Chat Control is the informal name for two European Union measures that would have providers scan users' private messages for child sexual abuse material (CSAM). The name covers two separate instruments. Chat Control 1.0 is a temporary regulation, adopted in 2021, that lets messaging and email providers scan unencrypted communications on a voluntary basis.[1] Chat Control 2.0 is a proposed permanent regulation that would make detection of abuse material mandatory for messaging and email providers.[2]
The Electronic Frontier Foundation and other digital rights groups say that, applied to end-to-end encryption (E2EE) services, it could be enforced only by client-side scanning, inspecting messages on the user's own device before they are encrypted, and that this breaks the encryption.[3] On July 9, 2026, the European Parliament allowed Chat Control 1.0 to stay in force until April 3, 2028; Chat Control 2.0 remained unresolved.[4][5]
Chat Control 1.0
Chat Control 1.0 is Regulation (EU) 2021/1232, adopted July 14, 2021. It is a temporary derogation from Articles 5(1) and 6(1) of the ePrivacy Directive (Directive 2002/58/EC), the provisions that protect the confidentiality of communications. Those confidentiality rules would otherwise expose a provider to liability for scanning private messages, so the regulation lifts that liability to the extent a provider chooses to detect CSAM, report it, and remove it.[1]
Scanning under the regulation is voluntary, not required, and it does not reach end-to-end encrypted messages.[1] In practice the providers that use it are United States services, including Gmail, Facebook Messenger, Instagram Messenger, Skype, Snapchat, iCloud Mail, and Xbox.[6] Genuinely end-to-end encrypted services are outside its scope.[1]
The regulation was written as a stopgap pending permanent legislation. It was extended in 2024 to run until April 3, 2026, but in March 2026 the European Parliament rejected a further extension and let it lapse in early April 2026.[6]
Chat Control 2.0
Chat Control 2.0 is the proposed Regulation laying down rules to prevent and combat child sexual abuse, known as the Child Sexual Abuse Regulation (CSAR), document COM(2022) 209 final. The European Commission presented it on May 11, 2022.[2] Its author was the Commissioner for Home Affairs, Ylva Johansson.[7][8]
Three features separate it from the 2021 derogation. Detection would be mandatory rather than voluntary: national authorities could issue detection orders requiring a platform to scan for known abuse material, new abuse material, and the solicitation of children.[2] It would be permanent rather than temporary. The Electronic Frontier Foundation says that on end-to-end encrypted services such an order could be met only by client-side scanning on the user's device, which would "fundamentally break end-to-end encryption."[3]
The proposal identifies each type of content using indicators supplied from a central database held by a newly created EU Centre.[2]
The proposal has not been adopted. As of July 2026 it remained in trilogue negotiation among the Parliament, the Council, and the Commission, with the most recent round, in late June 2026, ending without agreement.[9]
Ylva Johansson's defense of the bill
Ylva Johansson was the European Commissioner for Home Affairs from 2019 to 2024 and proposed the regulation.[8][7] In a podcast interview with the Swedish newspaper Svenska Dagbladet, translated into English by the privacy company Mullvad, she compared scanning encrypted communications to a police dog sniffing for contraband:
"It's about sniffing, checking out you could say. It's not as if you read the communication; I mean, it's like a police dog being able to smell if there's something there."[7]
Asked how authorities could detect abuse material without reading encrypted messages, Johansson said encrypted communications are already scanned, and pointed to the link preview that Signal shows when a user types a web address:
"Because encrypted communication today is scanned by the companies. They scan all communications for viruses. So, if you're on Signal, and you want to send me a link to an interesting Svenska Dagbladet article, when you start typing the address of the article, a picture of the article pops up, because they're scanning it."[7]
Karl Emil Nikka, the opposing participant in the debate, corrected her. Signal's preview is built by the sender's own device, not by Signal reading the message:
"That's not even how Signal works. The way Signal works is that if you get a preview, it's because your Signal client, from your device, is taking a picture of the website and including it in the message that's being sent. Signal has no access to this information."[7]
Johansson also said the proposal had nothing to do with encryption, while at the same time declining to exclude any technology from it:
"My Bill is not about encryption, it's not even mentioned. The Bill includes nothing to do with encryption ... my Bill is technology neutral. This is not a Bill intended to break or weaken encryption."[7]
Criticism
Data protection regulators and digital rights groups have opposed the mandatory-scanning proposal. In a joint opinion on July 29, 2022, the European Data Protection Board (EDPB) and the European Data Protection Supervisor (EDPS) warned that it could do more harm than good:
"The EDPB and EDPS consider that the Proposal, in its current form, may present more risks to individuals, and, by extension, to society at large, than to the criminals pursued for CSAM."[10]
Automated detection also produces large numbers of false hits. Mullvad noted that Swiss police had measured an error rate around 80 to 90 percent, mostly on already-known material, before any attempt to have software judge new images and conversations.[7] In December 2024 the privacy group noyb reported that the European Data Protection Supervisor had found the European Commission's use of targeted political advertising to build support for the proposal in the Netherlands unlawful.[11]
Current status
Chat Control 1.0 was allowed to lapse in April 2026, then revived three months later. In late June 2026, after the Parliament had already rejected an extension, Parliament President Roberta Metsola reopened the file and sent it to the Council, which returned it to the Parliament at the start of the summer recess, when it was harder to assemble a majority to reject it again.[5] On July 9, 2026, a motion to reject the Council's position drew 314 votes for rejection, 276 against, and 17 abstentions, short of the absolute majority of 360 members needed to block it.[4] The motion failed, and Chat Control 1.0 stayed in force until April 3, 2028.[5]
Patrick Breyer, a former Member of the European Parliament, called the outcome "a farce" that "damages democracy."[12] Svenja Hahn, a Member of the European Parliament, said it was "a disgrace that the Chat Control instrument has passed" and that it opened the door to "mass surveillance of all private communication of our European citizens".[5] Chat Control 2.0, the permanent regulation, remained in trilogue negotiation and had not been adopted.[6]
Provider implementation
- Signal stated it "would leave the [EU] market" rather than comply with the Chat Control regulation, should it be passed into law.[13]
- In the early days of the regulation's proposal, WhatsApp CEO Will Cathcart stated that they "will forever be committed to end-to-end encryption", but made no comment on resisting the regulation.[14]
- Telegram has not disclosed their planned actions, but warned users in France about the consequences of the regulation through a notification.[15]
- Paid messenger Threema promised to never release a version that spies on its users. Should regulation make this impossible, they would "take consequences" and leave the EU market.[16]
See also
References
- ↑ 1.0 1.1 1.2 1.3 "Regulation (EU) 2021/1232 of the European Parliament and of the Council of 14 July 2021 on a temporary derogation from certain provisions of Directive 2002/58/EC". EUR-Lex. July 14, 2021. Retrieved July 15, 2026.
- ↑ 2.0 2.1 2.2 2.3 "Proposal for a Regulation of the European Parliament and of the Council laying down rules to prevent and combat child sexual abuse, COM(2022) 209 final". EUR-Lex. May 11, 2022. Retrieved July 15, 2026.
- ↑ 3.0 3.1 "After Years of Controversy, the EU's Chat Control Nears Its Final Hurdle: What to Know". Electronic Frontier Foundation. December 3, 2025. Retrieved July 15, 2026.
- ↑ 4.0 4.1 "Combating child sexual abuse: support for a more limited ePrivacy derogation". European Parliament. July 9, 2026. Retrieved July 15, 2026.
- ↑ 5.0 5.1 5.2 5.3 "Chat Control 1.0 passed the European Parliament through the back door". Euronews. July 10, 2026. Retrieved July 15, 2026.
- ↑ 6.0 6.1 6.2 Breyer, Patrick. "Chat Control: The EU's CSAM scanner proposal". patrick-breyer.de. Retrieved July 15, 2026.
- ↑ 7.0 7.1 7.2 7.3 7.4 7.5 7.6 "The European Commission does not understand what is written in its own Chat Control bill". Mullvad VPN. March 28, 2023. Retrieved July 15, 2026.
- ↑ 8.0 8.1 "Ylva Johansson, Commissioner (2019-2024) Home Affairs". European Commission. Retrieved July 15, 2026.
- ↑ "Chat Control 1.0 and 2.0 Explained". Fight Chat Control. Retrieved July 15, 2026.
- ↑ "Proposal to combat child sexual abuse online presents serious risks for fundamental rights". European Data Protection Board. July 29, 2022. Archived from the original on July 30, 2022. Retrieved July 15, 2026.
- ↑ "Political Microtargeting by EU Commission illegal". noyb. December 13, 2024. Retrieved July 15, 2026.
- ↑ Breyer, Patrick (July 2026). "EU Parliament greenlights Chat Control 1.0, Breyer: "Our children lose out"". patrick-breyer.de. Retrieved July 15, 2026.
- ↑ Whittaker, Meredith (2025-10-03). "For a future with privacy, not mass surveillance, Germany must stand firmly against client-side scanning in the Chat Control proposal" (PDF). Signal. Archived from the original (PDF) on 3 Oct 2025. Retrieved 2026-07-16.
- ↑ Heinrichs, Max Hoppenstedt; Horchert, Judith (2021-03-12). ""What the Government Is Asking for Would Weaken Security for All"". Der Spiegel. Archived from the original on 24 Oct 2025. Retrieved 2026-07-16.
- ↑ "Telegram warns French users over EU 'chat control' proposal, citing threat to privacy". Hespress English. 2025-10-15. Archived from the original on 15 Nov 2025. Retrieved 2026-07-16.
- ↑ "Chat Control Must Be Stopped – Now!". Threema. 2024-06-16. Archived from the original on 17 May 2026. Retrieved 2026-07-16.