All essays
A complete chronological record of everything published on Transaction Intelligence.
-
№ 1 · 15 Sep
2 min readRegulatory
Give your AI the source
Connect ChatGPT or Claude directly to paymentslaw.eu and check the sources behind an SCA answer. A free, read-only connection to 51 curated EU payments instruments, with provisions, source editions and citations you can open.
-
№ 2 · 08 Sep
9 min readRegulatory
SCA gets a promotion
Strong Customer Authentication is being moved into a directly applicable regulation, not just amended. Your transition plan needs to separate what the text specifies, what waits on the EBA, and what it assumes about the handover. The law leaves that last part implicit.
-
№ 3 · 01 Sep
3 min read
Where the payments package actually is
A May forecast for summer publication has come and gone. The official record now points to December, and carries a status line that reads backwards until you know the procedure.
-
№ 4 · 25 Aug
5 min readRegulatory
Three numbers that no longer exist
The PSD3 and PSR timetable has moved, but many summaries have not. The April 2026 compromise texts change the planning assumptions and contain two easily missed provisions that apply from entry into force.
-
№ 5 · 16 May
3 min readAI & Automation
When “something you are” becomes “something they can make”
One in five biometric fraud attempts now involves a deepfake. The figure is striking on its own, but the more interesting story sits underneath it: inherence has quietly become the awkward leg of the SCA stool, and the trilogue text of the PSR is the first regulatory instrument to acknowledge it.
-
№ 6 · 04 May
5 min readRegulatory
Meet Alexandre Lamfalussy
PSD3 and the PSR have cleared trilogue. Coreper has the final texts. None of that tells you when the rules will apply to your business. A primer on the four-level framework that determines when EU payments regulation lands.
-
№ 7 · 16 Sep
4 min read
The Trust Triangle Evolution: From 3-D Secure's Three Domains to AP2's Agent Architecture
Twenty-five years ago, the payments industry solved the trust problem of e-commerce with a three-domain architecture that became the backbone of online authentication. Now, as AI agents prepare to shop on our behalf, we're witnessing history rhyme. But this time, humans might not be in the loop.
-
№ 8 · 22 Aug
4 min readAI & Automation
Second-Order Thinking: What the UK's Age-Check Law Taught Us About Regulation (and Why It Matters for AI)
Politicians love declaring victory. A new law passes, the metrics move in the right direction, and success is proclaimed. But in complex systems, the first metric to move is rarely the one that matters most.
-
№ 9 · 19 Aug
3 min read
Why Generalists Win in Complex Ecosystems
Enterprises often assume breakthroughs come from the deepest experts. Yet in environments where priorities collide and silos slow progress, it’s generalists who create clarity; connecting disciplines, aligning incentives, and unlocking outcomes specialists alone can’t reach.
-
№ 10 · 23 Jul
5 min readAI & Automation
The Wake-up Call: AI Has Defeated Bank Voice ID. Now What?
Financial institutions relying on voice biometrics face a serious problem. AI can now clone voices from seconds of audio, turning everyday digital footprints into authentication vulnerabilities. Under PSR's evolving framework, voice alone no longer meets regulatory or security standards.
-
№ 11 · 18 Jul
4 min readRegulatory
The £42 Million Lesson: What Barclays' FCA Fine Teaches the Digital Payments Industry
Barclays' £42m FCA fine for "one simple check" failure offers crucial lessons for digital payments. Analysis of how basic compliance gaps facilitated £46.8m in money laundering and what fintech, eCommerce and payment firms must do to avoid similar costly mistakes in an evolving regulatory landscape.
-
№ 12 · 09 Jul
5 min readRegulatory
When Systems Meet Reality: The Vocalink Fine and Lessons for Infrastructure Governance
When critical reports warning of "serious un-remediated issues" sit buried in email chains while boards sign compliance confirmations, something has gone catastrophically wrong. The Vocalink case reveals how even well-intentioned governance systems can fail when information flows break down.