The fatal conceit of the Payment Services Regulation (PSR) is the assumption that shifting liability and mandating data access will inevitably foster competition; in reality, these measures often create a "compliance moat" that only the largest incumbents can afford to cross. While the proposed framework aims to democratize the merchant counter, it risks triggering a massive wave of **de-risking**, where acquirers avoid small or high-risk merchants altogether to escape the draconian liability shifts associated with "Confirmation of Payee" (CoP) and fraud refund mandates.
## The Fraud Liability Trap and Merchant Exclusion
The PSR’s focus on "spoofing" and IBAN-name matching (CoP) introduces a systemic risk for merchant acquirers. By forcing providers to bear the financial burden of social engineering fraud, the regulation incentivizes **unwarranted de-risking**. As the [European Banking Authority (EBA) noted in its report on de-risking](https://www.eba.europa.eu/eba-takes-steps-address-unwarranted-de-risking-and-ensure-access-financial-services), aggressive regulatory requirements often lead financial institutions to terminate relationships with entire categories of customers rather than manage the complex risks involved.
- **The Real-World Failure:** In markets like the UK, where "Confirmation of Payee" was pioneered, the results have been mixed. Smaller institutions struggle with the technical overhead of real-time name matching across borders, leading to higher transaction failure rates and merchant frustration.
- **The Result:** Instead of a competitive landscape, we see a "regulator-induced oligopoly" where only Tier-1 acquirers with massive R&D budgets can maintain the necessary "Identity-Verifier" infrastructure.
## The Myth of Open Banking Disintermediation
The belief that Account-to-Account (A2A) payments will replace card schemes ignores the fundamental value proposition of the Visa/Mastercard duopoly: **consumer protection**. Card schemes provide a standardized dispute resolution mechanism (chargebacks) that PSD3/PSR does not adequately replicate for Open Banking. As argued by payments expert **Dave Birch** in his analysis of [the future of digital money](https://www.dgwbirch.com/), without a robust "ruleset" for consumer redress, merchants will find that A2A payments suffer from lower consumer trust.
> "The problem with A2A is not the technology; it is the lack of a commercial framework that handles the 1% of transactions where something goes wrong."
## The "SoftPOS" Security Fallacy
While PSD3 pushes for "technological neutrality," it underestimates the **hardware-rooted security** requirements of global standards like PCI-DSS. SoftPOS—turning a consumer smartphone into a terminal—introduces a massive attack surface. Unlike dedicated hardware with a [Hardware Security Module (HSM)](https://www.nist.gov/publications/security-requirements-cryptographic-modules), a smartphone is a "hostile environment" where the payment application must compete with malware.
This creates a hidden "Big Tech" lock-in: SoftPOS providers remain entirely dependent on Apple and Google’s willingness to grant access to the NFC controller. Far from fostering neutrality, this reinforces the gatekeeper status of mobile OS providers, who can use "security concerns" as a pretext to throttle third-party acquirers.
## Data Portability vs. Operational Gravity
Finally, the assumption that data portability ends merchant lock-in ignores **operational gravity**. A merchant’s choice of acquirer is increasingly driven by integration into complex Software-as-a-Service (SaaS) ecosystems (e.g., Shopify, Adyen, or Square). Porting a list of tokens is trivial compared to the cost of re-engineering a multi-channel inventory system. As **Friedrich Hayek** warned in [*The Constitution of Liberty*](https://press.uchicago.edu/ucp/books/book/chicago/C/bo10271465.html), central planning—even in the form of technical mandates—rarely accounts for the "particular circumstances of time and place" that keep businesses tethered to their service providers. Under PSD3, we may find that "data is portable, but the business is stuck."