← Blog

EU Chat Control Explained: What the CSA Regulation Does and Where It Stands

    Chat Control is the EU's proposed law to scan the content of private messages for child sexual abuse material before it is sent, including on encrypted apps. It has been debated since May 2022 under the formal name the Child Sexual Abuse (CSA) Regulation. The stated goal is protecting children. The mechanism is mass scanning of everyone's communication. This is the definitive explainer: what the law does, the full timeline through its dramatic July 2026 turn, what client-side scanning actually means for encryption, the error-rate math that undermines the whole premise, who is fighting on each side, and what happens next.

    What is Chat Control?

    Chat Control is the nickname critics gave the European Commission's proposed Regulation to prevent and combat child sexual abuse, presented on 11 May 2022. In its original form the regulation would let authorities issue detection orders compelling messaging, email, and hosting providers to search users' communications for three things: known abuse images, previously unknown abuse images identified by AI, and grooming detected in the text of conversations.

    The name stuck because of how the detection works. Rather than investigating specific suspects with a warrant, the proposal would scan the messages of every user of a covered service by default. The presumption flips. Instead of monitoring the guilty, it inspects everyone to find the guilty.

    Definition

    Chat Control is the informal name for the EU's Child Sexual Abuse (CSA) Regulation, a proposed law that would require online communication providers to scan the content of private messages for child sexual abuse material and grooming, including on end-to-end encrypted services. It is called Chat Control because it inspects the communications of all users rather than targeting named suspects.

    There are actually two things people mean when they say Chat Control, and confusing them is the single biggest source of misunderstanding in the debate. We will separate them clearly below.

    Chat Control 1.0 vs Chat Control 2.0: what is the difference?

    The two are related but legally distinct, and only one of them is currently in force.

    Chat Control 1.0 is the temporary measure. Officially it is Regulation (EU) 2021/1232, an interim derogation from the ePrivacy Directive adopted in July 2021. It permits providers to voluntarily scan unencrypted messages and email for abuse material. In practice a handful of mostly US services use it: Gmail, Facebook Messenger, Skype, Snapchat, iCloud Mail, and Xbox. It does not compel anyone, and it does not touch end-to-end encrypted content. It was always meant to be a stopgap while the permanent regulation was negotiated.

    Chat Control 2.0 is the permanent regulation proposed in May 2022, the CSA Regulation proper. This is the one with detection orders, mandatory scanning, and, in the Commission's original design, client-side scanning that reaches into encrypted apps. This is the version that has drawn years of opposition from privacy regulators and cryptographers. As of July 2026 it is not law. It is still stuck in negotiation.

    Keep the split in mind: 1.0 is voluntary, unencrypted, and temporary; 2.0 is mandatory, potentially reaches encryption, and permanent. When a headline says "Chat Control passed," the honest question is always: which one, and in what form.

    The full timeline: from 2021 to July 2026

    The story is long, and the twists matter. Here is the sequence, grounded in primary and official records.

    • July 2021: The EU adopts the temporary derogation (Chat Control 1.0), allowing voluntary scanning of unencrypted messages.
    • 11 May 2022: The European Commission proposes the permanent CSA Regulation, COM(2022)209. This is Chat Control 2.0.
    • 28 July 2022: The European Data Protection Board and European Data Protection Supervisor issue a joint opinion warning that the detection measures go beyond what is necessary and proportionate.
    • November 2023: The European Parliament's LIBE committee adopts a negotiating position that explicitly excludes client-side scanning and protects encryption, putting Parliament at odds with the Commission and Council.
    • 2024: Successive Council presidencies try and fail to reach a common position. A COREPER vote in June 2024 fails to secure a majority for mandatory scanning. Hundreds of scientists publish open letters against the plan.
    • October 2025: Germany and Luxembourg join a blocking minority of member states representing more than 35% of the EU population, killing the Council's attempt to mandate scanning.
    • 12-13 November 2025: After sustained protest, the Council removes the mandatory detection obligation from its negotiating mandate. Client-side scanning is dropped from the Council text.
    • December 2025 to June 2026: Five rounds of trilogue negotiation between Parliament, Council, and Commission. The fifth and supposedly final round on 29 June 2026 collapses over whether "voluntary" scanning becomes permanent.
    • April 2026: Chat Control 1.0, the temporary derogation, expires after Parliament declines to extend it again.
    • 2 July 2026: The Council revives the expired derogation using an urgent procedure, forcing a fast-tracked plenary vote.
    • 7 July 2026: Parliament approves the urgent procedure by 331 to 304 with 11 abstentions, scheduling the decisive vote.
    • 9 July 2026: Parliament votes on whether to reject the extension. 314 MEPs vote to reject, 276 vote against rejection, 17 abstain. Because this was a second-reading procedure, blocking required an absolute majority of 361. The rejection falls 47 votes short. Chat Control 1.0 is extended until April 2028.

    The 9 July 2026 outcome is the detail most people get wrong. A majority of MEPs who voted actually opposed the extension. It survived anyway, because the procedural threshold was an absolute majority of all 720 seats, not a majority of those present. Scheduling the vote for the last session before summer recess, when many members had already left, was widely read as deliberate.

    What does "client-side scanning" technically mean?

    This is the technical heart of the controversy, and the reason the permanent regulation is so contested.

    End-to-end encryption means a message is scrambled on the sender's device and can only be unscrambled on the recipient's. Nobody in between, not the provider, not a government, not an attacker on the network, can read it. This is the security model behind Signal, WhatsApp, and iMessage.

    Client-side scanning defeats this by moving the inspection to before encryption happens. Software on your own phone examines the message, photo, or video the instant before it is sealed, compares it against a database or an AI classifier, and reports a match. The provider can then truthfully say the message was end-to-end encrypted in transit, because the reading happened on the device first.

    Definition

    Client-side scanning is a technique that inspects the content of a message on the user's own device before it is encrypted. It preserves the appearance of end-to-end encryption while defeating its purpose, because the content is read on the device rather than protected all the way to the recipient.

    Security researchers reject the idea that this is a compromise. Their argument is structural, not political. Once every phone ships with a mandated function that reads private content and phones home when it finds a match, that function becomes the most valuable target in the world. It is a surveillance capability sitting on hundreds of millions of devices, and the same mechanism that scans for abuse images can be repointed at any other content by whoever controls the matching database. The EDPS made exactly this point: client-side scanning still constitutes mass surveillance because it processes every message to find the illegal ones, and it can be trivially circumvented by a determined criminal who encrypts content with a separate app first. It weakens security for everyone while barely inconveniencing the target.

    The false-positive and mass-surveillance math

    Even setting aside the encryption problem, the numbers do not support the premise that mass scanning is an effective way to protect children.

    Scanning at this scale means processing billions of messages to find a small number of genuinely criminal ones. When you run a probabilistic classifier across that volume, even a very low error rate produces an enormous absolute number of false alarms, each one flagging an innocent person's private photo or message for human review. The official statistics from bodies that have actually run these systems are damning:

    • Swiss federal police reported that around 80% of the machine-generated reports they received were criminally irrelevant.
    • Ireland's national police, An Garda Síochána, confirmed that only about 20% of the reports they received from the US clearinghouse (NCMEC) in 2020 were actual child abuse material.
    • Former EU Commissioner Ylva Johansson, the proposal's own champion, cited that roughly 75% of the flagged chats, out of around 300,000 reported EU chats per year, were not actionable.
    • Germany's Federal Criminal Police Office (BKA) noted that a large share of investigations into abuse material actually target minors themselves, for consensual sexting, rather than predators.
    • The Commission's own 2025 implementation report admitted there is no proven link between scanning private messages and actual convictions or children rescued.

    The implication is uncomfortable. A system that flags four innocent people for every real hit does not just waste investigators' time. It routes private, often intimate, images of ordinary citizens and their children into review pipelines and law-enforcement databases. The privacy cost is certain and universal. The child-protection benefit is unproven by the Commission's own admission. That is the trade at the center of the whole debate.

    Who supported it and who opposed it?

    The battle lines cut across the usual institutional roles.

    The supporters

    The European Commission, particularly under former Home Affairs Commissioner Ylva Johansson, drove the original mandatory proposal. Successive Council presidencies pushed to keep detection orders and, at various points, client-side scanning in the text. Several member states, along with some child-protection organizations, backed strong mandatory scanning as necessary to fight a real and serious crime. The sincerity of the goal is not in question. The dispute is over the method.

    The opponents

    The opposition is unusually broad and technically credible:

    • The European Data Protection Supervisor and European Data Protection Board, the EU's own privacy regulators, warned in their July 2022 joint opinion that the measures were disproportionate and that client-side scanning amounts to mass surveillance.
    • The European Parliament adopted a negotiating position that removed client-side scanning and protected encryption, refusing to endorse the Commission's version.
    • A blocking minority of member states, led by Germany and including Luxembourg, used qualified-majority-voting rules to stop the Council from mandating scanning.
    • More than 500 cryptographers and security scientists from 34 countries signed open letters calling the plan technically infeasible and a danger to democracy. Signatories included Bart Preneel (KU Leuven) and Carmela Troncoso (EPFL), among the most cited names in applied cryptography.
    • Journalists and activists, notably the German outlet netzpolitik.org and former MEP Patrick Breyer, documented the process and kept public pressure high.

    When your own data protection regulators, your directly elected parliament, a blocking minority of governments, and the field's leading scientists all say a measure is disproportionate and technically unsound, that is not fringe opposition. That is the institutional and expert core of the EU telling the Commission the design is wrong.

    The 1984 frame: the telescreen in your pocket

    George Orwell's telescreen watched you inside your own home. What made it total was not that the state read your letters in transit. It was that the surveillance sat with you, in the room, before you had said or done anything. The device itself was the informant.

    Client-side scanning is the closest real-world analogue we have built. It does not intercept your message on the wire, where at least encryption could protect it. It inspects your thought at the moment you commit it to the device, before it leaves your hands. The check happens on your side of the encryption, which is to say, inside the one place that was supposed to be yours alone.

    This is why the privacy objection is not hysteria about a specific database of abuse images. The database is the least permanent part. What is permanent is the architecture: a legally mandated function on every device that reads private content and reports matches. Build that once, for a purpose almost no one would argue against, and you have built the mechanism. What it scans for after that is a policy decision, changeable by the same institutions, subject to the same pressures, reachable by whoever can compel or compromise the list. The presumption of privacy, the default that your private communication is private until there is specific cause to suspect otherwise, is what gets inverted. That inversion is the thing worth resisting, independent of any single use.

    What happens next?

    Two tracks run in parallel, and it is worth watching both.

    On the temporary track, Chat Control 1.0 is now extended until April 2028. Voluntary scanning of unencrypted messages by the usual providers continues. The immediate fight over the derogation is settled for now, in favor of the extension.

    On the permanent track, Chat Control 2.0 remains unresolved. After the June 2026 trilogue collapse, negotiations are expected to resume under the Irish Council presidency, likely around September 2026. The unsettled question is whether "voluntary" scanning gets locked in permanently, and whether any future text tries to reintroduce detection orders or client-side scanning that the Parliament and the blocking minority have so far kept out. Nothing about this is final. The proposal has been declared dead and revived more than once already.

    For anyone whose work depends on confidential communication, lawyers, doctors, journalists, and any business handling sensitive conversations, the practical lesson does not wait for the final vote. The direction of travel is clear: regulators are increasingly willing to treat scanning of private communication at the edge as normal. The question that used to feel abstract, where and under whose jurisdiction is my most sensitive communication actually processed, is becoming a question every organization has to answer for itself. We take that up in the follow-up piece on why where your conversations get processed now decides everything.

    If you want the wider context on jurisdiction and processing, our guides on what sovereign AI actually means and the US CLOUD Act loophole in EU data centers cover the ground that Chat Control makes newly urgent.

    Frequently asked questions

    What is Chat Control?

    Chat Control is the informal name for the EU's Child Sexual Abuse (CSA) Regulation, first proposed by the European Commission on 11 May 2022. It would require messaging and email providers to scan the content of private communications for child sexual abuse material and grooming, including on end-to-end encrypted services via client-side scanning. Critics call it Chat Control because it turns every user's device into a scanning checkpoint rather than targeting specific suspects.

    Is Chat Control now law in the EU?

    As of July 2026, the permanent CSA Regulation (Chat Control 2.0) is not yet law. It remains stuck in trilogue negotiations after the June 2026 round failed. However, the temporary derogation known as Chat Control 1.0, which permits voluntary scanning of unencrypted messages, was extended on 9 July 2026 until April 2028 after the European Parliament failed to reach the 361-vote absolute majority needed to block it (314 voted to reject, short of the threshold).

    What is client-side scanning?

    Client-side scanning means software on your own phone inspects a message before it is encrypted and sent. Because the check happens on the device, providers can claim end-to-end encryption is technically intact while still reading the content. Security researchers argue this breaks the guarantee of encryption entirely: it installs a permanent surveillance function on every device that can be repurposed or exploited by others.

    Who opposes Chat Control?

    Opponents include the European Data Protection Supervisor and European Data Protection Board (joint opinion, 28 July 2022), the European Parliament's negotiating position (which excluded client-side scanning), a blocking minority of EU member states led by Germany, and more than 500 cryptographers and security scientists who signed open letters calling the plan technically infeasible and a danger to democracy.

    How accurate is message scanning for detecting abuse?

    Official figures suggest very high error rates. Swiss federal police reported that around 80% of machine-flagged reports were criminally irrelevant. Irish police confirmed only about 20% of the reports they received in 2020 were actual abuse material. Former Commissioner Ylva Johansson cited that roughly 75% of flagged chats were not actionable. The Commission's own 2025 implementation report found no proven link between mass scanning and convictions or children rescued.

    Chat Control makes one question unavoidable: where is your most sensitive communication actually processed? Numi is a sovereign meeting assistant that keeps your call audio, transcripts, and coaching inside EU jurisdiction, on infrastructure you can point to.

    Get Early Access