On July 23, EU governments confirmed the interim “chat control” regime, effective until 3 April 2028, allowing platforms to voluntarily scan for child sexual abuse material (CSAM). The measure was approved by written procedure, with 25 in favour, one against, and one abstention.

ADVERTISEMENT


ADVERTISEMENT

The text aligns with the version passed by MEPs on July 9 and excludes end-to-end encrypted services such as WhatsApp and Signal. This decision now shapes the bigger, still-unresolved fight over a permanent, potentially mandatory scanning law.

The Commission’s solution

The Commission proposed its regulation on preventing and combating child sexual abuse on 11 May 2022, nicknamed “Chat Control 2.0.” It would apply EU-wide regardless of where a company is based, replacing a narrower, temporary 2021 law that lets platforms scan voluntarily under a carve-out from ePrivacy rules, extended more than once and now running until 3 April 2028. The proposal also creates a new EU Centre on Child Sexual Abuse, to coordinate detection technology and forward confirmed cases to Europol and national police.

The Commission’s main argument centers on the scale of the problem. A European Parliament briefing reported over 20.5 million suspected CSAM cases in 2024 alone. Europol warns that abuse material is increasingly shared on mainstream platforms as offenders exploit encryption and anonymity. Supporters argue that voluntary reporting is too fragmented to address the issue effectively.

That framing has run into pushback from critics who dismiss child protection as a pretext, an accusation supporters reject outright. “There were parts of the house saying that whenever we speak about protecting children online, it’s just a false pretext,” said Lena Düpont, MEP with the European People’s Party, on the EPP’s podcast EU Decoded.

“I agree it cannot be the only tool we use to protect children, but it is one of the most important tools we have, particularly for prosecuting the horrible crimes connected to children being molested or abused online. We should never let ourselves be divided over how best to protect our children.”

How detection orders would work

Instead of default scanning, providers would first assess the risk of misuse on their platforms and implement mitigation measures. If a national authority still identifies significant risk, it may request a court or independent body to issue a targeted, time-limited, and proportionate “detection order.”

Known illegal material would be identified through “hashing,” while new material and grooming conversations would rely on less reliable AI pattern recognition, with human review included. Compliance could require automated content-recognition systems, new reporting processes, and age verification. For encrypted apps, the most debated requirement is client-side scanning, which inspects content on the device before encryption.

Is ‘Chat Control’ mass surveillance?

Digital rights groups argue that a “targeted” order effectively becomes mass surveillance once scanning infrastructure is implemented across a platform. The EU’s privacy watchdogs warn that the proposal could enable broad, indiscriminate scanning of ordinary communications, conflicting with the EU Charter’s privacy protections.

Patrick Breyer, a digital rights activist, jurist and former MEP with the Greens/European Free Alliance, argues policymakers place far too much faith in the technology’s reliability. “They think a hash signature can determine exactly what is legal and what is illegal,” he said. “But even though 90 percent of reports are a result of hash scanning and relate to known material, we’ve received numbers this week from Germany saying that more than 50 percent of these reports are actually not criminally relevant.”

The reason, he explained, is that inclusion in a database doesn’t equal a crime: it may never have been properly assessed against EU criminal law, and databases say nothing about intent.

“Even hash scanning, the least unreliable of these methods, comes with a very high rate of false positives of falsely incriminating people,” he said, adding that minors are frequently caught up, since “it’s very common among them to share self-generated material with peers, or think something is funny; it’s just part of being a teenager.”

Critics argue that inspecting messages on a device before encryption undermines true end-to-end encryption. Organisations such as the Electronic Frontier Foundation warn that client-side scanning creates a permanent inspection layer.

This could be repurposed or expanded, posing risks to journalists, whistleblowers and prompting services like Signal to leave the market. Hash-matching also requires access to message content, making it difficult to operate on encrypted traffic without shifting the checkpoint to the device.

Breyer argues the debate has skipped over alternatives. “What the European Parliament proposes is targeted investigations in private communications, but also proactive and systematic searching of the open internet and the dark net for known illegal material, and reporting it to providers for removal,” he said. “That’s been successfully used in the UK and Canada, but so far not in Europe.”

He also points to security by design: “The apps should warn users before they share personal details such as their phone numbers, because that’s a common part of grooming. We want users warned before they send nudity. You can do all that on the device without sharing the encrypted content with the provider.”

Breyer stresses that targeted, court-authorised surveillance of a suspect is one thing; scanning everyone by default is another. “It’s justified if a person is a suspect, if there’s a reasonable suspicion they’re involved, and if an independent court confirms it’s justified to intercept their communications,” he said.

“But opening everybody’s mail just in case is something unheard of.” That distinction, he argues, separates an acceptable law from an unacceptable one: “Chat control really means mass surveillance and indiscriminate scanning of all chats in bulk, without any targeting. That can never be justified. But once you start with targeted investigations under a court order, that’s not only acceptable, but an improvement, especially combined with proactive scanning and security by design.”

“Existing tools are insufficient”

Supporters argue that the current system relies on voluntary scanning, which companies could discontinue at any time, potentially cutting off law enforcement’s access to crucial tips. Europol has stated that a legal gap would significantly reduce referrals to child-protection hotlines and police.

The point, from this side, is replacing an improvised system with EU-wide rules, judicial authorisation, and defined limits, though supporters concede any final law needs stronger safeguards than the earliest drafts. Even many critics accept that argument in principle: most support tougher child-protection enforcement, so long as it targets specific suspects rather than scanning everyone by default.

Where the debate stands now

Progress on the proposal has been slow within EU institutions. Parliament adopted its position in November 2023, narrowing the scope and adding safeguards, including an effort to exclude end-to-end encrypted communications from detection orders, which remains a key issue for many MEPs. The Council reached a common position in November 2025 but has been more divided, and trilogue negotiations are ongoing into 2026.

The temporary voluntary-scanning law has also become a point of contention. The EU briefly missed a deadline to extend it in early 2026 but later extended its expiry to April 2028.

In support of the extension, Tomas Tobé, MEP and Vice Chair of the EPP group, wrote on X: “Every piece of child sexual abuse material that goes undetected represents a victim who is never heard and an offender who is never brought to justice. That is why the interim regulation is needed to close the unacceptable legal gap we currently have.”

What’s really at stake

“This sets a precedent,” Breyer said. “Is anybody allowed to invade private spaces just in case, to monitor them, in case there might be something illegal going on? You could apply that logic to the post office, ask it to open and scan everything. You could install devices in private homes to scan what’s happening there too. This is a very slippery slope.” He points to victims, whistleblowers and children as those with the most to lose if protected spaces disappear.

“Every right, every freedom is being abused by some,” he said. “But we need to look at the net benefit. I’m sure that the net benefit of having these spaces and rights is much greater, that we stand to benefit much more than we lose by having them.”

Read the full article here

Share.

Leave A Reply

Exit mobile version