UAE, 14 September 2026 — Open Finance in the Emirates has moved past being a regulatory headline. The current version of the Central Bank of the UAE (CBUAE) Open Finance Regulation, Circular 3 of 2025, has been in force since 10 July 2025, and in 48 hours — on 16 September 2026 — the one-year transitional period of the sweeping new federal Central Bank Law (Federal Decree-Law No. 6 of 2025) expires. That law brings open-finance service providers directly into CBUAE's licensing perimeter, and the rules of the game shift meaningfully for banks, payment operators, insurers and their customers — from the retail app user to the SMB setting up shop in the Emirates.
What CBUAE Open Finance is, and what is already in force
The Open Finance Regulation was originally issued as Circular 7 of 2023 and superseded by Circular 3 of 2025, effective 10 July 2025. It sets the licensing, supervisory and operational framework for the cross-sectoral sharing of customer financial data and for the initiation of transactions on the customer's behalf — through secure, standardised interfaces and only with the customer's express informed consent.
The CBUAE Open Finance Standards have been published in two versions: an initial release in August 2024 and the updated v1.2-final on 20 December 2024. The Standards cover API infrastructure, participant identity, security (OAuth2 / OpenID Connect / FAPI) and the data model.
Who must participate
Participation in the framework is mandatory for every CBUAE licensee. The perimeter includes:
- UAE-incorporated banks, foreign bank branches, specialised and Islamic banks;
- finance companies;
- payment service providers (PSPs);
- insurance companies and brokers;
- exchange houses;
- loan-based crowdfunding companies.
A subset of licensees — banks, finance companies, insurers and PSPs — are treated as deemed licensed under the Open Finance Regulation: they do not require a separate Open Finance licence but must obtain a No-Objection Certificate (NoC) from CBUAE before commencing open-finance activities. Third-Party Providers (TPPs) that are not already CBUAE-licensed financial institutions — fintech aggregators, PISP startups, analytics and B2B services — must apply for a dedicated Open Finance licence from the Central Bank.
Architecture: a centralised API Hub, not a European-style federation
The most important difference between the UAE model and its UK/EU counterparts is the centralised infrastructure. The hub is operated through CBUAE affiliates and partners:
- Al Tareq / Nebras — operator of the centralised API Hub, the Trust Framework and authentication functions; maintains the registry of participants, users and certificates;
- Al Etihad Payments (AEP) — the underlying UAE payments infrastructure enabling transaction initiation;
- Consent Manager — the centralised customer-consent service;
- Heimdall — the TPP connectivity component.
The centralised Hub removes the need for banks — and especially TPPs — to maintain N × M direct connections. Everyone routes through a single, standardised entry point. That accelerates time-to-market for TPP products and simplifies regulatory oversight, while giving CBUAE and Al Tareq / Nebras an outsized role in shaping the market.
What it changes for customers and SMBs
The practical impact of Open Finance breaks down into three pillars:
- Data — by consent only. The customer grants a specific licensed TPP explicit informed consent to access a defined set of data: balances and account movements, payment-instrument details, transaction history, consumer credit, insurance policies. Consent is scoped, purpose-bound and time-limited, and can be revoked at any time via the Consent Manager.
- Transaction initiation. With consent, a TPP can initiate a transfer from the customer's bank account without the user having to switch to the bank's own app. This is delivered through AEP.
- Cross-sectoral scope. Unlike a narrow open-banking model, the UAE framework also covers insurers and non-bank finance companies — the objective is a unified financial view of the customer, not just a banking dashboard.
For retail customers this means consolidated finance dashboards, credit scoring based on actual cash flow rather than the credit bureau alone, easier switching and richer personal-finance tools. For SMBs it means fast integration of accounting and treasury software with banks, automated reconciliation, instant B2B payments and materially easier access to working-capital credit through TPP aggregators that can see real bank-account flows. If your company is only just opening a corporate bank account in the UAE, prioritise a bank that is already live in the Open Finance framework — it becomes the base layer for later ERP, payment-gateway and compliance automation.
What is already live
The first commercial use-cases are already visible. According to the AlTareq community, Abu Dhabi Islamic Bank (ADIB) has been a live participant since 16 April 2026. Commercial Bank of Dubai (CBD) was the first UAE bank approved by CBUAE as a Third-Party Provider — since August 2026 CBD customers can see the balances of, and initiate payments from, their accounts held with other UAE banks directly from the CBD mobile app. Further Open Finance phases — expanded data domains and cross-sectoral use-cases — are being flagged by banks for the second half of 2026. The UAE's domestic payments infrastructure is evolving alongside, including the Jaywan national card and the Aani instant-payments system operated by Al Etihad Payments.
The Central Bank Law 6/2025 anchor and the 16 September deadline
Open Finance is now formally anchored in the new Central Bank Law — Federal Decree-Law No. 6 of 2025 — which took effect on 16 September 2025 with a one-year transitional period. The compliance deadline is 16 September 2026. For the first time, the law expressly places open-finance service providers and 'enabling technology providers' — companies whose protocols, API platforms or dApps enable licensed financial activity — inside the CBUAE licensing perimeter (Article 62). Maximum fines: AED 1 billion for institutions, AED 20 million for breaches of financial market infrastructure obligations, AED 5 million for individual liability. By the deadline, banks, insurers, PSPs and TPPs must hold the appropriate licence, an NoC, or have re-shaped their business model.
What businesses and customers should do
For a fintech planning to enter the UAE, the starting point is not the product but the licensing route: a stand-alone Open Finance licence or (where scope allows) operating under an existing CBUAE licence held by a parent entity. Banks and PSPs should complete a CBL 6/2025 self-assessment ahead of 16 September 2026 and file an NoC for their open-finance activities. SMBs and corporate clients should ask their bank whether it is connected to the centralised API Hub and which data domains are already available for accounting and treasury integration. Retail customers should watch for an 'Other banks' section inside their UAE banking apps (CBD already has one) — and read the consent text carefully before confirming: only informed consent gives a TPP access to your data.


