







The EU's proposed CSA Regulation—commonly known as "Chat Control"—would require messaging platforms to scan all private communications for illegal content using client-side scanning technology. Critics, including the EFF, the Internet Society, and data protection authorities, argue the law fundamentally undermines end-to-end encryption and poses a serious threat to privacy and free speech.
Given that the UK and Germany seem to regularly arrest people for posting online, more surveillance is bound to collapse any pretense of Freedom in the UE.
The European Union has positioned itself as a global leader in digital rights. GDPR set the gold standard for data privacy. The Digital Markets Act reined in Big Tech. But a proposed regulation quietly working its way through EU institutions could undo much of that progress—and put every private conversation in Europe under surveillance.
How did it pass the EU Parliament? In a scam vote.
The EU Parliament revived the temporary "Chat Control 1.0" through a combination of an urgent procedure and second-reading voting rules that require an absolute majority to block it. The temporary measure (originally Regulation (EU) 2021/1232) had expired in April 2026 after the Parliament rejected an extension in March 2026.

On July 7, 2026, the center-right European People’s Party (EPP) group, with support from Parliament President Roberta Metsola, successfully invoked the urgent procedure (Rule 170 of the European Parliament’s Rules of Procedure). This fast-tracked the file directly to plenary, bypassing normal committee review, and scheduled the vote for the last sitting day before the summer recess (July 9).
On July 9, 2026, in what was treated as a second reading of the Council’s position, the Parliament voted. Because it was at the second-reading stage, rejecting or substantially amending the Council’s text required an absolute majority of all MEPs — 361 out of 720 — rather than a simple majority of those present and voting. Absences and abstentions effectively counted against any rejection effort.
Vote results (on the key rejection motion):
314 MEPs voted to reject the extension.
276 voted against rejection (i.e., to keep/accept it).
Around 17 abstained or did not vote in a way that counted.
314 was a clear majority of those who voted and present, but it fell short of the required 361 absolute majority. As a result, the Council’s position passed by default. Some amendments were adopted, including one explicitly exempting end-to-end encrypted services (e.g., WhatsApp and Signal) from the scanning rules. The amended text now returns to the Council for approval.
Authoritarianism once granted is rarely refuted and reject in the future.
The regulation in question is the Regulation to Prevent and Combat Child Sexual Abuse, formally known as the CSA Regulation and colloquially dubbed "Chat Control." Its stated goal is unambiguous and well-intentioned: to detect and prevent the spread of child sexual abuse material (CSAM) online. But the mechanism it proposes to achieve that goal has alarmed privacy advocates, cybersecurity experts, and civil liberties organizations across the globe.
At the core of the CSA Regulation is a requirement for messaging platforms to scan user communications for CSAM—including text, images, and video. The technology used to do this is called client-side scanning (CSS).
Unlike server-side monitoring, CSS operates on a user's own device, before a message is encrypted and sent. In practice, this means the content of your messages would be analyzed locally—on your phone or laptop—before end-to-end encryption (E2EE) kicks in. The result is a system that scans private messages while technically preserving the encryption wrapper around them.
For many experts, this distinction is largely cosmetic. End-to-end encryption works precisely because no third party—not even the platform—can read the content of communications. CSS creates a backdoor that sits before encryption ever applies, gutting the privacy guarantee that E2EE is supposed to provide.
The European Data Protection Board (EDPB) and the European Data Protection Supervisor (EDPS) addressed this directly in their Joint Opinion 04/2022, concluding that the proposed regulation, as written, would likely constitute "an interference with the fundamental rights to privacy and data protection." That's not a fringe view—it's the assessment of the EU's own independent data protection authorities.
The Electronic Frontier Foundation (EFF) has called Chat Control "one of the most dangerous surveillance proposals in EU history," warning that CSS infrastructure, once built, creates a ready-made tool for broader government surveillance. The Internet Society has similarly warned that undermining encryption for any reason weakens it for everyone.
The risks are not evenly distributed. General users face erosion of privacy, but some groups face acute and immediate danger.
Journalists and whistleblowers rely on encrypted communications to protect sources. A scanning regime that flags content before encryption breaks that protection—potentially exposing sensitive sources to government scrutiny. Activists and human rights workers operating in countries with authoritarian governments often use EU-based platforms as safer alternatives to locally monitored tools. Chat Control would compromise that safety.
The latest compromise proposal in EU Council negotiations has tried to soften some of the backlash. Notably, it includes an exemption for state and government communications from the scanning requirement—a carve-out that critics argue reveals a troubling double standard. The privacy protections being stripped from ordinary citizens apparently remain important enough to preserve for officials.
The stakes become clearer when you consider the response from one of the world's most trusted encrypted messaging apps. Signal has stated explicitly that it would pull its application from the EU market entirely if the CSA Regulation passes in its current form. Signal's president, Meredith Whittaker, has described CSS as "surveillance" and argued there is no way to implement it without fundamentally breaking the security model that makes Signal trustworthy.
That's not a negotiating position—it's a statement about technical reality.
The CSA Regulation has stalled several times in the EU Council, facing pushback from member states including Germany and the Netherlands. But it has not been abandoned. Compromise versions continue to circulate, and the political pressure to be seen as tough on CSAM is real.
The challenge for legislators is to find a way to combat genuine harm without dismantling the digital infrastructure that protects the innocent alongside the guilty. Mass surveillance of private communications is not a proportionate answer—and history offers little comfort that surveillance powers, once granted, stay narrowly applied.
Protecting children online is a legitimate and urgent goal. The question is whether Chat Control actually achieves it—or whether it simply trades one harm for another.
What is Chat Control?
Chat Control is the informal name for the EU's proposed CSA Regulation (Regulation to Prevent and Combat Child Sexual Abuse). It would require online platforms to scan private communications for child sexual abuse material using client-side scanning technology.
How does client-side scanning undermine encryption?
Client-side scanning analyzes message content on a user's device before encryption occurs. This bypasses end-to-end encryption's core protection—that no third party can read message content—making the encryption guarantee effectively meaningless for scanned communications.
Why are journalists and activists especially at risk under the CSA Regulation?
Journalists use encrypted messaging to protect sources. Activists operating under repressive governments depend on private communications for their safety. A scanning regime that intercepts content before encryption exposes both groups to surveillance, regardless of whether that surveillance is the regulation's stated intent.
Has the EU's own data protection authority weighed in on Chat Control?
Yes. The EDPB and EDPS issued Joint Opinion 04/2022, concluding that the regulation as proposed would likely constitute an interference with fundamental rights to privacy and data protection under EU law.
Would Signal still operate in the EU if Chat Control passes?
No. Signal has stated it would withdraw its app from the EU market rather than comply with a law that requires client-side scanning, which Signal's leadership argues is technically incompatible with genuine end-to-end encryption.
Meta description
The EU's CSA Regulation could force encrypted apps to scan your messages. Here's why experts say it threatens free speech, privacy, and encryption itself.

Did You Know...
... if you improve 1/2% each day, then you will be 267% better over one year? Who can compete with that?

