Chat Control, in plain terms

"Chat Control" is the nickname critics gave the EU's CSA Regulation and the interim derogation beside it. Both share one premise: private messages should be checked, by default, before anyone is suspected of anything.

Now in force

Chat Control 1.0

A carve-out from the ePrivacy Directive letting messaging, email and social platforms scan communications for child sexual abuse material. Voluntary for the platform, not optional for you. Expired 3 April 2026, revived in July, now running until 2028.

Being negotiated

Chat Control 2.0

The permanent regulation. Its detection orders would reach into end-to-end encrypted services — scanning on your own device before a message is ever sealed. Talks resume in September. This is the one worth losing sleep over.

Three claims, and why they don't hold

The lines you'll hear defending Chat Control, and the gap in each one.

01
"It doesn't touch encryption."

Client-side scanning inspects the message on your device, before encryption is applied. The pipe stays encrypted; the contents stop being private. A lock isn't a lock if the wall behind it has an inspection hatch.

02
"If you've done nothing wrong, you have nothing to fear."

Automated detection produces false positives at population scale. Journalists, doctors, lawyers, abuse survivors and teenagers all send lawful messages that classifiers misread — each flag is a stranger reading your life.

03
"It's temporary."

Chat Control 1.0 was temporary in 2021. It has been extended, expired, and resurrected through an expedited procedure. Emergency powers rarely retire — they get renewed while nobody is looking.

How the vote happened → Take action