Regulatory Readiness in Late 2026: Turning Four EU Rulebooks Into One Adoption Decision
- 2 hours ago
- 6 min read

On 2 August 2026, the final tranche of the EU AI Act obligations came into force, folding credit scoring, insurance underwriting and a widening list of high-risk banking use cases into a single European rulebook. Ten days earlier, the Council of the European Union cleared the final compromise texts of PSD3 and the Payment Services Regulation, with formal parliamentary adoption expected in September. Meanwhile the Financial Data Access Regulation, the open finance instrument known as FIDA, is deep in trilogue and widely expected to be politically agreed before the end of the year. In parallel, national competent authorities across the euro area have quietly moved DORA supervision out of its tolerance phase, with the first supervisory letters landing in Amsterdam, Frankfurt and Paris.
For senior innovation leads inside European financial institutions, the last fortnight has felt less like a compliance calendar and more like a weather system. Four regulatory clocks are ticking in the same room, none of them synchronised, all of them changing the shape of adoption decisions that were already committed to 2027 roadmaps.
The problem
The instinct is to treat each regulation as its own workstream. In practice, this is where regulatory readiness quietly breaks down inside a large bank, insurer or asset manager.
The rulebooks now overlap at the same operating layer. The DORA ICT third-party risk chapter, the AI Act high-risk provider obligations, the PSR fraud liability shift, and the emerging FIDA data-sharing schemes all touch the same vendor contracts, the same data pipelines and, increasingly, the same procurement approvals. A build, buy or partner decision that used to sit inside a single legal or technology stream now surfaces in four separate governance forums, sometimes with contradictory positions.
Delivery pressure has also changed. In 2024 an innovation team could plausibly finish a payments pilot before the ISO 20022 CBPR+ deadline and only afterwards worry about DORA register of information duties. That sequencing has collapsed. Any material adoption decision made in the second half of 2026 has to consider all four regimes simultaneously, plus the ECB supervisory priorities and the Basel 3.1 output floor pressures already committed to internal capital plans.
Vendor noise has intensified accordingly. Every fintech deck now claims DORA compatibility, AI Act alignment and PSR readiness, and some of them are even accurate. Innovation teams are being asked to separate genuine regulatory posture from marketing veneer, at exactly the moment when the regulators themselves are only starting to publish practical guidance.
Common approaches, and their trade-offs
Three responses have emerged across European financial institutions this year. Each is defensible; none is complete.
The first approach is the compliance-led lockdown. The chief compliance officer's mandate expands to cover almost every technology decision above a low materiality threshold, and adoption visibly slows. This tends to produce clean regulatory posture but a starved innovation portfolio. Vendors report deals paused, pilots frozen and evaluation timelines stretched from weeks into quarters. It is a rational stance for institutions still working through DORA gap remediation, but it exports the delivery risk to the following year.
The second approach is the parallel-track workaround. Innovation and transformation teams keep experimenting outside the perimeter, using sandboxed environments, synthetic data and pre-production tenants. This preserves optionality and keeps peer-level learning alive, but it produces a widening gap between what the front office knows about the market and what the second line has approved. When the two worlds finally meet at architecture review, the surprises are rarely pleasant, and often expensive.
The third approach is the regulatory-first roadmap. Adoption decisions are re-sequenced explicitly around DORA milestones, AI Act annex III thresholds, PSR fraud liability transition dates and FIDA scheme readiness. This is analytically the strongest response, and it is what the more mature innovation offices in Germany, the Netherlands and the Nordics are quietly doing. The trade-off is that it demands a shared factual base across compliance, technology and business, which in most institutions still does not exist in one place.
Each approach has a hidden cost. The lockdown surrenders competitiveness. The workaround surrenders governance. The regulatory-first roadmap surrenders speed, unless the institution has already invested in the intelligence infrastructure to make the sequencing decisions quickly.
A smarter route
The underlying buyer questions have not changed under regulatory pressure. They have hardened. Innovation leads still need to know how peers in comparable jurisdictions are actually adopting; how to evaluate credible innovators without drowning in vendor pitches; how to make defensible build, buy or partner calls; and how to stay current on market movement without leaving the desk. The regulatory overlay simply raises the cost of getting each of these wrong.
This is where a curated, peer-level operating rhythm quietly outperforms the traditional conference circuit. A Discovery Innovation Meeting scoped to a specific regulatory pressure point, for example DORA third-party concentration or the AI Act annex III credit scoring provisions, gives an innovation office two or three genuinely regulator-aware vendors in a single afternoon, filtered for the institution's own ICT risk taxonomy rather than the vendor's marketing preferences. A Peer Forum with counterparts inside institutions of similar size and regulatory footprint compresses months of horizon scanning into a two-hour candid session, where the question is not what a regulator said, but what a peer in Milan or Copenhagen decided in response. A Roundtable, quietly convened, is often the fastest route to understanding how another bank interpreted the same ECB guidance, and where it chose to pause. Finance X Magazine, in the same portfolio, keeps the wider institutional memory current in the background while the immediate compliance clock is ticking.
None of this replaces the internal compliance workstream. It runs alongside it. What it does replace, effectively, is the assumption that a senior innovation lead can build their own regulatory intelligence layer from scratch, in the middle of a delivery quarter, while vendors are queueing at the door.
Why this matters right now
The next twelve weeks are unusual. They will contain the final adoption vote on PSD3 and the PSR, in all likelihood a political agreement on FIDA, the first serious wave of DORA enforcement letters into the largest EU banks, and the first supervisory dialogues on AI Act annex III systems. In parallel, ECB single supervisory mechanism inspection teams are already using the DORA register of information as an entry point into vendor concentration reviews, which many innovation teams did not anticipate.
Any bank, insurer or payment institution making a material technology commitment between September and December 2026 is effectively signing a contract that will need to survive four regulatory regimes at once. Institutions that have built a peer-level intelligence habit are moving with more confidence, not because they have more resources, but because they have more context. Institutions that are still working from vendor decks and consultancy summaries are quietly slowing down.
Two structural pressures are compounding this. First, the EBA and ESMA are increasingly cross-referencing findings across regimes, meaning a weak DORA third-party register can quickly become an AI Act supplier documentation problem, which in turn can become a PSR resilience concern. Second, national regulators, including the FCA in the United Kingdom, the DNB in the Netherlands and BaFin in Germany, are publishing sectoral thematic reviews that reveal peer expectations far faster than any consultancy could. Reading those reviews the week they land, and cross-checking them with peers running the same programme, is now table stakes.
Closing thought
Regulatory readiness in late 2026 is not a compliance question. It is an adoption architecture question. The institutions that will emerge from the next two quarters in better strategic shape are the ones that treat regulation as an input into their build, buy or partner logic, not as a separate stream that arrives afterwards to slow it down. That requires a working intelligence habit, not a bigger legal team. It requires the ability to see, quickly and credibly, what a peer institution decided when confronted with the same DORA article, the same AI Act annex, the same PSR liability clause.
For most European innovation offices, the next agenda item is not another vendor demo. It is a decision about how to build that habit before the September calendar reopens, and how to make sure the intelligence layer they will need for the next twenty-four months is in place before delivery pressure closes the window.



