# OB-AIS-004 — AIS access with or without the user

> The ASPSP lets the AISP access the designated accounts whether or not the user is actively requesting the information, and the text does not carry over the 2018 RTS limit of four accesses per 24 hours.

- Article: PSR 41(2)
- Who is bound: ASPSP
- Who it is for: API, Operations, Product
- Application: 21 months after entry into force, the general application date (Article 112).
- Level 2: No EBA mandate covers this obligation.
- Origin: RTS 2018/389, Art. 36(5)

Provisional numbering of the April 2026 compromise (Council doc. 8221/26). The final numbering will be added when the Official Journal publishes the text, without changing the id.

## STET 1.6.3: To review

The Framework has an `ACCESS_EXCEEDED` code (429) for exceeding the daily number of accesses, and `PSU-*` headers as proof that the user is connected. A daily quota built on the four-access rule no longer has any footing in the text.

- <https://openfinanceguide.com/en/stet/1.6.3/framework/3-prerequisites-and-technical-details>

## Sources

- [Council doc. 8221/26, page 255](https://data.consilium.europa.eu/doc/document/ST-8221-2026-INIT/en/pdf#page=255)

Checked on 2026-10-04. https://openfinanceguide.com/en/dsp3/obligations/ob-ais-004
