The EU's plan to scan your private messages isn't dead. It's heading for a September showdown
'Chat Control,' the EU push to scan private messages for child-abuse material, comes in two versions. A voluntary one survived a July vote; a far-reaching mandatory one now returns for a decisive autumn negotiation. At its heart is a question with no easy answer: can you scan everyone's messages without breaking the encryption that protects them? Here is the honest state of play.

"Chat Control" is the nickname for an EU push to detect child sexual abuse material (CSAM) in private messages. There are two strands. A temporary, voluntary regime that lets platforms scan non-encrypted services was extended in July 2026 to April 2028, after MEPs fell short of the votes needed to block it. The bigger fight is over a permanent law that could require scanning even of end-to-end-encrypted apps like WhatsApp and Signal, using "client-side scanning" on your device before a message is encrypted. That proposal is expected to return for a decisive round of EU negotiations in autumn 2026. Security experts argue you cannot scan encrypted messages without fundamentally weakening the encryption for everyone. It is a genuine, unresolved collision between protecting children and preserving private communication.
Few tech-policy fights have proven as persistent, or as misunderstood, as the EU's effort to scan private messages for child sexual abuse material. Supporters call it a proportionate way to catch predators; opponents call it "Chat Control" and warn it would end private messaging in Europe. In July 2026 its voluntary version survived an attempt to rein it in, while the far more sweeping mandatory version is now heading toward a decisive autumn negotiation. Because the details are genuinely confusing, and because both the "it's nothing" and "it's the end of privacy" takes are wrong, here is the careful version.
What "Chat Control" actually is
At its core, the EU wants online services to detect and report CSAM. Almost nobody disputes the goal. The fight is entirely about the method, and there are two separate things people lump together under "Chat Control."
- The voluntary regime ("Chat Control 1.0"). A temporary EU rule that permits messaging and email providers to voluntarily scan their services for known CSAM. This applies to services that are not end-to-end encrypted, and it is an exception to the EU's normal privacy protections that has to be periodically renewed.
- The mandatory proposal ("Chat Control 2.0"). A permanent law, still under negotiation, that could go much further and require providers to detect CSAM, potentially including on end-to-end-encrypted platforms. This is the controversial one, and the reason the phrase "Chat Control" sets off alarms.
Keeping those two apart is essential, because the July 2026 news was about the first, while the real stakes lie with the second.
What just happened
In July 2026, the temporary voluntary regime was up for renewal, and a group of members of the European Parliament tried to block or narrow it. They fell short: reporting indicates the move to reject it drew only around 314 votes, short of the 361 needed for an absolute majority, so the voluntary-scanning regime was extended to April 2028. In practice that keeps the status quo: platforms can keep voluntarily scanning non-encrypted services, and encrypted apps remain outside its scope for now.
Crucially, that extension is not the end of the story. It buys time for the far more consequential permanent law, "Chat Control 2.0," which has been deadlocked among EU governments for years and is expected to return for another decisive round of negotiations in the autumn. That is the fight worth watching.
Why encryption is the whole battle
The reason privacy and security experts treat this as an emergency is a technical one, not a political one.
End-to-end encryption means only the sender and recipient can read a message; not the platform, not a government, not an attacker. To scan an encrypted message for banned content, you cannot read it in transit, because by design no one in the middle can. So the only way to check it is to inspect it on the user's own device, before it is encrypted, a technique called client-side scanning. And that, experts argue, is the problem: once you build a system that scans everyone's messages on their own phone and reports matches, you have created exactly the surveillance capability that end-to-end encryption exists to prevent. It can be expanded to new categories of content, abused by a bad actor who compromises it, or turned to new purposes by a future government. As cryptographers have repeatedly put it, you cannot build a backdoor that only the good guys can use.
That is why apps like Signal have said they would rather leave the EU market than comply with mandatory scanning, and why WhatsApp and others have lined up against it. To them, "scan encrypted messages for one purpose" and "keep encryption" are simply incompatible, and no amount of careful wording bridges the gap.
The September showdown
The permanent proposal now heads back into EU negotiations expected around autumn 2026, with reporting pointing to a decisive round as soon as September, under the current Irish presidency of the Council. The exact shape is still moving, and past versions have been softened, re-drafted and stalled repeatedly as governments split over whether to include encrypted services. But the central question returning to the table is the same one that has hung over the whole saga: whether the final law forces detection on encrypted platforms, or carves them out.
Treat the specifics loosely, because this file has a long history of last-minute changes, but treat the direction seriously: this is the closest Europe has come, more than once, to mandating the scanning of private communications, and it is not going away.
Why it matters
Chat Control is the European front of a global fight over whether private, encrypted communication survives the demand to police its contents, and it sits right next to our reporting on the UK's secret order to weaken Apple's iCloud encryption. The two share a logic: a legitimate aim, protecting children or catching criminals, used to justify a capability that, once built, weakens security for everyone. What makes the EU version so consequential is its scale; a mandate across the bloc would set a template the rest of the democratic world would be pressed to follow. None of this makes the goal of stopping CSAM any less urgent. It makes the method the thing to get right, and it is precisely the method that Europe has not yet been able to agree on. For more, see the Privacy section and our look at Apple's fight over UK iCloud encryption.
Chat Control, at a glance
| The goal | Detect and report child sexual abuse material (CSAM) online |
| Voluntary regime ("1.0") | Lets providers scan non-encrypted services; extended to April 2028 in July 2026 |
| Mandatory proposal ("2.0") | Could require detection, potentially on encrypted apps; still under negotiation |
| July 2026 vote | MEPs' move to block the voluntary extension fell short (~314 vs ~361 needed) |
| The core objection | Scanning encrypted messages needs "client-side scanning," which weakens encryption for all |
| Next | Decisive negotiations on the mandatory law expected autumn 2026 (Irish Council presidency) |


