Right now: there is no single "Chat Control" law today — there are two tracks running in parallel. A
temporary rule letting platforms voluntarily scan messages was reinstated in July 2026 and runs until April 3, 2028. A
permanent regulation is still being negotiated between the Parliament, the Council, and the Commission, with the next round of closed-door talks scheduled for
September 29, 2026 — four days after this page went up. See
§4 for what's actually on the table.
1. What it actually proposes
In May 2022 the European Commission introduced draft legislation
formally called the CSAM Regulation (Child Sexual Abuse
Regulation) — the bill everyone now calls "Chat Control."[1]
It requires online platforms to assess the risk their service
will be used to spread child sexual abuse material, take
mitigation steps, and report suspected abuse to a new EU
coordinating body. None of that is controversial on its own.
The controversial part is the "detection order": a mechanism
that could compel a specific messaging app, email provider, or
hosting service to actively scan users' private communications
— including ones protected by end-to-end encryption — for known
abuse material, new abuse material, and text patterns that look
like grooming. To scan an encrypted message before it leaves
your device, the software has to inspect the contents on your
phone before encryption is applied. That technique has a name:
client-side scanning, and it's the mechanism
privacy and security researchers keep coming back to as the
crux of the fight.[2]
The case for it
Meta alone reported acting on 3.6 million pieces of suspected abuse material in 2023 under existing voluntary scanning, with human reviewers confirming a high share as genuine.[1] Supporters — most member states, child-protection groups, and the European People's Party — argue that as messaging moves to encrypted apps, law enforcement is losing the visibility it used to have, and that detection at scale is the only way to keep up.
The case against it
The EU's own data protection authorities warned in 2022 that mandatory detection risked "generalised and indiscriminate scanning" of everyone's messages, not just suspects.[1] Parliament's research service found in 2023 that no available detection technology can do this reliably without a high error rate.[1] Opponents — privacy and digital-rights groups, security researchers, and politicians across the spectrum — argue this is mass surveillance of an entire population's private messages to try to catch a much smaller number of offenders.
2. Why it threatens encryption
- Scanning before encryption breaks what encryption is for. End-to-end encryption means only the sender and recipient can read a message. Client-side scanning inspects the message on your device before it's encrypted — so the message is still private from other people, but no longer private from whatever is running on your phone. Once that scanning capability exists, it can be repurposed for anything else a government decides is worth looking for.
- False positives land on real people. Swiss federal police found roughly 80% of reports generated by an existing automated-detection pipeline turned out to be criminally irrelevant once a human looked at them.[2] German police data cited by opponents shows a majority of investigations opened from this kind of automated flagging target minors themselves, often for consensual activity between peers.[2]
Scaled to hundreds of millions of EU users, even a small false-positive rate is a very large number of innocent people's private photos and messages ending up in front of a human reviewer or law enforcement.
- Anonymity has real uses worth protecting. Mandatory age verification and the erosion of anonymous accounts, proposed alongside detection in some drafts, would also make it harder for whistleblowers, domestic abuse victims, LGBTQ+ people in hostile jurisdictions, and journalists' sources to communicate safely.[2]
- The EU's own lawyers have raised doubts. The Council's Legal Service concluded in April 2023 that mandatory detection orders risked violating the EU's fundamental rights to privacy and data protection.[1] In 2026, the same body reportedly warned that a later, broader version of the scanning proposal would likely be struck down by courts as illegal mass surveillance if enacted as drafted.[2]
3. Full timeline, 2022–2026
- May 2022European Commission introduces the CSAM Regulation, including mandatory detection orders that could reach encrypted messages.[1]
- Jul 2022EU data protection authorities warn the proposal could enable "generalised and indiscriminate scanning."[1]
- Apr 2023Parliament's research service finds no available technology reliably detects abuse material without a high error rate; the Council's Legal Service separately concludes mandatory detection orders risk violating privacy rights.[1]
- Nov 2023Parliament adopts its negotiating position: no scanning of end-to-end encrypted messages, detection limited to targeted, judicially-ordered cases.[1]
- May–Jun 2024Belgian Council presidency's compromise texts fail to win the required majority among member states.[1]
- Dec 2024Hungarian presidency's own attempt at a compromise also collapses.[1]
- Oct 2025Danish presidency drops mandatory detection from the Council's position entirely.[1]
- Nov 2025Council formally adopts a position built on voluntary detection plus new risk-assessment obligations for platforms.[1]
- Dec 2025Three-way "trilogue" talks between Commission, Council, and Parliament begin on the permanent regulation.[1]
- 26 Mar 2026Parliament votes down a further extension of the temporary voluntary-scanning derogation ("Chat Control 1.0"), which lapses on April 3, 2026.[1]
- 29 Jun 2026Fifth trilogue round on the permanent regulation ends without a deal; a Council-floated hybrid — voluntary detection for some content categories, mandatory for others, split by whether material is public or private — fails to close the gap.
- Late Jun 2026Parliament President Roberta Metsola reopens the lapsed temporary derogation, citing a child-protection gap, and sends it back to the Council.[3]
- 9–10 Jul 2026The Council relaunches the derogation as a fast-tracked proposal. Two Parliament votes to reject or amend it (314–276, then 276–286) each fall short of the 360-vote absolute majority required to block it under this procedure — so it is deemed adopted despite a plurality of MEPs voting against it, reinstating "Chat Control 1.0" until April 3, 2028, with an attached but ambiguously-worded encryption exclusion.[3]
- 29 Sep 2026Scheduled: a sixth trilogue round on the permanent regulation, reported as a potentially decisive session for whether it lands on judicially-ordered targeted scanning (Parliament's position) or broader "search plans" (the Council's).[2]
4. Where things stand right now
As of today, two separate things are true at once, and it's easy
to conflate them:
- The temporary rule is already in force. "Chat Control 1.0" — the derogation letting platforms voluntarily scan messages under an ePrivacy exemption — was reinstated in July 2026 and runs until April 3, 2028, regardless of what happens to the permanent regulation below.[1][3]
- The permanent regulation is still being negotiated. Parliament wants detection limited to specific suspects under a judicial warrant. The Council wants providers to be able to submit broader "search plans" covering portions of a service, which critics say could still reach every user of it.[2] A June 2026 attempt to split the difference — mandatory scanning for some categories, voluntary for others — didn't close the gap in the fifth trilogue round.
The next round of talks is scheduled for September 29,
2026. Advocacy groups tracking the file describe it as
one of the last chances to settle the permanent text before
positions harden further into the next EU institutional cycle.[2]
An April 2026 poll found 58% public support for stronger online
child-safety measures generally, but only 22% awareness of what
this specific proposal contains — and 28% concerned about its
effect on free expression once it was explained to them.[1]
5. Take action
These are independent advocacy organizations and tools, not run by this site — linked here because they're the actual places where contacting a lawmaker or adding your name goes somewhere.
-
A tool that drafts and sends an email to your country's MEPs on the Civil Liberties (LIBE) committee, asking them to hold the line on judicial warrants for specific suspects only — no broad search plans, no loopholes.
-
European Digital Rights' running explainer and campaign hub, updated as the trilogue talks move — the best single place to check for developments after this page was written.
-
A sitting/former MEP's long-running, detailed tracker of every draft, vote, and leak on this file, in English and German — the most granular public source this page draws from.
-
A petition asking EU decision-makers not to break encryption, framed around the same "detection order can't tell client-side scanning apart from surveillance" argument as the sources above.
If you'd rather just talk about it: #chatcontrol and #StopScanningMe are the tags most of this conversation happens under.
share this page →
6. Sources
- Wikipedia — "Chat Control", accessed 2026-09-25. Timeline, vote details, poll figures, and the 2023 Council Legal Service opinion.
- Patrick Breyer, "Chat Control: The EU's CSAM scanner proposal", accessed 2026-09-25. False-positive rates, the 2026 Council/Parliament positions on "search plans," the September 29 trilogue, and advocacy tool links.
- Euronews, "Why Chat Control 1.0 is the EU's most Orwellian law yet", 2026-07-10. The July 2026 procedural vote counts and the absolute-majority threshold that let the temporary derogation pass despite a plurality voting against it.
- European Digital Rights (EDRi) — "Chat Control: What is actually going on?" Background and the live campaign hub.