Regulations are, from a business perspective, both a burden and one of the most powerful market forces shaping the API economy — and the organizations that understand this navigate them as opportunity rather than just cost. Where the politics of regulation is about state power and public interest, the business of regulations is about the concrete reality that legal and compliance requirements increasingly dictate how companies must operate their APIs, and that these requirements create costs, risks, opportunities, and competitive dynamics. PSD2, GDPR, the HHS healthcare rules, CFPB banking rules, PCI-DSS, SOC 2 — these aren’t abstract policy debates to a business; they’re requirements that have to be met, with real consequences for failure and real opportunities for those who meet them well. I’ve watched regulations transform entire industries’ relationship to APIs, and the business lesson is consistent: regulation is a force you can fight, comply with grudgingly, or turn into a competitive advantage, and the smartest companies choose the last.
Regulation as a driver of API adoption is the most important business dynamic, and banking is the clearest case. I wrote extensively about how PSD2 in Europe meant no more scraping of banking data — only APIs — effectively mandating that banks build APIs whether they wanted to or not. The key points of PSD2, open banking in the UK, the CFPB’s rules in the US — all of these regulations forced banking, one of the most conservative industries, to expose APIs. From a business perspective, this is regulation creating a market: the regulatory mandate generated enormous demand for API development, API management, compliance tooling, and the fintech businesses that build on the now-mandated banking APIs. Regulation didn’t just impose costs; it created an entire business ecosystem. The companies that recognized open banking as a business opportunity rather than just a compliance burden — building the APIs well, creating fintech products on top of them, offering the tooling to comply — turned the regulation into revenue.
The healthcare parallel reinforces the pattern, and the business stakes are enormous. The HHS and CMS rules I wrote about in 2020 mandated that healthcare providers and insurers expose APIs to give patients access to their data — and like PSD2 in banking, this regulatory mandate created a massive market for healthcare API development, FHIR implementation, and the businesses built on healthcare interoperability. The business reality is that healthcare, like banking, was forced into APIs by regulation, and that forcing created opportunity for everyone positioned to help the industry comply and build on the mandated infrastructure. Regulation as a business driver follows this consistent pattern: a regulatory mandate forces an industry to build APIs, and the forced infrastructure becomes a foundation for new businesses, new products, and new revenue. The regulation is the catalyst; the API economy that grows around compliance is the result.
Compliance as competitive advantage is the business insight that separates the savvy from the reactive, and AWS modeled it. I wrote in 2018 about AWS having a head start helping navigate regulatory compliance in the cloud — because AWS recognized that compliance navigation at scale is genuinely hard and genuinely valuable, and built a real business advantage out of mapping which services meet which regulatory requirements. This is compliance as a product: when regulation is complex and the stakes of non-compliance are high, helping customers navigate compliance becomes a valuable service. The companies getting ahead of EU regulations that I wrote about in 2018 understood the same thing: being proactively compliant, and being able to demonstrate it, is a competitive advantage that earns enterprise and government trust. In a regulated environment, demonstrable compliance isn’t just risk avoidance — it’s a market differentiator that opens doors closed to less-compliant competitors.
The cost-and-burden reality is the honest other side, and I don’t want to romanticize it. GDPR forcing organizations to ask hard questions about their data, as I wrote in 2018, imposed real costs — the work of data inventory, the privacy-by-design requirements, the operational changes. Regulations are genuinely burdensome: they require investment, they constrain operations, they create compliance overhead, and they carry real penalties for failure. The business of regulations includes this cost side honestly. But the framing I’ve consistently argued for is that this cost is unavoidable and that fighting it is usually futile, so the strategic question is how to meet the requirements efficiently and, where possible, turn the compliance investment into competitive advantage. The organizations that treat regulation as a pure cost to be minimized often comply poorly and miss the opportunity; the ones that treat it as a business reality to be navigated strategically turn the same requirements into trust, differentiation, and new markets.
The deepest business lesson about regulations, which I’ve watched play out across multiple industries, is that regulation increasingly shapes the API market more powerfully than almost any other force, and businesses ignore it at their peril. The top industries in need of API regulation that I identified in 2025 — payments, healthcare, advertising — are exactly the industries where regulation is creating or will create the biggest API markets, and the businesses positioned to serve those regulated markets are positioned to thrive. The CFPB’s choices about whether to mandate APIs or just “developer interfaces” in its 1033 rule, which I wrote about in 2024, are business-consequential decisions that shape what the market for banking data access will look like. From a business perspective, regulation is not a side issue or a compliance afterthought — it’s one of the primary forces determining where API markets form, which industries are forced into APIs, what the cost of operating in regulated spaces will be, and where the competitive advantages lie. The businesses that read the regulatory landscape well — anticipating where regulation will mandate APIs, positioning to serve the regulated markets, turning compliance into competitive advantage, and meeting requirements efficiently rather than grudgingly — are the ones that turn the heaviest regulatory burdens into business opportunity. Regulation is a business force as much as a political one, and treating it strategically rather than reactively is one of the most important disciplines in building a durable API business in an increasingly regulated digital economy.
References
- No More Scraping Of Banking Data In Europe According To PSD2, Only APIs
- AWS Has Head Start Helping Navigate Regulatory Compliance In The Cloud
- Key Points From The Payment Services Directive 2 (PSD2)
- What Is Open Banking In The UK
- US Companies Getting Ahead Of EU Regulations
- GDPR Forcing Us To Ask Questions About Our Data
- HHS And CMS Finalizes Rules To Provide Patients More Control Of Their Health Data Using APIs
- CFPB’s Choice To Use Developer Interfaces Instead Of APIs In The 1033 Rule
- The Top Three Industries In Need Of API Regulation