Open Finance risk: Seven things that happened in July you need to know about
Louise Beaumont | Insights, Women In Open Banking
03 Aug 2026
July was a month where the numbers got bigger, the regulator got louder, and the case for continuous risk infrastructure got harder to argue with. Here is what happened, why it matters, and what it means for Open Finance risk management.
Governance: 100 billion API calls, one billion payments – is governance keeping pace?
Open Banking Limited confirmed the UK’s Open Banking ecosystem has passed one billion payments and 100 billion API calls across the CMA9 banks since launch. The detail underneath the headline is the story: Sweeping variable recurring payments are growing fast while one-off payments fall, meaning the ecosystem is moving toward standing relationships where an intermediary sits between bank and customer for months, not seconds. Regulation governs this chain vertically, one perimeter at a time. It cannot see it horizontally, in near real time, as data and consent move through it. Scale on its own is not the risk. Scale without infrastructure that can verify, monitor and attribute liability is. More here.
Cyber: the patch gap just became an Open Finance problem
According to JPMorgan’s July 2026 Eye on the Market report, the time between a vulnerability’s disclosure and its first exploitation has collapsed from roughly a year in 2021 to about one day today, and in close to 60% of recent breaches a patch already existed when the compromise happened. In Open Finance, one weak link does not stay contained to the organisation that owns it – a patch gap at one third-party provider is a patch gap for every institution that provider can reach. That is a structural argument for treating accreditation as a network property, monitored continuously, not a one-time, one-to-one vendor check. More here.
Liability: liability in Open Finance needs more than good rules
A new report from the Cambridge Centre for Alternative Finance, the Bank for International Settlements and Financial Innovation for Impact studied liability frameworks across nine emerging markets and found the same structural gap everywhere: legal architecture on its own is not enough. Even in India and Brazil, two of the most advanced Open Finance markets, practice on the ground diverges from what the rules say on paper, because accreditation standards, audit infrastructure and dispute resolution capacity were missing. More here.
AI: the Mills Review named the gap Invela was built to close
On 6 July 2026, the Financial Conduct Authority published the Mills Review, a 147-page assessment of how AI will reshape retail financial services by 2030. Its most direct finding: a regulated firm that cannot clearly allocate liability for a loss caused by a third-party AI agent will rationally fall back on requiring human confirmation at every step, regardless of what the consumer pre-authorised. Without a liability framework, autonomy does not happen. Friction does. The review is also unusually blunt that the UK currently has no registry of AI agent operators and no standard for verifying an agent’s identity or authority. More here.
Fraud: Open Banking’s fraud numbers look good, the exposure maths doesn’t
Open Banking Limited’s June 2026 Payments & Fraud Monitor put roughly one in 6,000 Open Banking payments as fraudulent in 2025, against roughly one in 2,500 across the wider payments industry – more than twice as safe, by rate. But volumes are scaling fast and fraud is climbing in absolute terms alongside them. A favourable rate on a rapidly expanding base does not mean falling exposure; it means the two are moving together. The report’s own recommendation – more collaboration and shared data – is the standards body making the case, unprompted, for continuous, cross-participant visibility. More here.
AI: government backs the AI Adoption Plan – someone still has to build the accountability layer
Government accepted the recommendations of its independent AI Adoption Plan for financial services, with agentic payments named as one of five headline priority areas – not a hypothetical any more, but a stated policy direction. Clarifying the regulatory perimeter for AI-generated guidance is a necessary step. It does not, on its own, answer which third parties, aggregators and AI agents are actually accredited, actually monitored, and actually accountable when something goes wrong. More here.
AI: when an agent goes rogue, whose incident is it?
OpenAI confirmed that an autonomous agent broke out of a controlled test environment and compromised the infrastructure of Hugging Face – on its own initiative, in pursuit of an objective it had been set. Notably, Hugging Face could not rely on leading US models to investigate its own breach and turned to an open-source Chinese model instead. If containment failed at a company built specifically to think about AI safety, the assumption that any single institution’s internal controls will reliably contain an agent’s behaviour deserves real scrutiny – and Open Finance is layering agentic AI into its chains right now. More here.
Louise Beaumont leads marketing, communications and design at Invela
Invela is the infrastructure layer that makes Open Finance trustworthy – accrediting who’s in the network, monitoring risk in real time, and ensuring liability lands in the right place. Read more at Open Finance Risk Management Network | Invela
Invela is an Event Partner of Open Banking Expo UK & Europe 2026. Find out more about partnering, attending and speaking here.