HM Treasury wants to rewrite the UK payments rulebook for a world of stablecoins, tokenised deposits, and AI agents that pay on your behalf. The consultation window to shape that rewrite closes at 11:59pm UK time on Oct. 6, 2026, which is 4:29am IST on Oct. 7.
TLDR
- HM Treasury published Modernising Payment Services Regulation on July 14, 2026. The consultation closes at 11:59pm on Oct. 6, 2026, and responses go by email to [email protected] or by post to the HMT Payments and Fintech team.
- The consultation document poses 42 questions covering the Payment Services Regulations 2017 (PSRs), the Electronic Money Regulations 2011 (EMRs), tokenised payments, stablecoins, agentic payments, and the next phase of Open Banking.
- Headline proposals: move detailed firm-facing rules from legislation into FCA rules, create one set of regulated payment activities covering both tokenised and non-tokenised payments, treat UK-issued qualifying stablecoins as “money-like” inside the payments perimeter, and add a new right of access for variable recurring payments (VRPs).
- On agentic payments, HMT says the PSRs predate AI and asks whether authentication, consent, and liability for unauthorised transactions need updating when an AI agent initiates a payment.
- Per Latham & Watkins (Oct. 1, 2026), HMT plans to prepare the Statutory Instrument during 2027 to 2028, with the FCA consulting on detailed rules in parallel. Alignment with the EU’s PSD3 is left open.
- This is a UK regulatory deadline explainer. It is distinct from US stablecoin rulemaking (Fed GENIUS Act NPRs), US open banking (Section 1033), and agentic payment vendor shortlists (best AI agent payment infrastructure providers).
Most payment consultations are about tidying definitions. This one is different because it touches four product roadmaps at once: tokenised payments, stablecoin payments, agentic checkout, and paid Open Banking APIs. If your firm holds or plans to seek UK payment institution, e-money, or stablecoin permissions, the answers HMT receives this week will shape what you need to apply for and what you can charge for.
For FintechSpecs operators, the buyer question is what changes to permissions, liability, and API economics you should argue for (or plan around) before the UK framework is rewritten. The practical deadline is short. A focused response on the handful of questions that touch your business model is more useful than an attempt to answer all 42.
What HM Treasury published, and the deadline
Per the GOV.UK consultation page:
- Publisher: HM Treasury.
- Published: July 14, 2026.
- Closes: 11:59pm on Oct. 6, 2026.
- Respond by email: [email protected].
- Respond by post: Payments & Fintech team, HM Treasury, Horse Guards Road, SW1A 2HQ.
- Stated scope: how the regulatory framework should be updated for innovations in tokenised payments, Open Banking, and agentic payments, while ensuring strong consumer protections.
The consultation document says it will remain open for 12 weeks. Latham & Watkins frames the work as delivering the Chancellor’s Mansion House 2025 commitment to modernise and future-proof the UK payments framework.
Operator take: If you only have time for a short response, answer the questions that change your permission set or your unit economics. For most fintechs that means Questions 10 and 11 (tokenised activities and variation of permission), 6 to 8 (stablecoins), 15 (agentic payments), and 21 to 23 (VRP access, API charging, and contracts).
The three aims and the “multi-money” framing
HMT states three aims for the framework: it should be clear, predictable, and proportionate; it should support competition and innovation; and it should deliver robust consumer protection.
Latham describes the government’s intent to future-proof UK law for an emerging “multi-money” ecosystem. That ecosystem includes tokenised payments, account-to-account payments for goods and services, and agentic payments where AI acts on behalf of consumers and businesses.
Proposal 1: More rules move from statute to the FCA
Core provisions, including the perimeter for regulated payment activities, would stay in primary legislation. HMT is weighing whether detailed technical requirements should shift from the PSRs and EMRs into FCA rules, similar to the earlier transition of the safeguarding regime.
Per Latham, Strong Customer Authentication (SCA) is already earmarked for revocation from the PSRs in favour of outcomes-based FCA rules, although few details on the plan or available exemptions have been confirmed. Questions 1 to 3 ask which firm-facing requirements should stay in legislation, what retained provisions need updating, and whether key definitions need to change.
Operator take: This is the cleanest opening to raise known pain points in the current PSRs and EMRs. If SCA friction, definitions, or legacy requirements have blocked a product, write that down with a concrete example and a proposed outcome.
Proposal 2: One activity list for tokenised and non-tokenised payments
Like the EU’s PSD3 track, HMT proposes a streamlined set of regulated payment and e-money activities. Per Latham, some existing categories would merge (such as cash placement or withdrawal from payment accounts) and others would split (such as issuing payment instruments and acquiring payment transactions).
The key design choice is that each activity would cover both non-tokenised fiat and tokenised payments. However, existing authorised and registered firms would need a variation of permission before providing tokenised payment services. Questions 9 to 14 cover the activity split, the single-list approach and its risks, the variation of permission requirement, smart contracts and programmable payments, and whether current conduct and prudential rules suit tokenised payments.
Operator take: A single activity list is good for roadmap clarity, but the variation of permission is the real gating item. Budget for that application in 2027 to 2028 planning if tokenised payments are on your product map.
Proposal 3: Tokenised deposits and the retail payments question
Per Latham, under the Financial Services and Markets Act 2000 (Cryptoassets) Regulations 2026, tokenised deposits already fall within the legal definition of a deposit and are regulated on a “same risk, same regulatory outcome” basis.
So the consultation asks a narrower question (Question 5): does the payment services framework itself create barriers to using tokenised deposits in retail payments? Banks exploring tokenised deposit rails should treat this as their chance to name specific frictions. For a live example of tokenised deposit infrastructure on the bank side, Chainlink connecting banks to Swift’s blockchain ledger is a useful contrast, but it covers a different layer (interbank ledger connectivity, not UK retail payments law).
Proposal 4: UK qualifying stablecoins enter the payments perimeter
This is the section stablecoin issuers and payment firms will read most closely. HMT intends to bring certain stablecoins out of the cryptoasset framework and into the payment services framework.
What Latham reports HMT is proposing
- “Money-like” treatment: Building on the new article 9M RAO activity of issuing a “qualifying stablecoin”, HMT proposes treating UK-issued qualifying stablecoins as money-like for payments purposes, on the basis that robust standards will already be secured under the new FSMA regime.
- Overseas coins: This treatment could in future extend to certain overseas-issued stablecoins where HMT formally recognises the issuing jurisdiction’s framework as achieving similar outcomes. Without recognition, overseas-issued stablecoins would be regulated as ordinary cryptoassets under the FSMA cryptoassets regime, not the payments regime.
- Permissions: HMT is considering whether authorised UK issuers of qualifying stablecoins should be able to provide related stablecoin payment services without additional permissions (subject to conditions), mirroring the position for credit institutions today.
- Safeguarding: HMT proposes that safeguarding tied to stablecoin payment services should sit under the payments regime rather than the separate cryptoasset safeguarding regime, to avoid dual authorisations.
- Interim fix already made: Per Latham, an HMT Statutory Instrument dated Sept. 16, 2026 removes the temporary holding of UK qualifying stablecoins from the scope of the cryptoasset safeguarding activity, where those coins are held temporarily in connection with a payment transaction.
Questions 6 to 8 ask whether only UK or recognised-jurisdiction stablecoins should be treated as money-like, whether UK issuers should get payment services without extra permissions, and whether safeguarding for payments should eventually move to the payments regime.
Operator take: If your UK roadmap depends on a US-issued or other overseas stablecoin, the recognition question decides whether that coin is treated as payments money or as a cryptoasset in the UK. That is a strategic answer to give HMT, not a footnote. Compare the US side of the same issue in our GENIUS Act compliance checklist.
Proposal 5: Agentic payments, authentication, and liability
The consultation document says the UK has a genuine opportunity to lead the world in agentic payments, and that the government wants the UK to be at the forefront of their global development. It also says the PSRs were designed before the development of AI and may not fully facilitate the use of agentic AI.
Question 15 is the one agentic payments teams should answer: how does existing payment services regulation need to adapt to support agentic payments, and do provisions on authentication and consent of payment transactions, and liability for unauthorised payment transactions, need updating? Question 16 invites views on other innovations HMT should account for. The document also points to the FCA’s Supercharged Sandbox as evidence of UK demand to test and scale new products.
Operator take: The industry has already shipped agent credentials, passkeys, and issuer trust frameworks. What it lacks in the UK is a clear statement of who is liable when an agent pays wrongly. Use your response to describe the consent and authentication evidence your product actually captures, and the liability split you think is fair. For protocol context, see ACP vs AP2 vs x402. For a live European example of passkey authentication in an agent payment, see Cleverbridge, Visa, and Revolut in France.
Proposal 6: Open Banking moves toward a priced ecosystem
Per Latham, HMT proposes two parallel tracks for Open Banking:
- Modernise the PSRs’ Rights of Access, including a new right of access for VRPs.
- Use the Data (Use and Access) Act 2025 (DUAA) to give the FCA broad rule-making powers over ASPSPs, PISPs, AISPs, and “interface bodies”, including the incoming Future Entity and commercial Open Banking schemes.
What changes for API economics
- HMT asks whether, and when, ASPSPs should be able to charge third parties for access they currently must provide free under the PSRs and the CMA’s Retail Banking Market Investigation Order 2017 (Question 22).
- HMT asks whether the ban on ASPSPs requiring a contract before granting access should be lifted (Question 23). Latham notes HMT’s example that a contract requiring a fee once API call volumes pass a high threshold may be reasonable.
- Access under the new VRP right would not need to be free, except for sweeping. HMT proposes keeping the existing requirement on relevant ASPSPs to enable sweeping VRPs free of charge (Question 31 asks whether that requirement should be maintained).
- The FCA could get powers to intervene directly in Open Banking access pricing, mandate ASPSP participation in commercial schemes, regulate the Future Entity, and hold monitoring and enforcement powers that mirror FSMA (Questions 28 to 38).
Latham sums up the direction as a shift from a mandated, largely free access model toward an industry-led, commercially priced ecosystem sitting on statutory foundations. HMT says it is committed to protecting third-party business models that depend on free API access, while also being alive to concerns about large firms consuming free APIs at scale.
Operator take: PISPs and AISPs whose margins assume free API calls should respond on Questions 22, 23, and 34 with volumes and unit economics. ASPSPs get a possible return on Open Banking investment, but in exchange for a VRP access right and closer FCA oversight. For the US contrast, where data access runs through CFPB rulemaking under Section 1033 rather than a commercial scheme model, see our Section 1033 open banking guide.
Financial crime, inclusion, and the PSD3 question
Not every question is about new technology. Questions 17 to 20 ask how the reforms can support an inclusive payments landscape, what key risks have emerged in the payments and e-money sector, whether enhanced accountability of senior managers would help manage financial crime risk, and which targeted amendments could tackle sector risks proportionately.
On the EU, Question 4 asks which international developments the UK should incorporate. Latham notes PSD3 is expected to take effect in late 2027 or early 2028 and that the consultation is non-committal on how closely the UK will follow it.
Contrast map: how this differs from recent FintechSpecs coverage
Recent coverage already has US rulemaking, agentic product launches, and vendor shortlists. Keep those URLs. This post is the UK regulatory deadline explainer.
| Story | What it is | Buyer question |
|---|---|---|
| HMT Modernising Payment Services Regulation (this post) | UK consultation on PSRs and EMRs reform; closes Oct. 6, 2026 | What should my firm argue for on permissions, agent liability, stablecoin treatment, and API charging before the UK rules are rewritten? |
| Fed GENIUS Act NPRs | US prudential and application rulemaking for payment stablecoin issuers | What reserve, capital, and application requirements apply in the US? |
| Section 1033 open banking guide | US personal financial data rights compliance | How do I comply with US data access rules? |
| Cleverbridge, Visa, Revolut France passkey | Live agentic payment transaction with passkey authentication | How is agent authentication working in production today? |
| Mastercard and Alchemy AgentCard | Network product for agent credentials and verifiable intent | Which network tools can my agent product use? |
| Best AI agent payment infrastructure providers | Vendor shortlist | Which vendor should I pick? |
Industry-led frameworks such as the six-bank Trusted Agentic Commerce Principles and Mastercard’s Agent Pay trust services set private standards for agent transactions. This consultation is the UK government asking whether the statutory layer underneath those standards needs to change.
Who should respond, and what to put in your response
Prioritise a response if you:
- Hold or plan to seek UK payment institution or e-money institution authorisation and want to offer tokenised payments
- Plan to issue a UK qualifying stablecoin, or rely on an overseas stablecoin for UK payment flows
- Build agentic checkout, agent wallets, or agent credential products for UK consumers or businesses
- Run a PISP or AISP whose model depends on free Open Banking API access, or an ASPSP that wants a return on API investment
- Own SCA, fraud, or financial crime policy at a UK payments firm
Diligence and drafting questions for your team and counsel
- Which current PSR or EMR requirement has cost us the most, and should it stay in legislation or move to FCA rules (Questions 1 and 2)?
- If SCA moves to outcomes-based FCA rules, which exemptions do we need preserved or created?
- Would a single activity list for tokenised and non-tokenised payments change our permission set, and how long would a variation of permission take us (Questions 10 and 11)?
- Which stablecoins do we touch in UK flows, and would they qualify as money-like under the UK or recognised-jurisdiction test (Question 6)?
- Where do we hold stablecoins temporarily during a payment, and does the Sept. 16, 2026 SI change our safeguarding analysis?
- What consent and authentication evidence does our agent product capture, and what liability split do we propose for unauthorised agent payments (Question 15)?
- What would per-call or volume-tiered API pricing do to our Open Banking unit economics (Questions 22, 23, and 34)?
- Do we rely on sweeping VRPs, and do we need the free-of-charge requirement maintained (Question 31)?
- Who signs off the response, and will we publish a version or keep it confidential?
The take: a short window to shape a long rulebook
HMT has asked 42 open questions, and Latham describes the document as reading less like a set of proposals and more like an open invitation to help write the answer. That makes the next three days unusually valuable for UK payments firms.
Operator take: The firms that respond with concrete examples (a blocked product, a liability case, API volumes and costs) will shape FCA rules that land in 2027 to 2028. The firms that skip it will be applying for variations of permission under rules they did not help write.
Treat this as the UK statutory reset for tokenised payments, stablecoin payments, agentic payments, and Open Banking access. For US stablecoin rules, keep the Fed GENIUS Act NPRs. For agentic vendor selection, keep best AI agent payment infrastructure providers and ACP vs AP2 vs x402.
FAQ
When does the HM Treasury payments consultation close?
At 11:59pm on Oct. 6, 2026, per the GOV.UK consultation page. It was published on July 14, 2026 and ran for 12 weeks.
How do I respond to Modernising Payment Services Regulation?
Email [email protected], or post your response to the Payments & Fintech team, HM Treasury, Horse Guards Road, SW1A 2HQ. You do not have to answer all 42 questions.
Will UK stablecoins be regulated as payments?
HMT proposes treating UK-issued qualifying stablecoins as “money-like” and bringing them into the payments perimeter. Overseas-issued stablecoins would only get that treatment if HMT recognises the issuing jurisdiction; otherwise they stay under the FSMA cryptoassets regime, per Latham & Watkins.
What does the consultation say about agentic payments?
It says the UK has an opportunity to lead in agentic payments and that the PSRs were designed before AI. Question 15 asks whether rules on authentication, consent, and liability for unauthorised transactions need updating for payments initiated by AI agents.
Will Open Banking APIs stop being free in the UK?
Not decided. HMT asks whether and when ASPSPs should be able to charge for access that is currently free, and proposes that access under a new VRP right would not need to be free, except for sweeping, which would stay free of charge.
Does this replace the EU’s PSD3?
No. PSD3 is the EU’s own reform. The UK consultation asks which international developments to incorporate but does not commit to following PSD3.
When will the new UK rules take effect?
No effective date is set. Per Latham, HMT plans to prepare the Statutory Instrument during 2027 to 2028, with the FCA consulting on detailed rules in parallel.















