Chat Control makes the everyday tools you already use worth a second look: the ones that are not end-to-end encrypted, or that process your data under US jurisdiction, are the ones exposed to scanning. This is a practical swap guide. Category by category, it maps which common tools leave your communication scannable, and which end-to-end encrypted or EU-sovereign alternatives close that gap. Then the harder question: if the stricter version of Chat Control passes, even switching to encryption stops being enough, and where your data is processed becomes the whole game.
What does Chat Control actually change for your tools?
Two different laws travel under the name Chat Control, and only one is currently in force. Confusing them is the fastest way to make the wrong decision, so the distinction is worth pinning down before you change anything.
Chat Control 1.0 is the interim voluntary regime, Regulation (EU) 2021/1232, a derogation from the ePrivacy rules that lets communication providers voluntarily scan unencrypted messages and email for abuse material. It was extended on 9 July 2026 to run until April 2028. Chat Control 2.0 is the proposed permanent CSA Regulation, still in negotiation, which contemplates mandatory detection orders and client-side scanning that would reach into encrypted apps.
The practical takeaway from 1.0 is simple. Voluntary scanning only touches content the provider can actually read, which means unencrypted messages and email. A July 2026 amendment made the point explicit by formally excluding end-to-end encrypted communication from the scope of voluntary scanning. So under the regime that exists today, moving to a genuinely end-to-end encrypted tool takes your content out of scanning range. That is the lever this guide pulls. For the full legislative background, see our explainer on what the CSA Regulation actually does.
There is a second axis that matters just as much as encryption: jurisdiction. A tool can be technically secure and still sit under a legal regime that can compel access to it or to its metadata. Most of the default tools people reach for are run by US companies, which means the content or the metadata is reachable under US law, including the CLOUD Act, regardless of where the servers physically sit. Encryption answers "can they read it." Jurisdiction answers "who can compel it." A good swap improves both.
The swap table: exposed tool to encrypted or sovereign alternative
The table below is the short version. Each row names a category, why the common default is exposed, and where to move. The detail for each row follows underneath. Every claim here reflects each tool's stated encryption model and corporate jurisdiction as of July 2026; verify against the provider before you standardize on anything, because these things change.
| Category | Exposed default | Why it is exposed | Switch to |
|---|---|---|---|
| Messaging | Telegram cloud chats, Facebook Messenger | Not end-to-end encrypted by default; provider can read content | Signal, Threema, or self-hosted Matrix/Element |
| Gmail, Outlook / Microsoft 365 | Provider holds the keys and can read content; US jurisdiction | Proton Mail (CH), Tuta (DE), Mailbox.org (DE) | |
| Video and meetings | Zoom, Google Meet, Microsoft Teams | No default end-to-end encryption; US jurisdiction and CLOUD Act | Jitsi (self-host), Whereby (NO), Element Call |
| File sharing | Google Drive, Dropbox, OneDrive | Provider-held keys, files readable server-side; US jurisdiction | Proton Drive (CH), Tresorit (CH), Nextcloud (self-host) |
| Notetakers and meeting AI | Otter.ai, Fireflies, Gong, Zoom AI Companion | Cannot be end-to-end encrypted; content processed in the US | Numi, a sovereign meeting assistant (EU processing) |
Messaging
The exposure here is uneven, so precision matters. Telegram's default cloud chats are not end-to-end encrypted: Telegram holds the keys and can access the content, and only its opt-in "secret chats" are encrypted end to end. Facebook Messenger has moved to end-to-end encryption by default, but its owner Meta is a US company. WhatsApp is end-to-end encrypted by default using the Signal protocol, so its message content is out of scanning range, but it collects extensive metadata that feeds Meta's advertising systems and remains under US jurisdiction.
The cleanest upgrade for content and metadata is Signal, which is end-to-end encrypted by default and stores almost no metadata. Be honest about one nuance, though: Signal is run by a US nonprofit foundation, so it is a privacy upgrade rather than an EU-sovereign one. If sovereignty is the goal, Threema is a paid Swiss app that works without a phone number and minimizes metadata, and a self-hosted Matrix/Element deployment keeps both the content and the server under your own control inside the EU.
Standard Gmail and Outlook are encrypted in transit but not end to end. The provider can read your messages, which is exactly the condition that makes voluntary scanning possible, and both are run by US companies reachable under US law. Gmail has historically been among the services that use the voluntary derogation to scan for abuse material.
The alternatives split by jurisdiction. Proton Mail is based in Switzerland, which sits outside the EU and outside the Five Eyes and Fourteen Eyes intelligence-sharing alliances, and offers zero-access encryption so it cannot read your stored mail (note that message subject lines are a known exception). Tuta, based in Germany, encrypts message bodies, subjects, and contacts, though Germany is part of the Fourteen Eyes group. Mailbox.org is another established German option. None of these makes email between you and a Gmail user private, since the other end is still Gmail, but they stop your own provider from being a scanning point.
Video and meetings
Zoom, Google Meet, and Microsoft Teams are the default for most business calls. None is end-to-end encrypted by default; Zoom offers an optional end-to-end mode that disables several features, and all three are operated by US companies subject to the CLOUD Act. For routine internal calls that may be acceptable. For sensitive conversations it is the same jurisdiction problem as email, on live audio and video.
Jitsi Meet is open source and can be self-hosted inside the EU, with optional end-to-end encryption for smaller calls. Whereby is a Norwegian provider operating under EU and EEA data rules. Element Call, built on Matrix, offers end-to-end encrypted calling and can be self-hosted. The trade is the usual one: self-hosting gives you the strongest jurisdiction guarantee and asks the most of your team.
File sharing
Google Drive, Dropbox, and OneDrive hold the encryption keys to your files, which means the files are readable server-side and reachable by the provider, and all three are US-jurisdiction. For documents you would not want scanned or subpoenaed, that is the exposure.
Proton Drive and Tresorit are both Swiss and provide end-to-end encrypted storage, so the provider cannot read your files. Nextcloud is open source and self-hostable, which keeps files on infrastructure you choose and control inside the EU. As with messaging, self-hosting maximizes the jurisdiction guarantee at the cost of running the service yourself.
Notetakers and meeting AI
This is the row where the whole framing shifts, and it is the reason the swap table cannot end at "just use end-to-end encryption." An AI notetaker exists to read your meeting: to transcribe it, summarize it, and in a sales context score it. That is impossible on encrypted data. The content has to be decrypted and processed in cleartext for the model to do anything at all. End-to-end encryption is not a feature these tools are missing; it is structurally unavailable to the category.
So the question changes. For a notetaker you cannot ask "is it end-to-end encrypted," because none of them can be. You have to ask where the audio goes, whose servers transcribe it, which country's law reaches those servers, and which model provider sees the transcript. Otter.ai, Fireflies, Gong, and Zoom's AI Companion process meeting content in the United States, under US jurisdiction, and typically hand the transcript to US model providers. The full breakdown of what that exposes is in our piece on the hidden cost of free AI notetakers.
The alternative is not a more-encrypted notetaker, because that does not exist. It is a sovereign one: a meeting assistant where the audio, the transcript, and the AI processing all stay under EU jurisdiction on infrastructure the vendor can actually point to. That is the design constraint Numi is built around, and it is why meeting AI belongs in a Chat Control tool-swap guide at all.
The catch under Chat Control 2.0: even encryption gets scanned
Everything above works because Chat Control 1.0 only reaches content a provider can read. Switch to genuine end-to-end encryption and your content is out of range. That logic holds under the current regime. It does not survive the proposed one.
Client-side scanning is a technique that inspects the content of a message on your own device before it is encrypted and sent. Because the check happens on the device, a provider can still claim the message was end-to-end encrypted in transit while the content was read first. Security researchers argue this defeats the purpose of encryption entirely and installs a permanent inspection function on every device.
Chat Control 2.0, the permanent CSA Regulation, is where client-side scanning lives as a possibility. Parliament and a blocking minority of member states have kept mandatory scanning out of the text so far, and negotiations are expected to resume around September 2026, so nothing is settled. But the direction is clear enough to plan around. If client-side scanning ever becomes mandatory, the inspection moves to the one place your encryption could not protect: the moment before the message is sealed, on your own device. At that point "switch to an end-to-end encrypted app" stops being a complete answer, because the scan happens before encryption applies.
When that happens, the only remaining question is the one the notetaker row already forced: not "is it encrypted" but "where, and under whose jurisdiction, is my content actually processed." Encryption stops being a wall and becomes one control among several. The durable question, the one that survives whichever way the 2.0 negotiations land, is jurisdiction. Whoever controls the infrastructure and the law that reaches it controls the data, encrypted or not. We develop that argument in the companion piece on why where your conversations get processed now decides everything.
So what should you actually do?
You do not have to rebuild your entire stack this week. Order the work by sensitivity of the content and by how much a switch costs you.
- Move your most sensitive written communication to end-to-end encryption first. Signal for messaging, an encrypted mailbox for email. This is the cheapest, highest-value swap and it protects you under the regime that exists today.
- Prefer EU or Swiss jurisdiction where you have a real choice. Between two encrypted tools, the one outside US legal reach is the safer default, because encryption can be undermined by future law but jurisdiction is harder to move.
- For anything that cannot be encrypted, make jurisdiction the deciding criterion. Meeting AI, analytics, and any service that has to read your content in cleartext fall here. There is no encrypted version to switch to, so choose the vendor whose processing stays under a legal regime you trust.
- Ask every vendor where processing happens and who can compel it. Not where the data is stored, which the CLOUD Act makes close to irrelevant for US companies, but which entity operates the compute and which country's courts reach it.
If you want the wider context on why storage location is the wrong question and jurisdiction is the right one, our guides on what sovereign AI actually means and the US CLOUD Act loophole in EU data centers cover the ground Chat Control makes newly urgent.