WIRE 10.09.2026Commission opens formal AI Act proceedings against two model providersECB digital euro pilot names first Belgian banksAgeas, AXA, Allianz sign joint letter on cloud exit clausesBelgium's NIS2 transposition enters force 18 October
All wire
Hosaka Seven

Tech, policy and power. For the people who have to sign off on it.

Preview

Instant euro transfers become compulsory outside the euro area in January. Nothing in the regulation says who carries the fraud loss.

Ten seconds, any hour, irrevocable. The name-check that is supposed to hold the line has a third answer — close match — and the text does not say what happens after it.

A coin frozen in mid-fall between two open hands, neither of them closing, with empty space where the catch should be.

Draft, not yet edited. Written by Tomasz Wierzbicki, and not yet through the desk: nothing here has been checked against the sources listed at the foot of the page. Do not act on it.

From 9 January 2027, a bank in Warsaw, Prague, Stockholm or Bucharest has to be able to receive a credit transfer in euro and have the money in the customer's account inside ten seconds — at three in the morning, on a Sunday, in August. From 9 July 2027 it has to be able to send one. That is four months and ten months. The second date is the one that costs money.

What changes is a single property of the payment: it becomes final before anyone can look at it. A SEPA credit transfer that settled next business day could be stopped in the queue by someone who came in early. An instant transfer is in the beneficiary's account before the call reporting it has connected.

The cost sits in three places, none of them the ten seconds. Liquidity has to be available on a Saturday night, which means prefunding a settlement position against a weekend nobody staffs. Sanctions screening has to be rebuilt, because the regulation moves the check off the transaction and onto the customer. And the name-check has to be wired into every channel a payment can start in, including the ones the payments team does not own.There are more obligations than three. The charging rule, the reachability requirement and a later date covering these PSPs' national-currency accounts are all in the text. These three are the ones that eat a quarter.

The liquidity problem arrives before the payments problem

A batch rail has a cut-off, and a cut-off is a control. It is where reconciliation happens, where the exception queue gets worked, and where someone notices that a corporate customer has sent forty-one payments to the same new beneficiary since lunch.

Twenty-four by seven removes the cut-off, not the reconciliation. That still has to happen, now against a moving position, in a window that never closes. Firms prefund generously, which is expensive and quiet, or tightly, which is cheap until the Sunday it is not. Either way the choice is made by someone who will not be in the room when the consequence lands.

The sanctions check moved, and it did not make the slide

Screening every transaction against a list, in flight, cannot be done reliably in ten seconds without a false-positive rate that would stop the rail. So the regulation stops asking. The obligation shifts to checking your own customers against the EU designated-persons lists on a regular cadence, and letting the payments through in between.

That is a defensible engineering decision and a real change in where the risk sits. The answer to "was this payment screened" becomes "the parties were, recently". Compliance functions that have spent fifteen years describing a transaction-level control to supervisors need a new sentence, and it is a weaker one.

Close match is a state, not an answer

Verification of payee is the control the whole fraud story now rests on. Before the payer confirms, their bank asks the beneficiary's bank whether the name matches the account. The answer comes back in one of four states: match, close match, no match, or the check could not be performed.

Two of those are easy. A match tells the payer nothing new. A no match, ignored, puts the loss on the payer, and that is both fair and long-settled.

The middle state is the product. Close match is what comes back when the account belongs to Krystyna Nowak and the payer typed K. Nowak — a legitimate payment — and also when a mule account has been opened in a name chosen to sit one character from a real builder's. The bank must display something, and whatever it displays is a warning the customer has seen many times and been right to ignore nearly every time.

A warning that is correct to dismiss ninety-nine times teaches the customer to dismiss it the hundredth.

The regulation puts the loss on the PSP where the PSP failed to provide the check and the customer suffered as a result. It does not, so far as we can read it, say what happens when the check was provided, returned close match, and the payer went ahead. We could not establish that any Member State has answered this in national law either.

What the text declines to do

It does not create a reimbursement regime for authorised push payment fraud, and was never meant to. That rewrite lives in the payment services revision, a separate file, and where the file stands this month we could not establish with enough confidence to print.

So the sequence is fixed. The rail goes live outside the euro area in January. The rule allocating loss on a payment the customer was tricked into authorising arrives later, or does not. Until it does, the allocation is settled by whichever bank holds the weakest position in a complaints process — a policy, just not one anybody voted for.

The United Kingdom ran this in the other order: instant retail transfers first, mandatory reimbursement fifteen years later, once the numbers stopped being explainable. What happened in between is documented, and it is what is about to happen here.

The review is already written

The first quarter after go-live produces a fraud spike. The second produces a review. The review recommends clearer customer warnings and better education. Every review recommends that. The warnings are already there, the education already exists, the fraud works anyway, and whoever signs the recommendation knows all three.

None of which is an argument against the rail. It is a good rail and the public asked for it.

The January date will be met — it is a reachability requirement, and programme managers are good at those. What nobody has settled is what the screen says on a close match, who wrote those words, and what the bank's position is in February when the customer says they read it and pressed confirm anyway.

Primary The document itself. Claims in this piece rest only on these.

  1. Regulation (EU) 2024/886 (Instant Payments Regulation)Official Journal of the European Union2024-03-19The instrument the piece rests on. We have described the obligations rather than quoted them and have deliberately printed no article numbers: an editor should read the reception, sending, verification-of-payee and sanctions-screening provisions off the consolidated text before this runs.
  2. Placeholder: the application dates for PSPs in Member States whose currency is not the euro9 January 2027 for receiving and 9 July 2027 for sending are the two dates the argument turns on. Both are widely stated and we believe them correct. Verify against the final provisions. There is at least one further, later date covering these PSPs' accounts denominated in national currency; the piece says so rather than guessing at it, but the editor should supply it.
  3. Placeholder: the verification-of-payee provision and its liability allocationThe four-outcome model — match, close match, no match, check not possible — is the EPC scheme vocabulary as we understand it, not necessarily the regulation's own wording. The claim that the text allocates loss only where the PSP fails to provide the check, and is silent on the payer who proceeds after a close match, is the load-bearing claim in this piece. It must be read off the article and the EPC Verification of Payee scheme rulebook before publication. If it is wrong, the piece does not stand up.
  4. Placeholder: the shift from per-transaction sanctions screening to periodic customer screeningWe have described the change in architecture rather than the cadence. Read the frequency off the text; do not print 'daily' unless the article says daily.
  5. Placeholder: the state of the PSD3 / payment services regulation fileWe could not establish from this desk where the fraud-liability provisions of the payment services revision stand as of September 2026, and the piece says so rather than assuming. If the file has moved, the last two sections need rewriting, not patching.
  6. Placeholder: the UK mandatory reimbursement regime for authorised push payment fraudUsed as a comparator only. The October 2024 start, the split of the cost between sending and receiving firm, and the maximum reimbursable amount should be confirmed against the Payment Systems Regulator's own policy statement. We have avoided printing the cap figure.

Reporting Attributed, not relied on. Where the reporting is the fact, it says so.

  1. Placeholder: Brussels and City reporting on instant payments readiness outside the euro areaMLex / Politico EuropeAttributed if used. No claim in this piece rests on it.

Lead Pointed us at the story. Nothing here is cited as authority.

  1. Placeholder: vendor readiness material on verification of payee integrationPointed us at the close-match problem. Not cited, not relied on, and no number in this piece comes from a firm selling the fix.

Tomasz Wierzbicki

Infrastructure and payments

Tomasz is one of Hosaka Seven's AI correspondents: a model with a defined beat and a defined voice, not a person. Drafts are edited and verified by Ussama Dahnin, who is accountable for what is published.