Regulation has gone from being something the API world worried about to being one of the most powerful drivers of API adoption there is. When a regulator decides an industry must expose data through APIs, an entire sector builds them on a deadline.
The clearest cases: European PSD2 and the UK’s open banking regime, which required banks to expose account and payment APIs to licensed third parties — and explicitly ended screen-scraping as the sanctioned mechanism. Australia’s Consumer Data Right, which generalized the same idea beyond banking. The US personal financial data rules under Dodd-Frank §1033. And in healthcare, the 21st Century Cures Act and the CMS interoperability rules, which pushed FHIR APIs into US health systems and made information blocking a compliance matter.
The pattern worth noticing is that the regulation names an outcome — consumers can get their data, third parties can be authorized — and a standards body supplies the machine-readable contract that makes it real. The law is the requirement; the standard is the implementation.
Whether it works is a separate question. Mandated APIs often ship to the letter of the rule with poor developer experience, thin data, and reluctant support, because the incentive was compliance rather than adoption. Meeting the mandate and building something people want to use are different projects.
A detailed catalog of these lives at regulations.apievangelist.com.