatory structuring carried out before a product is built is usually considerably easier and less expensive than restructuring the business after technology, contracts and commercial partnerships have already been fixed.
How Buckingham Capital Consulting can help
Buckingham Capital Consulting has specialised in payment and electronic money regulation since 2013, supporting fintech businesses, Payment Institutions and Electronic Money Institutions with UK and European authorisation, regulatory structuring and ongoing compliance.
We advise new applicants on the appropriate regulatory route, prepare and manage FCA authorisation applications and support existing regulated firms where their business model or permissions need to change. Our work includes Payment Institution and EMI authorisation, regulatory perimeter analysis, Variation of Permission applications, safeguarding and CASS 15, financial crime frameworks, governance reviews and FCA regulatory engagement.
For businesses developing new payment products, the most valuable regulatory work often takes place before the application or product launch begins. Establishing which entity should perform each activity, how customer funds should move and which permissions are required can prevent unnecessary applications, launch delays and expensive restructuring later.
Where an existing PI or EMI is considering stablecoins, tokenised settlement, Open Banking or another material change to its operating model, the regulatory implications should be assessed before implementation. To discuss a new payment business, FCA authorisation or changes to an existing regulated payment model, contact Buckingham Capital Consulting.
Frequently asked questions
Are the Payment Services Regulations 2017 being replaced in 2026?
No. The Payment Services Regulations 2017 and Electronic Money Regulations 2011 remain in force. HM Treasury is consulting on a future modernised framework, including which requirements should remain in legislation and which could move into FCA rules. Any substantive changes will require further implementation before they affect firms.
Do existing PIs and EMIs need new FCA permissions now?
Not simply because the consultation has been published. Existing permissions remain valid, but HM Treasury proposes that authorised and registered firms should require a Variation of Permission before carrying out payment services using tokenised payments. Firms developing these services should therefore assess future permission requirements before launch.
Will stablecoin payments be regulated under UK payment services law?
The Government intends to regulate the use of certain stablecoins for payments and integrate qualifying tokenised payments into the future payments framework. The treatment will depend on factors including where the stablecoin is issued and what activities the firm performs. Separate cryptoasset permissions may continue to apply where a business provides activities such as custody, dealing or exchange outside the payment-services framework.
What do the reforms mean for firms applying for a PI or EMI licence?
Applications continue under the existing regulatory regime. Firms should nevertheless ensure their application accurately reflects any planned use of stablecoins, tokenisation, Open Banking or other new technologies. The appropriate permission should be determined from the actual activities, customer journey and flow of funds rather than from the product label the business uses.
When will the new UK payment services rules take effect?
There is no single implementation date yet. HM Treasury’s consultation closes on 6 October 2026, after which the Government will consider responses and develop the implementation framework. Further legislation and FCA rules will be required for many of the proposed changes, so existing firms must continue complying with the current regime until new requirements formally take effect.



