EU temporarily extends controversial chat-scanning regime until 2028
The only good thing is that end-to-end encrypted messaging services such as Signal are temporarily safe. However, this law fundamentally threatens encryption and citizen safety. There is something you can do about that:
https://www.euronews.com/my-europe/2026/07/23/eu-temporarily-extends-controversial-chat-scanning-regime-until-2028Open linkView original on lemmy.world
25 replies
This is Chat Control 1.0, the "temporary", voluntary scanning of unencrypted stuff.
They are actively working on Chat Control 2.0, the permanent, mandatory scanning of everything including encrypted stuff.
Read more about the differences here: https://fightchatcontrol.eu/chat-control-overview
2.0 keeps getting shot down by the EP, but some member states keep bringing it back. It's really annoying and fucked up.
My wonderful Denmark is heading the charge, we're not even a full member of the EU, but we love to be pioneering anything sketchy
Not sure how Denmark is not a full member of the EU - having opt-outs doesn't change your membership status.
That said, the timing of Denmark chairing the Council of the EU last year couldn't have been much worse (not unlike Ireland while there's a lot happening in digital sovereignty currently).
Chat Control 2.0 specifically protects e2e encryption. It's not about scanning of encrypted messages in any way. It's mostly about age verification. Where do people take this false info from and why they keep spreading it? Is it on purpose or are people simply confused?
CC 2 does NOT specifically protect e2e encryption because it hasn't passed yet, and in order to achieve the articulated primary aims it cannot protect it. Supposedly protecting it is one of the variants that has been tabled to try and get it through (and that proposal has truck sized holes in it).
As per the link above
"Does it touch encrypted messages? Potentially yes — inclusion of end-to-end encrypted messengers remains contentious between Parliament and the Council. "
Timeline June 2026 "Chat Control 2.0 “Final” trilogue fails
The fifth trilogue, billed as the last with adoption targeted for July, produces no deal. Negotiators cannot agree on making suspicionless scanning permanent, as requested by Council. Progress is reported on excluding mandatory age verification, but agreement is postponed and talks continue under the incoming Irish presidency. "
Suspicionless scanning REQUIRES a bypass to e2e - you can't routinely scan all messages if they are encrypted.
It is not a coincidence that IT security and tech literate people are the ones fighting the hardest on this -we understand what this breaks
https://8bitsecurity.com/posts/chat-control-2-0-%E2%80%93-how-the-european-union-wants-to-get-rid-of-privacy-and-what-we-can-do-to-stop-it/
"the proposed technological solution is completely inappropriate and would lead to the establishment of a mass surveillance system that would completely eliminate the privacy of all European citizens.
According to this proposal, every European citizen's online activity should be automatically scanned and categorized by Artificial Intelligence (AI) algorithms."
https://informatecdigital.com/en/chat-control-what-is-it/
"There are two distinct frameworks: 1.0 (voluntary and in place) and 2.0 (proposed with mandates for detection and debate on encryption). Chat Control 2.0 is not approved: the Council must establish a position, and then a trilogue and final vote will follow. Pre-encryption scanning poses technical and legal risks; legal experts warn of incompatibilities with fundamental rights."
https://www.brusselsreport.eu/2025/10/01/chat-control-2-0-the-end-of-our-private-communications/
https://rvntos.io/blog/eu-chat-control-explained/
"This post explains what Chat Control actually proposes, why cryptographers say “client-side scanning” breaks end-to-end encryption even when the encryption technically stays in place, how the political fight unfolded through 2025 and 2026, and where it stands now."
Edit, formatting for readability
Chat control is specifically about scanning chats to see if there's no CSAM. That's mass surveillance (one that child protection services and such don't think'll work).
E2E-protection means nothing when the scanning is done on the client.
That's what Chat Control 1.0 is about and the scanning is voluntary. Here is the text of Chat Control 2.0: https://data.consilium.europa.eu/doc/document/ST-15318-2025-INIT/en/pdf
Can you point me to the part about scanning chats? Because the entire text doesn't even contain the word 'scan'. It barely mentions CSAM or chats. It does say:
So detection is still specifically voluntary and e2e encryption protected. Which part of this document introduces mandatory chat scanning? But please, point me parts of the document, not some vague blog posts. I'm not saying it's not there, just that I read it and didn't find it. If you're claiming it's there I'm sure you will be able to show it.
You're right, it doesn't use the word "scan", it uses "detect". It doesn't say "chat", it says "interpersonal communication". There are 335 mentions of "child sexual abuse", I wouldn't call that "barely mentions". All of it is mentioned in the opening paragraph as background info.
Detection obligations have indeed been removed since the linked document (it wasn't before that, as you can see in that same document, page 3), thanks to the EP, but it still provides the legal framework for companies to do so anyway, without any reasonable suspicion. That's already bad enough.
Moreover, there are mitigation obligations:
Mitigation is very hard to do without identifying it. For that you'll have to detect it in some way, f.e. by scanning chats, which you are allowed to do through this. Scanning might not be the only way (though I can't think of another way), but it is the easiest way.
Authorities can adjust the risk assessment themselves.
Very ironic. The ruling class and elites are excluded.
E2EE protection is nice, but pretty irrelevant. With clientside scanning, the E2EE is not broken, because your device has already decrypted it. It simply negates E2EE
This EU explainer, puts the document in simpler language: https://www.consilium.europa.eu/en/press/press-releases/2025/11/26/child-sexual-abuse-council-reaches-position-on-law-protecting-children-from-online-abuse/
How would a chat company do such a thing without scanning chats?
But, even if all of it was fully voluntary (what chat control 1 more or less is), it's still really bad. Why do we want to give companies the legal right to scan everything we do on their platforms?
I recommend taking a look at Patrick Breyer's site (ex-MEP for the Pirate Party) and the EDRi.
Ok, thanks. So hopefully you will stop spreading misinformation that in introduces mandatory scanning now.
Did you read the rest of my comment?
Voluntary scanning is bad enough, but it still introduces mandatory mitigation, which may as well be the same thing as mandatory scanning in all but name.
That's why people are still up in arms about it.
Nothing more permanent than a temporary solution.
Yeah, I mean, look at "Vigipirate" in France. It's a state of heightened security due to terroristic threats. It was implemented in 2015 after terrorists attacks, safety measure and all that. We're in 2026. It's still there. It simply became a normal thing that people forgot about and now, the heightened surveillance, the "people checking the content of your bags", the alternative entrances to public spaces that are closed to funnel you through a single entrance with a security checkpoint, the military soldiers with assault rifles patrolling the streets... it's just "normal".
We in Europe are masters at it. Isnt that right, Capital of the EU that keeps moving to different countrys?
It's funny in a weird way how this is now voluntarily for companies and the US tech giants have jumped on it while European companies reject it.
There may be a few exceptions either side, but by and large...
We need to fight CC2 in each and every way, and I presume the final battle will be in the courts, but it seems we also have to fight the functioning of Parliament now. While the way this extension passed may have been technically legal it was wholly unethical, void of decency and completely against the spirit of the EU.
Great, I'll temporarily extend XMPP and Matrix, then.