Politics Business Culture Technology Environment Travel World
Home Politics Feature
Politics · Exclusive

Why Chat Control Has Become the EU's Defining Digital Rights Battle

Why Chat Control Has Become the EU's Defining Digital Rights Battle
Politics · 2026
Photo · Anna Schroeder for European Pulse
By Anna Schroeder Brussels Bureau Chief Jul 28, 2026 5 min read

On 23 July, EU governments confirmed an extension of the bloc's interim "chat control" regime, allowing online platforms to continue voluntarily scanning for child sexual abuse material (CSAM) until 3 April 2028. The measure, approved by written procedure with 25 member states in favour, one against, and one abstention, aligns with the version passed by MEPs on 9 July and notably excludes end-to-end encrypted services such as WhatsApp and Signal.

This decision sets the stage for a far more contentious battle over a permanent, potentially mandatory scanning law—a proposal that has become one of the most polarising digital rights debates in Brussels.

The Commission's proposal and its rationale

The European Commission tabled its regulation on preventing and combating child sexual abuse on 11 May 2022, quickly dubbed "Chat Control 2.0." It would apply EU-wide, regardless of where a company is based, replacing a narrower 2021 temporary law that permits voluntary scanning under a carve-out from ePrivacy rules. The proposal also establishes a new EU Centre on Child Sexual Abuse to coordinate detection technology and forward confirmed cases to Europol and national police.

The Commission's central argument rests on the scale of the problem. A European Parliament briefing reported over 20.5 million suspected CSAM cases in 2024 alone. Europol warns that abuse material is increasingly shared on mainstream platforms as offenders exploit encryption and anonymity. Supporters argue that voluntary reporting is too fragmented to address the issue effectively.

That framing has drawn sharp criticism from digital rights advocates who dismiss child protection as a pretext—an accusation supporters reject outright. "There were parts of the house saying that whenever we speak about protecting children online, it's just a false pretext," said Lena Düpont, MEP with the European People's Party, on the EPP's podcast EU Decoded. "I agree it cannot be the only tool we use to protect children, but it is one of the most important tools we have, particularly for prosecuting the horrible crimes connected to children being molested or abused online. We should never let ourselves be divided over how best to protect our children."

How detection orders would work

Under the permanent proposal, providers would first assess the risk of misuse on their platforms and implement mitigation measures. If a national authority still identifies significant risk, it may request a court or independent body to issue a targeted, time-limited, and proportionate "detection order." Known illegal material would be identified through hashing, while new material and grooming conversations would rely on less reliable AI pattern recognition, with human review included. Compliance could require automated content-recognition systems, new reporting processes, and age verification. For encrypted apps, the most debated requirement is client-side scanning, which inspects content on the device before encryption.

Is 'Chat Control' mass surveillance?

Digital rights groups argue that a "targeted" order effectively becomes mass surveillance once scanning infrastructure is implemented across a platform. The EU's privacy watchdogs warn that the proposal could enable broad, indiscriminate scanning of ordinary communications, conflicting with the EU Charter's privacy protections.

Patrick Breyer, a digital rights activist, jurist, and former MEP with the Greens/European Free Alliance, argues policymakers place far too much faith in the technology's reliability. "They think a hash signature can determine exactly what is legal and what is illegal," he said. "But even though 90 percent of reports are a result of hash scanning and relate to known material, we've received numbers this week from Germany saying that more than 50 percent of these reports are actually not criminally relevant." The reason, he explained, is that inclusion in a database doesn't equal a crime: it may never have been properly assessed against EU criminal law, and databases say nothing about intent.

"Even hash scanning, the least unreliable of these methods, comes with a very high rate of false positives of falsely incriminating people," he said, adding that minors are frequently caught up, since "it's very common among them to share self-generated material with peers, or think something is funny; it's just part of being a teenager."

Critics argue that inspecting messages on a device before encryption undermines true end-to-end encryption. Organisations such as the Electronic Frontier Foundation warn that client-side scanning creates a permanent inspection layer that could be repurposed or expanded, posing risks to journalists, whistleblowers, and prompting services like Signal to leave the market. Hash-matching also requires access to message content, making it difficult to operate on encrypted traffic without shifting the checkpoint to the device.

Breyer argues the debate has skipped over alternatives. "What the European Parliament proposes is targeted investigations in private communications, but also proactive and systematic searching of the open internet and the dark net for known illegal material, and reporting it to providers for removal," he said. "That's been successfully used in the UK and Canada, but so far not in Europe." He also points to security by design: "The apps should warn users before they share personal details such as their phone numbers, because that's a common part of grooming. We want users warned before they send nudity. You can do all that on the device without sharing the encrypted content with the provider."

Breyer stresses that targeted, court-authorised surveillance of a suspect is one thing; scanning everyone by default is another. "It's justified if a person is a suspect, if there's a reasonable suspicion they're involved, and if an independent court confirms it's justified to intercept their communications," he said. "But opening everybody's mail just in case is something unheard of." That distinction, he argues, separates an acceptable law from an unacceptable one.

For a deeper look at the technical and legal arguments, see our earlier analysis of the EU's chat control proposal. The debate also touches on broader questions of digital rights and privacy that affect European citizens across the continent.

More from this story

Next article · Don't miss

Asian chip stocks plunge on AI sustainability fears, European markets brace

South Korea's Kospi index fell more than 10% on Tuesday, triggering a trading halt, as chipmakers Samsung and SK Hynix saw double-digit losses. Analysts point to rising competition from Chinese AI startups and chipmakers, exemplified by CXMT's 466% debut surge

Read the story →
Asian chip stocks plunge on AI sustainability fears, European markets brace