The European Union is grappling with a delicate balance: how to shield children from online sexual abuse without dismantling the privacy protections that underpin digital communication. At the heart of this debate is a set of rules colloquially known as “Chat Control.”
Earlier this month, Members of the European Parliament voted to extend the current regulation, Chat Control 1.0, until April 2028. This measure, in force since 2021, allows online platforms to voluntarily scan private messages and emails for child sexual abuse material (CSAM). Crucially, it does not apply to end-to-end encrypted services such as WhatsApp and Signal, where only the sender and receiver can read the content.
Chat Control operates as an exception to the EU’s e-Privacy Directive, which generally prohibits the interception or monitoring of private communications without user consent. The directive requires explicit permission before any access, surveillance, or use of private digital activity.
The scale of the problem
The rationale behind Chat Control is stark. The European Commission reports a dramatic surge in online child sexual abuse reports: from one million in 2010 to over 23 million in 2025. Those reports contained 61.8 million files, including 29.4 million images and 26.3 million videos. Proponents argue that stronger tools are needed to identify content that would otherwise remain hidden in private channels.
Yet the current voluntary system has limits. Encrypted platforms, which are increasingly popular for private communication, remain outside its scope. This has led the Commission to propose a more ambitious overhaul.
Chat Control 2.0: a more intrusive approach
Negotiations are underway for Chat Control 2.0, which would mandate that all online platforms — including those using end-to-end encryption — scan private conversations for CSAM. This would represent a significant departure from the current framework and has sparked fierce opposition from privacy advocates, tech companies, and some member states.
Scanning encrypted messages would effectively break the security guarantees that encryption provides. Critics argue that this would violate EU laws, including the e-Privacy Directive and the General Data Protection Regulation (GDPR), which set strict limits on processing personal data. The proposal also raises concerns about creating a backdoor that could be exploited by malicious actors or governments.
Co-legislators have not yet reached an agreement on these tougher rules. Negotiations are scheduled to resume in September, with the outcome likely to shape the future of digital privacy in Europe.
Broader context: privacy and child protection
The Chat Control debate is part of a wider European conversation about online safety and fundamental rights. France recently became the first EU country to ban social media for under-15s, while Brussels found that TikTok failed to protect minors' privacy from adult users. These moves reflect growing political will to regulate digital platforms, but they also highlight the tension between protection and privacy.
Meanwhile, the EU is also scrutinising the role of AI in spreading disinformation. A recent investigation revealed that AI chatbots unwittingly amplify Russian propaganda from EU-sanctioned outlets, raising questions about the unintended consequences of automated content moderation.
What’s next?
As the EU institutions prepare for the next round of negotiations, the stakes are high. Child safety advocates argue that without mandatory scanning, abusers will continue to exploit encrypted platforms with impunity. Privacy defenders counter that mass surveillance of private communications is a disproportionate response that undermines trust in digital services.
The outcome will not only affect how Europeans communicate online but also set a precedent for how democracies balance security and liberty in the digital age. For now, Chat Control 1.0 remains in place, but the debate over its successor is far from over.


