Earlier quoted context omitted.
It can no longer be against the terms of service of financial service providers to prohibit sharing the credentials used to access your accounts on their systems?
Yes, every UK bank had to write to their customers updating their terms allowing such activity end of last year.
Are we talking at cross-purposes here? Encouraging non-experts to share security credentials that give unrestricted access to their accounts with third parties is so obviously dangerous that I find it hard to believe that (a) the financial providers are now required by law to do it, and (b) not a single one of the updates I received from mine drew attention to this in any way that I noticed and recall now.
Surely the entire point of the new access paths under PSD2 is that the financial providers don't have to endorse the dangerous practice, and can instead provide an alternative way to achieve similar results but with much better control and regulation to protect all involved?