Mobile-only approach to customer authentication will not be enough for EU compliance
In June 2023, the European Commission published its draft proposals for the
Directive on Payment Services and Electronic Money Services (“PSD3”) and the Payment Services Regulation (“PSR”), which will become the successors of the revised Payment Services Directive (“PSD2”) and the revised E-Money Directive (“EMD2”). Article 88 of the PSR proposal stipulates that financial institutions must not use a single Strong Customer Authentication (SCA) mechanism, such as a mechanism based on smartphones, but instead support various authentication mechanisms. These requirements imply that financial institutions cannot adopt a mobile-only approach. Financial institutions will need to support other authentication mechanisms such as hardware authentication devices, in addition to SCA mechanisms based on smartphones.
Article 88 of the PSR requires financial institutions to ensure that all users can perform SCA, including people with disabilities, older persons, and those with low digital skills. It also includes those who do not have access to digital channels or payment methods.
So: "These requirements imply that financial institutions cannot adopt a mobile-only approach."
If your bank directors have refused to give you a hardware key, or some other alternative to the phone app, they are in breach of the EU regulations. I would definitely look for a better bank. Take your custom elsewhere.