On 9 July, the European Parliament voted on whether to keep Chat Control alive. 314 MEPs voted to bury it. 276 voted to keep it. It is now in force until April 2028.
None of those numbers are typos.
I've been circling this topic for weeks because it makes me tired in a way that's hard to turn into anything useful. But I run my own servers, I've argued here that you should own your infrastructure, and this is the file that decides whether private communication in Europe stays private. So let's walk through it calmly. Mostly calmly. I'll try, at least...
What actually passed
"Chat Control" is two different things wearing one name, and mixing them up is how every discussion about it derails.
Chat Control 1.0 is what just got extended: a derogation, a formal carve-out from the EU's ePrivacy rules, that lets providers voluntarily scan private messages and mail for child sexual abuse material. (A purpose I take seriously, for the record. We'll get back to how it's being used.) In practice "providers" means webmail and messaging services, overwhelmingly the big American ones; Patrick Breyer's rundown names Instagram DMs, Snapchat, Gmail and iCloud mail among them. No warrant or suspicion attached to you personally. The regime is voluntary, excludes audio, and - after the July amendments - explicitly excludes properly end-to-end encrypted services like Signal and WhatsApp. For now.
Chat Control 2.0 is the still-pending CSA Regulation. The original 2022 proposal contemplated mandatory detection orders, and applying those to end-to-end encrypted apps is only possible if you break the encryption or read messages on the device before encryption happens. The permanent text is still being negotiated, and the treatment of encryption is the contested heart of it. (The commissioner who originally championed it once compared this to a police dog sniffing luggage. A metaphor that works right up until you ask what the dog is supposed to smell... bits can be anything, you know...) It hasn't passed. It hasn't died either.
The part where losing counts as winning
Parliament already rejected this extension once, in March. The file was reopened at the end of June, bounced through the Council, and came back for a vote on 9 July, in the last plenary before the summer break.
At that stage of the procedure, rejecting the Council's position takes an absolute majority of all 720 seats: 361 votes. A majority of votes cast doesn't count. Rejection got 314 votes against 276, with 17 abstentions, and more than a hundred MEPs didn't vote at all - which, under an absolute-majority rule, has the same practical effect as voting against rejection. Rejection failed by 47 votes, and the derogation now runs until 3 April 2028.
I want to stay measured here, because "the EU is corrupt" is the lazy version of this post and I don't believe it. Absolute-majority rules of this kind are old and exist for defensible reasons, and I can't prove anyone picked the date with the attendance sheet in mind. So I'll stick to math. In March, Parliament rejected the previous extension 311 to 228. The opposition exists. On 9 July, not enough of it was in the room, and the rule did the rest.
They exempted it from their own privacy law
Here's the part I most want you to take away, because "Chat Control violates GDPR" gets repeated a lot, and it's almost right in a way that's worth being precise about.
Strictly speaking, it doesn't violate GDPR, for roughly the same reason a hole doesn't violate the fence. The precise version goes like this. Once EU confidentiality rules - the ePrivacy Directive - fully applied to messaging services, providers could no longer lawfully run this kind of scanning; GDPR alone was not a sufficient basis for it. So Chat Control 1.0 was written as a derogation: a formal exemption from ePrivacy's confidentiality articles, passed so the scanning could continue. And the regulation's own text says the quiet part. It derogates from the confidentiality rules, it does not itself create a lawful basis under GDPR, and it describes the voluntary scanning as an interference with the fundamental rights of every user of the service. Their words.
Sit with that for a second. Nobody argued that the scanning complies with the confidentiality rules. They wrote an exemption from those rules so that it wouldn't have to comply. Bureaucracy...
The EU's own institutions have been blunt about the mandatory version too. The European Data Protection Supervisor and the EDPB jointly warned it was disproportionate; German civil-rights lawyers call it incompatible with fundamental rights outright. And the Court of Justice wrote, back in Schrems, that generalised access to the content of communications compromises "the essence" of the right to private life. Courts don't reach for the word essence casually. It marks the line past which no safeguard can save a law.
I'm not a lawyer, and I won't pretend to know how Chat Control 2.0 would fare on its inevitable trip to Luxembourg. I'll only observe that when your flagship child-protection law needs a trapdoor cut through your flagship (no sarcasm here) privacy law, one of the two is not what you claim it is.
Apple already ran this experiment
Now the engineering part, which is the part I'm actually qualified to be angry about.
To scan end-to-end encrypted messages you have two options. Option one, break the encryption, which nobody serious pretends is safe. Option two, client-side scanning: ship a classifier on every phone that reads each message before it gets encrypted and reports whatever it dislikes. The premise behind option two is that it "preserves" encryption. It preserves it the way a chaperone preserves a private conversation.
We don't need to speculate about how this goes, because Apple ran the experiment in 2021. NeuralHash: on-device CSAM detection, perceptual hashing, backed by the best-funded security team in consumer tech. Within weeks, researchers had extracted the model and produced collisions - harmless images that fingerprint as flagged ones. Apple paused the rollout, then killed it, and later admitted that scanning infrastructure creates new attack surface and sits one policy change away from scanning for other things. One failed system doesn't mathematically doom every future one; Apple's design isn't the only possible design. Also, 5 years passed since then. So take this as my engineering judgement rather than a proof: if the best-funded security team in consumer tech walked away rather than own the risks, a regulation is not going to conjure a safe version by mandate.
That's the core security problem. A scanner on half a billion devices with a remotely updated watchlist is infrastructure, and what it scans for is a configuration detail. Today, CSAM. Tomorrow, whichever category is urgent that year - maybe music piracy, maybe documents or payments control. The infrastructure is the decision; everything after it is scope.
"But I have nothing to hide"
Every time I write about surveillance, someone shows up with the same two sentences: "I have nothing to hide," and its uglier sibling, "if you're hiding something, it's probably something illegal."
Privacy is a right. Article 7 of the EU Charter of Fundamental Rights: everyone has the right to respect for their private life and communications. The word communications is sitting right there in the text, next to the article that guarantees you a fair trial. Rights don't owe anyone a justification; searches do. That is the entire logic of a warrant: suspicion first, a named person, then the search. Chat control runs it backwards: scan a whole continent first, let a classifier generate the suspicion afterwards.
And of course you hide legal things. You hide your salary from your coworkers and your diagnoses from your boss. You tell your best friend things you'd never tell your mother, and your therapist things you'd never tell your best friend. Choosing who sees what is called having relationships. A scanner in every chat flattens all of it into one audience you never invited.
But here's what worries me most about "nothing to hide": it assumes that you decide what counts as suspicious. You don't. A model does. And your chats look a lot weirder to a model than you think.
The false-positive machine
I'm a developer. When a Unix process makes a copy of itself, that's called a fork. The copy is a child. When the child hangs, you kill it. When the parent dies first, the children become orphans, sometimes zombies, and the system reaps them. Which means my actual work chats contain sentences like "just kill the child manually" and "the parent died, so the orphaned children got reaped." Now put a grooming classifier on that - a model trained to find predators in text, with no idea what a process is - and tell me how confident you feel. Google search once interpreted one of my searches as malicious intent. A few others showed me emergency help lines. I was googling dev problems :)
Gamers have it worse. Half the strategy genre reads like a tribunal transcript out of context. RimWorld players casually discuss selling prisoners and harvesting organs; Crusader Kings players marry off twelve-year-old heirs, because it's the twelfth century and that's the game. A quest walkthrough, a heist plan over voice chat. None of these people are criminals. All of them are one context-blind classifier away from a report with their name on it.
And then there's the category nobody wants to say out loud, so I will, briefly. If you exchange intimate photos with your partner - and a lot of adults do - a scanning regime means a classifier can see them. (Today that's a possibility on services that choose to scan; making it universal is what the 2.0 fight is about.) That's already a violation with no further steps required: a third party in the most private channel you have. Nudity is what these systems are tuned to stop on, and under the current law suspected new material must be confirmed by a human before it's reported - a safeguard on paper that means, in practice, a stranger reviewing pictures meant for exactly one person. The failure mode past that ruins lives: estimating age from a photo is notoriously unreliable, and a wrong guess about an adult puts your private photos in an abuse-report pipeline with your identity attached. If your partner is short, skinny, or simply cursed/blessed with a very youthful face, you may be safer sending photos by actual carrier pigeon.
Here's where I have to mention teenagers, and I want it on record that I resent this law for making that necessary. Arguing against chat control competently meant researching the failure statistics of abuse-reporting pipelines, and I hate that I now know them. The short version, per figures Patrick Breyer has published for years (he campaigns against this file, but the numbers he cites come from police statistics, linked in his write-ups): nearly half the scanner reports reaching German federal police are criminally irrelevant, a large share of the resulting investigations end up targeting minors over their own pictures, and 99% of what Meta reports is previously known, already-catalogued material - which can still have investigative uses, but is a strange flagship result for a system sold as finding new abuse. That's all the space I'm giving it.
The canonical false positive is documented by the New York Times: a father photographed his sick toddler for a telehealth appointment, Google's classifier flagged him, police investigated and cleared him, and Google still never returned his account, phone number included. Scale that pipeline to 450 million people and tell me it's a child-safety system.
The juiciest target in Europe
Follow the data one step further. Scanning means copying. Everything flagged (correctly or, far too often, not) flows into review queues at moderation vendors, then into report databases, then into police systems across borders, where it sits for years. Intimate photos and private conversations, pre-sorted for sensitivity, with identities attached, concentrated in a handful of systems. If you were designing bait for every criminal group and intelligence service on the planet, this is what you would design.
Will it actually get breached? I can't prove the future, so call it an exceptionally valuable target that will be attacked permanently, by professionals. If I were an attacker, I’d lose sleep over this. What I can do is point at the record - pick any week of security news: telecoms, insurers, hospitals, now and then a security agency itself. The on-the-nose case is Salt Typhoon. In 2024, a Chinese state group burrowed into US telecom networks through the lawful-intercept systems built for police wiretaps and camped there for months. The backdoor for the good guys was a front door for someone else, which is what security engineers had been predicting for thirty years, to a chorus of "think of the children." The aftermath was the comic part: US federal agencies responded to the breach by advising citizens to move to end-to-end encrypted messaging. America built the wiretap machine, watched it get robbed, and told everyone to install Signal. Europe watched the same robbery and decided to build a bigger machine.
The paper trail
One more layer, because the story of how the 2.0 proposal got made has receipts of its own - dug up by journalists, a parliamentary committee, the EU's privacy watchdog, and the EU Ombudsman, none of whom can be waved away as paranoid cryptographers.
The 2022 proposal was then-Commissioner Ylva Johansson's file (the police-dog metaphor from earlier is hers 🫠 ). A BIRN investigation titled, fittingly, "Who Benefits?" documented how closely Thorn (a US organisation co-founded by Ashton Kutcher and Demi Moore that develops and sells AI-based CSAM-detection tools) was involved along the way: extensive access to the commissioner's cabinet, over €600,000 spent on EU lobbying in a single year, and a letter from Johansson to Thorn's director celebrating the "journey to this proposal" and thanking the organisation for helping supply its evidence base. An organisation that sells scanning technology helped build the case for a law that would create a continent-sized market for scanning technology. Meanwhile, digital-rights groups and even an established Dutch abuse-reporting organisation said they struggled to get comparable access.
Now the hedges, because they matter. None of this proves bribery. Johansson denied any financial influence, and a European Parliament research briefing later concluded the Commission had formally followed its consultation rules. But Parliament's civil-liberties committee still summoned her over conflict-of-interest allegations. And in February 2025 the European Ombudsman ruled on the other end of the pipe: two Europol officials had moved to Thorn, one straight from working on AI-based CSAM detection, and Europol's failure to manage that "clear risk of a conflict of interest" was formally ruled maladministration.
The doubts even predate the launch. The Commission's own Regulatory Scrutiny Board initially rejected the proposal's impact assessment, questioning whether scanning encrypted communication was feasible at all and whether it could comply with the ban on general monitoring; the assessment was revised and squeaked through with reservations. And minutes obtained by journalists show Europol suggesting early on that other crime areas could benefit from the detection infrastructure, with unfiltered access to the harvested data on its wish list. Earlier I wrote that the infrastructure is the decision and everything after it is scope. I was late. Europol got there while the machinery was still on the drawing board.
Then, when support in the Council wavered, the Commission promoted the proposal with targeted ads on X in the Netherlands and other hesitant countries, ads that used people's political and religious profiles to decide who would see the message. noyb complained, and in December 2024 the EDPS formally found that the Commission had unlawfully processed sensitive political-opinion data, settling for a reprimand only because the campaign had already stopped. Read that again: the executive proposing a mass-scanning law promoted it with illegal political profiling. At this point satire should file for early retirement.
So, the fair summary, hedges attached: the proposal for a law that would legitimise mass scanning was shaped with unusually close input from organisations that develop and sell scanning technology, while some civil-rights and abuse-reporting groups said they struggled to obtain comparable access. It was published over its own reviewers’ initial objections, discussed internally as infrastructure that could serve purposes beyond its stated one, promoted using unlawful political profiling, and followed by an official maladministration finding involving Europol and Thorn. No conspiracy required. Just incentives - all of them on the record.
"BUT" - you will say - "that's logical! Consulting the industry is completely logical and is the right thing to do." Yes... BUT - The problem starts only when "consultation" becomes "the interested vendor helped define both the problem and the required solution."
Imagine you ask a cleaning company how to keep offices clean. Reasonable. Now imagine that the same company supplies the evidence that offices are dangerously dirty, helps shape a law requiring continuous automated cleanliness monitoring, sells the monitoring equipment, and reports more than €600,000 in EU lobbying expenditure that year.
That does not prove corruption. It does create a conflict of incentives visible from the International Space Station without a telescope.
The argument you're not allowed to argue with
Every critic of chat control opens with the same disclaimer: child abuse is real, protecting children matters. Mine is a few sections up, and I meant it. But notice that the disclaimer is mandatory: skip it and you'll be read as defending the people this law claims to hunt. That reflex is the mechanism. For twenty years, nearly every expansion of surveillance has shipped wrapped in terrorism or children, and the wrapper is chosen precisely because it makes the price of opposition your own decency.
So apply the only honest test: does it protect children? This system risks burying investigators in machine noise and repeatedly reports already-catalogued material, while abuse survivors have told Parliament directly that escaping abuse required confidential channels in the first place. Breyer's harshest point is also his most bureaucratic: as long as mass scanning keeps ticking along, nobody has an incentive to fund the targeted, unglamorous police work that actually finds abusers. "Think of the children" is doing the job here that evidence was supposed to do.
The argument's last resort is personal: "do you want this to happen to your child?" No. I also don't want my child assaulted on the way home, hit by a car, or manipulated by an adult they trust. And we haven't answered any of those by pinning an always-on mic and camera to every kid and streaming the feed to an automated reviewer. Imagine how safe they would be! Instead - we teach them, watch over them, build safer streets, and investigate when there is actual cause. What I want for mine is technical literacy, a healthy radar for manipulation, and above everything - a confidential channel through which to ask for help: the kind this proposal keeps trying to place a stranger inside. Child safety is a shared duty. Universal surveillance is not a synonym for it.
What I'm doing about it
Nothing dramatic. Time to move to Signal, I guess; its current exclusion exists at the pleasure of the next vote, and its president has already said they'd leave a market before they'd break encryption. My mail sits with a non-Gmail European provider, and the self-hosting argument I made here two years ago just grew another leg. Chat Control 2.0 is still moving, which means MEPs will vote again, which means writing to your MEPs is, boringly, the actual lever. July's rejection failed by 47 votes.
And once again: I hate that I now know all this.
//Sincerely
Views are personal and do not represent any current or former employer. Apparently this must be said.