European Union governments have formally approved a temporary framework that permits messaging services to voluntarily deploy measures to detect suspected child sexual abuse material (CSAM), extending the regime until 3 April 2028. The decision, confirmed via written procedure on Wednesday, maintains a carve-out for end-to-end encrypted messages that was introduced by the European Parliament earlier this month.
Written procedures are typically reserved for uncontroversial files, allowing member states to register their voting preferences without convening a formal meeting. On Thursday, the measure was confirmed as adopted with 25 governments in favour; only one voted against, while another abstained. The text mirrors the version passed by the European Parliament, including a last-minute amendment that excludes end-to-end encrypted messaging services such as WhatsApp and Signal from its scope.
Privacy Concerns and Political Maneuvering
The temporary measure has drawn sharp criticism from privacy advocates, who have branded it “chat control” and warned of a dangerous precedent for scanning private communications. The European Parliament initially voted against prolonging the measure in March, and it lapsed in April. However, Parliament President Roberta Metsola reintroduced the file at the request of the European People’s Party, leading to a vote earlier this month that extended the regime until 2028.
In a last-minute move, centre-left lawmakers introduced an amendment excluding end-to-end encryption from the scope, a tactic that privacy-minded legislators hoped would prompt member states to reject the text outright. “A clear majority wanted to limit the scope to known CSAM and include targeted measures,” said Birgit Sippel (Germany/Socialists & Democrats), the MEP leading the file, after the Parliament adopted the move. “However, due to procedural constraints requiring a qualified majority for amendments to be adopted, we were only able to highlight the crucial protection of end-to-end encryption.”
Last week, the European Commission delivered a favourable opinion on the parliamentary amendments, enabling member states to adopt the file without further negotiation with MEPs.
Ongoing Negotiations for a Permanent Solution
Even as the temporary regime is extended, EU policymakers continue to negotiate a permanent solution that would introduce binding rules rather than voluntary measures. The current derogation from the bloc’s privacy of electronic communications rules is intended to combat the spread of illegal content while preserving fundamental rights.
Despite the exclusion of end-to-end encrypted messaging services, several MEPs remain critical. “Any scanning of the content of private communications must be limited to specific suspects,” said MEP Ignazio Marino (Greens/EFA/Italy). His group voted to reject the temporary regime’s prolongation outright, joined by radical left and far-right parties to assemble a total of 276 lawmakers against the provisional scheme.
Other political groups split during the vote, signalling internal disagreement. The centre-left Socialists & Democrats were mostly in favour of the extension, but rapporteur Sippel was among the 20 MEPs voting against it. Sceptic lawmakers argue that child protection should not come at the expense of EU citizens’ privacy or by violating the right to secret communications.
As the debate continues, the extension highlights the delicate balance between security and privacy in the digital age. For context, Europe’s interconnected infrastructure often requires harmonised rules, but this issue remains deeply divisive. Meanwhile, other EU policies also reflect the bloc’s struggle to balance humanitarian concerns with security measures.


