Rail Governance

Dodd-Frank Section 1033 Data Access Rules and AI Transaction Agents

Banks face conflicting federal and state rules on sharing customer financial data.

Editorial team · · 10 min read
Cover illustration for “Dodd-Frank Section 1033 Data Access Rules and AI Transaction Agents”
OCC and Fed Rulemaking · October 5, 2026 · 10 min read · 2,212 words

Section 1033 of Dodd-Frank gives consumers a statutory right to their own financial data, held by the banks and credit unions that service them, subject to rules the CFPB is supposed to write and enforce. The CFPB's October 2024 final rule was supposed to turn that right into something operational: a working set of obligations banks had to build toward, on a clock. Eighteen months later, that clock has stopped, though the rule itself hasn't gone away. Understanding why requires separating two things that sound similar but aren't: what the rule demands, and whether anyone can currently make a bank do it.

Start with the demands. The 2024 rule required covered institutions to expose customer-permissioned APIs covering account information, transaction history, payment initiation, and recurring payments. Data had to come back in machine-readable format, protected by strong customer authentication and a real consent management flow, not a PDF or a login-sharing workaround. Institutions had to publish uptime and performance metrics and give consumers access at no charge. The rule barred banks from using collected account data for targeted advertising, marketing, or sale to data brokers, and it capped how long an authorized third party could retain data: one year past the consumer's most recent authorization.

"Covered data" under the rule means transaction information, account balance, payment-initiation data (including the account and routing numbers needed for ACH transfers), terms and conditions, upcoming bill information, and basic account verification. And the scope of "covered products" is narrower than Dodd-Frank's statutory language technically allows: the rule applies to consumer credit cards and Regulation E accounts, not the full sweep of financial products. Small depository institutions with $850 million or less in assets are exempt.

The legal status, where most of the confusion lives, traces back to the rule's finalization on October 22, 2024 and its effective date of January 17, 2025. By May 2025, the CFPB itself told the court the rule was unlawful, a remarkable reversal from the agency that wrote it. The court stayed the litigation in July 2025 while the CFPB worked on reconsidering the rule, and around October 2025 it issued a preliminary injunction barring enforcement.

That leaves the rule in a specific, precise state: enjoined, not vacated. It still sits in the Code of Federal Regulations. No court has struck it down or declared it void. It simply cannot be enforced right now. That distinction carries weight for anyone planning around it, because an enjoined rule can come back to life once litigation resolves, while a vacated one would need to be rebuilt from scratch. The five-tier compliance schedule built into the rule, every deadline falling on April 1, remains on the books in that same suspended state. Tier 1, covering the largest depositories and nondepositories, hit its April 1, 2026 deadline without triggering any enforcement obligation. All five dates still exist on paper. None of them currently bind anyone.

What the Rewrite Changes and Leaves Intact

The CFPB is narrowing in on two contested provisions while leaving the rest of the 2024 architecture largely where it stood, a detail that should shape how institutions plan. The rewrite process has moved in concrete, dated steps. On August 22, 2025, the CFPB published an Advance Notice of Proposed Rulemaking that reopened four areas: the scope of who counts as an authorized representative, data security, data privacy, and the defrayment of costs, meaning fees. On August 6, 2026, the CFPB submitted its Section 1033 reconsideration NPRM to the federal regulatory review office that vets agency rules, the first formal procedural step toward an actual rewritten rule. If OIRA clears that NPRM within its typical review window, a proposed rule and public comment period could follow by late 2026 or early 2027, with a final rule possible by mid-to-late 2027, assuming no fresh litigation arrives to slow things down again.

The first contested area is fees, and it's genuinely open. The 2024 rule banned covered data providers from charging for API access. The reconsideration puts that ban back on the table. Commercial practice is already running ahead of the regulatory text here: JPMorgan and Plaid struck a paid data-access deal in September 2025, well before any rule change made that arrangement a formal requirement. Access pricing is now a planning variable that needs to be designed around as it evolves.

The second contested area is who gets to act as a data recipient. The current rule lets any consumer-authorized third party request data with no accreditation requirement and no clear bar for what makes a third party unsafe to deal with. The rewrite is expected to tighten this into a more defined "authorized representative" standard, potentially carrying fiduciary-level obligations for aggregators handling consumer financial data. That tightening would reach directly into AI agent design: whether an agent can qualify as an authorized representative, what consent structure has to support that status, and what ongoing obligations attach to it once granted, are all live questions the rewrite will answer.

What's not up for renegotiation deserves equal attention. The API-based access obligation itself, the machine-readable format requirement, consent management, the ban on using shared data for targeted advertising, and the one-year retention cap are the stable core the ANPRM left alone, not the provisions driving reconsideration. Market infrastructure is converging around that core independent of the rule's legal status: the Financial Data Exchange, FDX, was recognized as the standard-setting body in January 2025 for a five-year term running through January 8, 2030. The bulk of the 2024 rule's obligations remain the most credible baseline to build against, even while enforcement sits frozen.

States Moving Into the Federal Void

A federal injunction halts federal enforcement. It doesn't halt regulation generally, and it hasn't here. What's happened instead is a shift in where the regulatory pressure originates, from the federal level to state legislatures, and New York offers the clearest working example of what that shift looks like in practice.

New York Assembly Bill 10640, introduced March 13, 2026, and its companion Senate Bill 9483, introduced March 17, 2026, were both still sitting in committee as of June 2026. The bill text lays out a framework that shows what a state-level alternative to Section 1033 would actually require. The bills also require adherence to GLBA and FTC safeguard standards, folding existing federal privacy law into the new access framework.

Where the New York bills diverge from the federal rule is where the real complexity starts. First, they cover all consumer financial products and services, not the narrower set of credit cards and Regulation E accounts the federal rule limits itself to. And on fees specifically, the two frameworks are now pointed in opposite directions: the New York bills would prohibit financial institutions from charging for data access, full stop, while the federal rewrite is actively moving toward permitting some form of fee structure. An institution operating in New York, if both frameworks end up in force, would need to reconcile a state ban on fees with a federal rule that allows them.

That contradiction is the structural problem for any bank or credit union building data infrastructure right now. If its bills pass, they could function as a template other states adapt for their own legislation, which would mean the compliance perimeter for data access starts fragmenting by jurisdiction well before any federal uniformity returns.

For an AI agent built to access transaction data, this layering is a design requirement, not an abstract legal curiosity. The agent has to be able to show, for any single interaction, which consent framework applied, what data it touched, for what purpose, and under what retention rule, and that record has to hold up under whichever regime governs that particular transaction in that particular state. An agent that can answer those questions for a Regulation E account in one state might not be able to answer them the same way for a small-business account in New York, which is the baseline condition multi-state deployment already requires.

Section 1033's Data Architecture and AI Transaction Agents

Section 1033's API framework is the data plumbing that agentic AI systems need in order to do anything useful with a bank account: monitor it, move money through it, or execute a multi-step financial task without a human clicking through each stage.

Break down what an agent actually needs to operate, and the dependency becomes concrete. It needs continuous access to transaction history and account balances to track patterns and catch anomalies as they happen. It needs payment-initiation data, including account and routing numbers, to execute or trigger a transfer on the account holder's behalf. It needs consent and authorization data that clearly establishes the agent is acting within the bounds of what the account holder actually permitted. And it needs that data delivered in structured, machine-readable form, not screen-scraped from a web interface built for humans, because reliable decision logic depends on reliable inputs.

Production deployments are already running against this kind of infrastructure, so this isn't theoretical. Fiserv launched agentOS on May 14, 2026, an agentic AI operating system built with OpenAI and AWS and running on Amazon Bedrock AgentCore. Jack Henry expanded its Google Cloud collaboration in June 2026 to build a proprietary AI security platform, deploying agent use cases for customer service support, insights and reporting, and back-office automation on the Gemini Enterprise Agent Platform, aimed at its community bank and credit union client base. These are live systems operating on real account data, not pilots confined to a lab.

That raises an important question: what happens when the system making decisions off this data isn't deterministic? Agentic AI is probabilistic by design, meaning identical inputs can produce different outputs depending on the run. Feeding the same transaction history and the same instructions to an agent twice may not produce the same action both times. Applied to a system with the authority to move money, that non-determinism is not a minor quirk. It means the same data access, granted under the same consent, can produce different payment or routing decisions at different moments, for reasons that aren't always traceable after the fact.

Existing payment regulation wasn't built with this in mind. It was built around human actors making deliberate choices, and it doesn't cleanly separate "unauthorized use" from "user negligence" when the actor in question is an algorithm that hallucinated a wrong account number or misread an instruction. One might argue that the technology has simply outpaced the law here, and that's fair as far as it goes. But it leaves a real governance question sitting unanswered at every institution deploying these systems: what is this bank actually willing to delegate to a machine, at what dollar thresholds, and under what conditions. That's a decision that needs to get made before an agent moves a dollar, not after an incident forces the question.

The accountability gaps that 1033 limbo leaves unresolved for agent deployments

None of this uncertainty is neutral. Every month the rule sits enjoined rather than resolved is a month institutions deploy agentic systems against a data-access framework with real, named holes in who bears responsibility when something goes wrong.

Start with the liability gap around data breaches. If a bank shares a customer's data with a third party because the customer authorized it, and that third party is later breached, the bank can still end up on the hook even though it did what the rule and the consumer asked of it. The bank complied. The consumer consented. The breach happened somewhere downstream, outside the bank's direct control, and the question of who absorbs the consequences remains unanswered by anything on the books.

Layer the accreditation gap on top of that. Under the 2024 rule as written, any fintech can request a consumer's data as long as the consumer authorizes it. There's no accreditation requirement screening who gets to make that request, and no clear standard defining what makes a given third party "unsafe" to hand data to. The rewrite's tightened authorized representative standard is aimed squarely at this gap, but until that standard actually exists in a final rule, the gap stays open. Any AI agent acting as, or interacting with, a data recipient today operates in that same undefined space, granted access through consumer consent, with no regulatory floor confirming the recipient meets any particular bar of safety or conduct.

The data architecture agents depend on is largely stable, built on the FDX standard and the core access obligations of the 2024 rule. But the rules governing who can be trusted with that data, what happens when trust is misplaced, and what a bank owes a customer when an agent acts unpredictably are all still being negotiated, in parallel, across a federal rulemaking process and a growing number of state legislatures. Institutions deploying agentic systems now are building governance architecture to operate inside the uncertainty rather than waiting for that negotiation to finish: consent logs precise enough to survive scrutiny under more than one possible rule, transaction thresholds calibrated to the agent's actual reliability rather than its theoretical capability, and internal accountability structures that don't assume a regulator will eventually draw the lines for them. The rule's limbo doesn't pause the deployment of these systems. It defines the terms under which that deployment has to prove itself responsible.

Sources

  1. Dodd-Frank 1033: What a U.S. Open Banking Rule Means for Banks
  2. Open Banking Update: CFPB’s Final 1033 Rule, What’s New, What’s Different, and What’s Next?
  3. Federal Register :: Required Rulemaking on Personal Financial Data Rights
  4. Court halts 1033 rule compliance deadline - ICBA.org
  5. Cozen O’Connor: Section 1033 Compliance Date: Open Banking Rule Enjoined and Under Reconsideration [Alert]
  6. Required Rulemaking on Personal Financial Data Rights
  7. CFPB working on new 1033 rule - ICBA.org
  8. Federal Register :: Personal Financial Data Rights Reconsideration

More in OCC and Fed Rulemaking