“Chat Control” puts one of Europe’s hardest digital-policy questions front and center: how do you detect child sexual abuse material in private messages without weakening privacy or encryption?
The EU has extended its temporary Chat Control regime until April 3, 2028, allowing some messaging and email services to continue voluntarily scanning for child sexual abuse material.
End-to-end encrypted apps such as WhatsApp and Signal remain exempt, while lawmakers are still negotiating a separate permanent framework that could bring broader scanning obligations and sharper privacy concerns.
Inside the EU’s temporary ‘Chat Control’ rules
The temporary regime has been in place since 2021 as an exception to the EU’s ePrivacy rules. Euronews reported that it allows providers to voluntarily scan private messages and emails to detect suspected child sexual abuse material, or CSAM.
The policy is intended to help identify abusive material that might otherwise go undetected. Euronews cited European Commission figures showing online child sexual abuse reports rising from about 1 million in 2010 to more than 23 million in 2025. Together, those reports covered 61.8 million files, including 29.4 million images and 26.3 million videos.
The extension survived an unusual parliamentary vote. EU Analytics reported that 331 lawmakers opposed the Council position, but 360 votes were required to reject it at second reading.
The Council subsequently adopted the temporary derogation through 2028 while retaining Parliament’s exemption for end-to-end encrypted services.
Euronews separately noted that EU governments confirmed the extension on July 23, after 25 governments voted in favor, 1 voted against, and 1 abstained. The Council accepted the Parliament text without further negotiations after the European Commission gave a favorable opinion on its amendments.
The privacy and encryption stakes
For users of WhatsApp, Signal, and similar services, the immediate effect is limited. Euronews said that end-to-end encrypted services remain outside the temporary scanning regime because of the amendment adopted by Parliament.
The wider concern is whether allowing providers to inspect private communications creates a precedent for broader monitoring. EU Perspectives highlighted that European Digital Rights argued companies covered by the regime could scan messages, emails, and shared images.
EU Perspectives also cited experts who pointed to narrower existing tools. Rand Hammoud of the Center for Democracy & Technology said targeted telecommunications surveillance based on concrete suspicion and judicial authorization remains possible, while known and previously verified CSAM can be identified through hash matching and flagged for human review.
The debate therefore goes beyond whether technology companies should help combat child sexual abuse. The real debate is over how much access detection systems should have to private communications without undermining encryption or Europe’s privacy safeguards.
The fight over ‘Chat Control 2.0’
The proposed permanent Child Sexual Abuse Regulation, sometimes called “Chat Control 2.0,” raises the bigger stakes.
Euronews said that co-legislators are negotiating a permanent framework that could require online platforms, including encrypted services, to scan private digital conversations. Those tougher rules have not yet been agreed, and negotiations were expected to resume in September.
EU Perspectives similarly distinguished the permanent proposal from the temporary derogation. MEP Martin Sonneborn described the temporary system as keeping voluntary scanning alive while saying the permanent regulation would make scanning mandatory. Thomas Lohninger of epicenter.works said negotiations remained ongoing and that their outcome was uncertain.
For users and tech companies in Europe, the difference is more than technical. The temporary regime continues until 2028 with end-to-end encryption carved out. The permanent rules could determine whether that protection survives as the EU tries to balance child safety, confidential communications, and encryption.
More News: The EU’s platform scrutiny is also widening, with ChatGPT and Roblox potentially facing stricter Digital Services Act rules.


