New web APIs speak JSON (JSON, Columnar and Binary Formats), but whole industries standardized on XML first, and their standards still govern what partners exchange: ONIX for Books carries product metadata from publishers to retailers, ISO 20022 defines payment messages with XML Schemas (the Eurosystem's T2 moved to it in March 2023), XBRL and Inline XBRL carry company filings such as the SEC's, and Office Open XML, SVG, RSS and sitemaps are XML inside everyday files and websites.
XML also handles mixed content, text with markup inside it, as in <summary>A <i>lighthouse</i> keeper's daughter</summary>, which still reads as one string; JSON needs an invented convention for that. Add namespaces (Namespaces and xml: Attributes), schemas that check business rules (Document Type Definitions to Schematron) and signatures (Signing and Encrypting XML); subtract verbosity, untyped values and risky parser defaults (XML Security). For a new internal API, JSON is usually the better default; when a partner or a standard defines XML, consume XML, validate it, then convert it to tables.