On 7 September 2026, the Department for Business, Innovation, Science and Trade published the outcomes of its Smart Data Challenge Prize: ten finalists and one fellow, working with Nesta Challenge Works and the Open Data Institute, tasked with proving what Open Banking-style data sharing could do once extended into energy, transport, property and retail. With the Data (Use and Access) Act 2025 now law and £36 million committed to Smart Data, this isn't a thought experiment - it's the next phase of the expansion this blog has been tracking.
The report is careful to flag that finalist proposals are self-submitted and haven't been independently validated by government. But one finding, across finalists working in completely unrelated sectors, does need to be taken seriously, not least because the fix most of them reached for doesn't hold up.
Rodeo, working on portable earnings data for gig workers, proposed a scheme modelled directly on Open Banking. Its own description of what that scheme would need is worth quoting in full: "The scheme would also need clear governance arrangements. These would include rules on accreditation, data protection, audit logs, consent management, dispute resolution and ongoing compliance."
Here's where the proposal runs into trouble. Rodeo's own next sentence: "A central body or regulator would likely be needed to approve standards, oversee participants and make sure the scheme operates consistently."
This is precisely the wrong answer. A regulator's authority runs vertically, inside one sector: the FCA in financial services, Ofgem in energy, the ICO across data protection generally but with no sector-specific enforcement teeth. Smart Data, by design and by government's own stated ambition, runs horizontally - across energy, property, transport, retail and finance at once. No existing regulator has jurisdiction across all of those. Building one that does means new primary legislation, a new arm's-length body, ministerial sign-off, and years of consultation before it can approve a single participant.
The report's own cross-cutting conclusions describe exactly this bind, without drawing the obvious lesson from it: "policymakers may want evidence of viable services before supporting a scheme, while businesses may hesitate to invest in services that depend on infrastructure not yet in place." That is a chicken-and-egg problem with no natural end point, because it assumes the only path to accreditation infrastructure runs through a regulator that doesn't yet exist, for a cross-sector mandate no regulator currently holds.
VoltView, working on combined energy, property and financial advice for SMEs, ran into the identical structural gap without reaching for a registry. Its own account: "Energy Smart Data regulations are still developing, and VoltView identifies a need for clarity on how new requirements would interact with existing Authorised Third-Party obligations. This includes the permitted use of data and liability where advice combines energy, property and financial information."
Authorised Third-Party status in energy doesn't answer a liability question that only arises when energy data gets combined with financial advice. Nobody's vertical mandate covers that combination, because the combination is the whole point of Smart Data - and the report's own synthesis names this as a pattern, not a one-off: "governance became harder as datasets were combined," true across six of the ten finalists working in unrelated sectors.
None of this means Rodeo and VoltView are wrong about what's needed. Accreditation, continuous risk monitoring, audit trails, and clear liability when data crosses sector boundaries are exactly the right requirements. What's wrong is the assumption that a regulator is the only entity that can supply them.
A commercially operated, cross-sector accreditation and risk-monitoring layer doesn't have this problem, for the simple reason that it was never confined to one sector's statutory boundary in the first place. It doesn't need primary legislation to acquire jurisdiction over energy, property and financial data together - it can be built to cover all of them from day one, because its authority comes from the participants who choose to be accredited against it and the institutions who choose to rely on that accreditation, not from a ministerial designation order. It can onboard a new sector as Smart Data expands into it, on a commercial timeline, rather than waiting for a new regulatory mandate to be legislated. And because it isn't a periodic approval process but standing infrastructure, it can monitor participants continuously - catching a provider whose risk profile has changed since accreditation, rather than only checking once at the point a regulator signed it off.
That's the gap this Challenge surfaced. Ten finalists, working across five different sectors, converged on the need for accreditation and cross-sector governance. Government's own report makes the honest case for why a new regulator is unlikely to supply it quickly enough. The infrastructure that can move at the speed Smart Data now needs to move is commercial, neutral, and built to run horizontally across the sectors this Challenge was designed to connect - not vertically, inside just one of them.
Invela is the infrastructure layer that makes open finance trustworthy - accrediting who's in the network, monitoring risk in real time, and ensuring liability lands in the right place.
Learn more about the Invela Network.
Invela is the infrastructure layer that makes open finance trustworthy - accrediting who's in the network, monitoring risk in real time, and ensuring liability lands in the right place.