US banks are building application programming interfaces, or APIs, to hand customers control over their own financial data. The push follows the Consumer Financial Protection Bureau’s Section 1033 rule, which requires banks to make transaction and account data available on request. An open banking API is the technical channel banks use to meet that requirement, replacing older methods that relied on stored passwords.
What an open banking API does in practice
Open banking, at its simplest, is a customer’s right to let a third party pull their own account data directly from the bank, without handing over login credentials. A budgeting app, a lender or an AI assistant can request the connection, but only with the customer’s permission. Before APIs existed for this purpose, most apps used screen scraping: they logged in with the customer’s own password and read the account page the way a browser would. Screen scraping is fragile and hands the aggregator the customer’s credentials. An API instead gives the aggregator a defined, permissioned data feed that the bank controls and can revoke.
The CFPB 1033 timeline banks are working against
Section 1033 of the Dodd-Frank Act became a final rule on 22 October 2024 and took effect on 17 January 2025, with compliance deadlines staggered by bank size. Fintechly has covered the rule’s rollout and the litigation challenging it in detail. The Bank Policy Institute and the Kentucky Bankers Association are among the groups that have challenged the rule, arguing it forces mass data sharing without adequate privacy safeguards.
The rule remains in effect, but it is not settled. On 22 August 2025 the CFPB issued an advance notice of proposed rulemaking asking for comment on two contested points: who counts as a consumer’s authorised representative when requesting data on their behalf, and whether a bank can charge a fee to cover the cost of responding to a data request. PYMNTS reported in August 2026 that a formal proposed rule is expected to follow, meaning the fee question banks and aggregators are building around today could still change.
Who is building the pipes
Three aggregators dominate the US market for open banking connections: Plaid, Akoya and MX. Each occupies a slightly different position. Plaid connects consumer accounts to thousands of apps and, more recently, to AI tools. Jelena McWilliams, Plaid’s president of corporate, legal and external affairs, wrote in July 2026 that consumers are now extending permissioned data access to AI assistants that build personal financial agents, and argued that consumer protections need to travel with the data wherever it goes.
Akoya runs a bank owned network built specifically around API access rather than screen scraping, with Wells Fargo, U.S. Bank, JPMorganChase and core provider Jack Henry among the institutions connected to it. MX, the third major aggregator, describes itself as a leader in open finance and confirmed a new connectivity partnership with core provider Lumin Digital on 10 September 2026, evidence that bank side integration work is still expanding well over a year after the rule took effect.
A bank’s own move: JPMorganChase and Akoya
The clearest evidence of where the fee debate is heading sits in a real contract. On 18 November 2025, Akoya and JPMorganChase renewed their data access agreement with what the companies described as an updated pricing structure. Akoya’s chief executive, Paul LaRusso, said the company was created “to give consumers greater control over their financial data, safely and securely.” JPMorganChase’s head of consumer payments, Melissa Feldsher, said the bank remained “committed to advancing the open banking ecosystem” through the partnership.
The renewal predates the CFPB’s fee reconsideration by nine months, which suggests banks and aggregators are not waiting for the regulator to settle the question before negotiating pricing directly with each other.
What this means for banks still on the sidelines
Smaller banks without a direct aggregator relationship are exposed on two fronts. They remain liable under Section 1033 for making data available even without an API of their own, and they typically rely on a core provider or a middleware partner to build the connection for them, the same role Lumin Digital plays for MX. Compliance teams evaluating a vendor in this space benefit from the same due diligence they would apply to any regtech purchase. Fintechly’s guide to regtech versus compliance tech sets out how to separate genuine automation from a relabelled manual process, a distinction that matters as much for data sharing APIs as for transaction monitoring.
A fuller list of infrastructure providers building this layer, including the aggregators named above, is on Fintechly’s infrastructure sector directory.
Frequently asked questions
What is open banking, and does Section 1033 force banks to offer it for free?
Open banking is a customer’s right to let a third party pull their account data directly from the bank instead of scraping it with a password. Section 1033 does not yet settle whether a bank can charge for that access. The CFPB opened that question for comment in August 2025 and has not issued a final answer.
Is screen scraping now banned under the CFPB’s rule?
No. Section 1033 does not outlaw screen scraping outright, but it pushes the market toward API based access instead. Akoya has publicly called on the CFPB to phase out screen scraping and restrict how aggregators reuse the data they collect.
How does a smaller bank know if its core provider already supports a 1033 compliant API?
The fastest check is to ask the core provider directly which aggregator networks it already connects to. Jack Henry, for example, has been a member of Akoya’s network since 2021, so banks running on that core may already have the plumbing in place without having built anything themselves.
Who is liable if a fintech misuses data it pulled through a bank’s open banking API?
Liability runs through the permission and the contract, not just the API connection. Banks, aggregators and the fintechs they onboard each carry obligations under Section 1033 and their own data sharing agreements, and the CFPB’s pending rulemaking on the representative definition is partly aimed at tightening who can request data on a consumer’s behalf.