23 Jul 2026

The API Economy: Governance, Consent, and Liability in India’s Open Banking Frontier

The API Economy: Governance, Consent, and Liability in India’s Open Banking Frontier

The API Economy: Governance, Consent, and Liability in India’s Open Banking Frontier

~Sura Anjana Srimayi

INTRODUCTION

As of mid-2026, India’s financial landscape is defined by a radical shift from "walled gardens" to an interconnected, consent-driven API economy. At the heart of this transformation is the Account Aggregator (AA) framework, a world-leading digital public infrastructure that allows consumers to securely share financial data between institutions. With 17 operational Account Aggregators and over 1,100 regulated entities now participating in the ecosystem, the "Open Banking" revolution has fundamentally altered the economic power balance, shifting control of financial information from legacy institutions to the consumer. However, this transition toward hyper-connectivity brings complex legal challenges regarding data liability, breach accountability, and the integrity of consent. 

I. The Economic Shift: From Ownership to Access

The Account Aggregator framework has effectively commoditized financial data, forcing traditional banks to evolve from passive custodians of "trapped" data into active platform participants. By facilitating seamless data portability, the ecosystem has lowered entry barriers for fintechs, enabling hyper-competition in lending, wealth management, and insurance. 

For consumers, this means access to customized products without the burden of manual documentation. For banks, it signifies a transition where the value proposition is no longer the "ownership" of a customer's statement, but the "service" provided through API integrations. However, this shift increases the interdependencies between entities; a failure at a single API node can now cascade across the entire financial network, making operational resilience an economic imperative. 

II. The Legal Challenge: Liability and the Consent Architecture

The legal governance of this ecosystem is anchored by the Reserve Bank of India (RBI) and reinforced by the June 2026 recognition of Sahamati as the Self-Regulatory Organisation (SRO) for the AA ecosystem. Despite this robust framework, legal professionals are navigating three critical areas of concern: 

 

1. Consent as a Legal Artefact 

Under the AA framework, consent is not a blanket "I agree" checkbox. It is a structured, machine-readable, and revocable "Consent Artefact" that binds the Financial Information User (FIU) to specific parameters: purpose, duration, and frequency. Legally, the AA acts as a "neutral pipe", it cannot view, store, or sell data. The challenge for legal teams is ensuring that FIUs strictly adhere to the "purpose limitation." If an FIU uses data for a purpose outside the scope of the consent artefact, they face severe regulatory action and potential litigation for breach of contract and privacy violations. 

 

2. The Liability Gap in API Breaches

A primary concern for the industry is the distribution of liability in the event of an API data breach. The RBI’s April 2026 regulatory package introduced a tiered Digital Fraud Compensation Framework, which shifts liability timelines in favor of the customer. 

  • Systemic Failure: If a data breach occurs due to a vulnerability within the bank (FIP) or the third-party (FIU), the institution responsible must provide full compensation to the customer.

 

  • The Indemnity Struggle: Fintechs and banks are currently renegotiating contracts to include granular indemnity clauses. The legal task is to define exactly where the "chain of custody" for data ends and the liability of the receiving party begins, especially when multiple technology service providers (TSPs) are involved in the API integration.

 

3. Regulatory Enforcement and "Compliance-by-Design"

The RBI has moved from "legislative creation" to "legislative enforcement." With the Digital Banking Channels Authorisation Directions (2026), the expectation is that compliance is not merely documented but functionally demonstrated. For any entity accessing data through APIs, this means: 

  • Two-Factor Authentication (AFA): Mandatory for all digital payment and data-access touchpoints. 

 

  • Audit Rights: FIUs are legally obligated to provide banks (FIPs) with audit rights to ensure that the data accessed via API is stored securely and deleted upon the expiry of consent.

III. Protecting the Ecosystem: The Role of the SRO

The recognition of Sahamati as the SRO-AA in June 2026 marks a new phase of ecosystem discipline. By developing unified operational and technical standards, the SRO serves as a bridge between the regulator and the market. From a legal perspective, this provides a mechanism for dispute resolution that is faster than the traditional court system, ensuring that the "API economy" remains stable even as it scales toward billions of data shares. 

CONCLUSION

The API economy in India is a testament to the power of consent-led digital infrastructure. By legally formalizing the consumer's right to their data, the AA framework has successfully democratized financial services. However, the legal and operational burden on participating entities has never been higher. As we look ahead, the resilience of India's Open Banking model will depend on the clarity of liability frameworks and the rigorous implementation of security standards. The transition from "ownership" to "access" is complete; the current mandate for fintechs and banks is to ensure that this access is governed by transparency, protected by robust security, and held accountable by the rule of law.

Disclaimer

Every effort has been made to ensure accuracy in this material. However, inadvertent errors or omissions may occur. Any discrepancies brought to the author’s notice will be rectified in subsequent editions. The author shall not be liable for any direct, indirect, incidental, or consequential damages arising from the use of this material. This article is based on various sources including statutory enactments, judicial decisions, academic research papers, professional journals, and publicly available legal materials.

~Sura Anjana Srimayi