soc.octade.net is a Fediverse instance that uses the ActivityPub protocol. In other words, users at this host can communicate with people that use software like Mastodon, Pleroma, Friendica, etc. all around the world.
This server runs the snac software and there is no automatic sign-up process.
The US Congress is considering legislation that cripples privacy and security online, under the guise of seeking a silver bullet that will “keep kids safe.”
Chat Control is back. This Monday, June 29, the EU holds its final negotiation on a regulation that could force messaging apps to scan your private messages before they’re encrypted, no warrant required.
Parliament rejected it by one vote in March. Now it’s being pushed through the back door.
Here’s the thing they can’t legislate around: you can’t scan what never touches a server. Zerion has no server to place a scanner on.
zerion.chat
🚨 The EU's #ChatControl proposal is back.
This isn't just another privacy debate.
The proposal could affect:
🔹 End-to-end encryption
🔹 Private messaging
🔹 Client-side scanning
🔹 Age verification
🔹 Digital privacy across Europe
Supporters say it's about protecting children from CSAM. Critics argue it could create a precedent for scanning everyone's private communications before they're encrypted.
I spent hours researching the legislation, the timeline, the technical implications, and what actually happens next.
📖 Read the complete guide here:
👉 https://thecybersecguru.com/news/eu-chat-control-2026-guide/
If you care about:
#Privacy #CyberSecurity #Encryption #EU #DigitalRights #InfoSec #Signal #WhatsApp #Technology #GDPR #InfosecCommunity #NetSec #CyberNews #OnlinePrivacy #E2EE
Please share. The more people understand the proposal, the better informed the public discussion will be.
EU Chat Control Is Back – And This Time It Might Actually Pass (Update: It Has Passed)
EU Chat Control is back in its final legislative round on June 29, 2026. This complete guide covers what Chat Control proposes, the full timeline from 2021, why it keeps returning, and what happens if it passes [SENSITIVE CONTENT]
Latest Update: Unfortunately, despite our best efforts, chat control 1.0 has passed with a few amendments.
Update: Parliament’s second vote is done. These two changes got approved:
Amendment 30 (Renew Europe)
Purpose: Protect end-to-end encrypted communications.
What it proposes:
Adds a new Article 1(2a) stating that the regulation does not apply to interpersonal communications protected by end-to-end encryption (E2EE), whether encryption is already in place or will be applied.
The stated justification is simply: “Protection of end-to-end encrypted communications.”
In short: This amendment creates a blanket exemption for E2EE communications from the scope of the regulation.
Amendment 26 (PfE Group)
Purpose: Narrow the scope of scanning and protect encrypted communications.
What it proposes:
Removes the requirement to detect child solicitation (grooming), limiting processing to the detection of known CSAM only.
Removes permission to process related traffic data, restricting processing to only the content data strictly necessary.
Adds a new condition stating the regulation must not apply to interpersonal communications protected by end-to-end encryption, whether encryption is already in use or will be applied.
In short: This amendment significantly limits what providers can scan and explicitly exempts end-to-end encrypted communications from the regulation.
Key difference
Amendment 30 is focused solely on excluding E2EE communications from the regulation.
Amendment 26 goes further by reducing the scope of scanning (known CSAM only, no grooming detection, no related traffic data) and also excluding E2EE communications.
Update: The expedited procedure has been approved, and a subsequent vote on Chat Control 1.0 is scheduled for this Thursday.
The vote tallies were as follows:
For: 331
Against: 304
Abstentions: 11
Update: The vote for allowing the new vote for Chat Control 1.0 will be on Tuesday at noon
Update: The European Commission is expected to announce plans in September to ban children from using social media across the EU.
Update: Next week, when many MPs are already on vacation, Chat Control 1.0 mass scans are supposed to be secretly passed again via a third vote!
Update: There are some reports that after carrying long discussions about this, they have reached an initial decision with some compromises. Final decision expected to be made public soon after more discussions. Also, The debate would now be shifting toward mandatory age verification (ID or facial scan) on messaging apps. As of now, no concrete final decision have been reached. The fight continues
The EU is, as of right now, in the final hours before a vote that could permanently change the way private digital communication works in Europe. Monday, June 29, is the fifth and supposedly final round of trilogue negotiations on Chat Control 2.0 – the permanent regulation that would, in one form or another, give authorities the ability to monitor the private messages of 450 million EU citizens.
And if that weren’t enough: this Friday (June 27), a separate backroom deal is reportedly underway to revive Chat Control 1.0 – the expired voluntary scanning regime through the backdoor.
📬 Stay Ahead of Cyber Threats
Get the latest cybersecurity news, critical vulnerabilities, threat intelligence, tutorials, and exclusive giveaways delivered straight to your inbox. No spam. Unsubscribe anytime.
Subscribe to the Newsletter →Two simultaneous attacks on the same target. If either succeeds, the version of the internet Europeans have used for the past two decades – one where a private message is actually private could be gone by July.
This guide covers everything: what Chat Control is, what it proposes, the full legislative history, why it keeps dying and coming back, what’s at stake in the final trilogue, and what you can do. Start from the top or jump to the section you need.
What Is Chat Control?
What Is Chat Control?
“Chat Control” is the public nickname for the EU’s proposed Child Sexual Abuse Regulation – CSAR for short, sometimes called CSA Regulation 2022/0155. It was formally proposed by European Commissioner for Home Affairs Ylva Johansson on 11 May 2022. The stated goal is child protection: detect and report child sexual abuse material (CSAM) circulating across digital platforms.
Why is Chat Control so concerning?
Nobody argues with the goal. The fight is entirely about the method.
The Commission’s approach focuses on regulating digital services such as messaging apps, email providers, cloud storage by placing a legal duty on them to use technology to scan users’ communications in order to detect and report illegal activity. That means AI systems reading your messages before they reach the person you sent them to. All of them. Not because anyone suspects you of anything.
Civil society organisations argue the proposal would effectively mandate mass scanning of all private digital communications, undermining end-to-end encryption and violating fundamental rights to privacy and data protection.
The argument is simple: to catch the small fraction of criminals distributing abuse material, you have to build infrastructure that watches everyone.
Chat Control 1.0 vs Chat Control 2.0
It helps to understand that there are technically two separate legislative tracks running at the same time.
EU mass surveillance legislation
Chat Control: two tracks
Two separate legislative tracks running simultaneously — one expired, one heading into its fifth trilogue.
Track 1
Chat Control 1.0 Expired
Voluntary scanning of unencrypted messages only. Temporary derogation to ePrivacy Directive.
Track 2
Chat Control 2.0 CSAR — active
Permanent regulation. Mandatory scanning. Designed to bypass end-to-end encryption.
Timeline — Track 1
2021
Temporary derogation passed
Gmail, Messenger, Skype, Xbox and others voluntarily scan unencrypted messages for CSAM. E2EE content untouched.
2024
Extended by two years
EU adopts a second extension of the voluntary regime, pushing expiry to April 3, 2026.
March 2026
Parliament rejects third extension
European Parliament votes against a further extension. Legal basis for Chat Control 1.0 ends.
April 3, 2026
Chat Control 1.0 legally expires
The derogation lapses. Scanning without a legal basis is no longer authorised.
⚠ Companies continue scanning anyway
Despite the legal expiry, Google, Meta, Microsoft, and Snap have announced they will continue scanning private messages — with no legal basis and no consequences while CSAR negotiations continue.
Google Meta Microsoft Snap
Track 2 — CSAR (Chat Control 2.0)
Child Sexual Abuse Regulation
The permanent replacement — currently being negotiated Negotiating
Scope
All service providers — mandatory, not voluntary
Encryption
Designed to bypass end-to-end encryption
⚖
5th trilogue — June 29, 2026
Four rounds of negotiations have already concluded. The fifth session — this Monday — is where the permanent regulation is being decided.
Key distinction
1.0 — voluntary, expired Platforms could opt in. Only unencrypted messages. Legal basis gone since April 2026.
2.0 — mandatory, pending No opt-out. Targets encrypted messages. Permanent if adopted.
thecybersecguru.com
Chat Control 1.0 is the older, expired system. In 2021, the EU passed a temporary derogation to the ePrivacy Directive called Chat Control 1.0 by critics which allowed email and communication providers to search messages for CSAM. It was not mandatory and did not affect end-to-end encrypted messages.
This derogation let platforms like Gmail, Facebook Messenger, Skype, and Xbox voluntarily scan unencrypted messages. In 2024, the EU adopted an extension of the voluntary Chat Control 1.0 regulation by two years, until April 3, 2026. In March 2026, the European Parliament rejected a second extension.
So Chat Control 1.0 legally expired on April 3, 2026. However, Google, Meta, Microsoft and Snap announced they will continue indiscriminate and warrantless scanning of private messages. Companies can break the law without consequences while the permanent regulation is being negotiated. That alone should concern you.
Chat Control 2.0 (the CSAR) is the permanent replacement. This is what the June 29 trilogue is about. The purpose of CSAR is to make it mandatory for service providers to scan messages for CSAM and to bypass end-to-end encryption.
This is the regulation that has gone through four rounds of trilogue negotiations and is heading into its fifth on Monday.
The Proposals: What’s on the Table
The Original 2022 Commission Proposal
The first version of Chat Control 2.0 was aggressive. The Commission’s original proposal contains a requirement that platforms, once served with a detection order, must scan people’s messages not just for known CSAM (images identified previously and hashed for detection) but also for unknown CSAM (new images of abuse).
A further component in the Commission’s proposal requires platforms to identify grooming activity in real time. This means apps would need to be able to parse the contents of users’ communications to understand when an adult user might be trying to lure a minor to engage in sexual activity.
That last part – text-based behavior analysis in real time means the AI isn’t just checking images against a database. It’s reading conversations and deciding whether they look suspicious.
How the Technology Works (Client-Side Scanning)
How Client-Side Scanning Works
With client-side scanning, end-to-end encryption remains in place, but it’s fundamentally circumvented: to detect CSAM, content must be checked on the sender’s device before encryption. Detection software would be embedded in the messaging app or operating system to scan chat content and automatically forward any material flagged as prohibited to law enforcement agencies.
It turns the user’s phone into a checkpoint, running pattern matching or machine learning classification locally and triggering reporting workflows when something looks suspicious.
The key thing to understand here: when privacy advocates say Chat Control “breaks encryption,” this is what they mean. End-to-end encryption is not cracked, it’s bypassed. The inspection happens before the message is encrypted. The lock is still on the door; they just check your bag before you put anything in it.
Cryptographers and security researchers warned that on-device detection “inherently undermines the protections” of end-to-end encryption without any guarantee that it would improve protection for children. The detection mechanism would become a high-value target for hackers and hostile nation states, which could reconfigure it to target other types of data, such as people’s financial or political interests.
The “Voluntary” Shift in the Council’s Position
After years of rejections, the Council text softened – at least on paper. The latest Council position drops the requirement for compulsory automated scanning of encrypted or unencrypted communications.
The Council agreed on its position, which removed the requirement that forces providers to scan messages on their services. It also comes with strong language to protect encryption.
So why are privacy advocates still furious? Because “voluntary” doesn’t mean what it sounds like.
Critics have argued that this amounts to mandatory scanning with extra steps. MEP Patrick Breyer has characterized the Council position as “cementing ‘voluntary’ mass scanning” and “legitimizing the warrantless, error-prone mass surveillance of millions of Europeans.”
The mechanism works through Article 4 risk mitigation requirements. Providers classified as “high-risk” for CSAM must implement unspecified “risk mitigation measures.” Scanning is one option on the list. The law doesn’t mandate scanning directly. Instead, it mandates risk mitigation, then includes scanning as the obvious compliance path, then makes non-compliant services legally liable. Patrick Breyer argues the framework could leave privacy-preserving services with little practical choice: “The proposal includes overly heavy and complex risk mitigation measures that punish privacy-respecting services, effectively forcing them to implement surveillance tools to avoid liability.”
It’s opt-in surveillance with enough carrots and sticks attached that it functions like opt-out surveillance.
Mandatory Age Verification
Separate from the scanning debate and arguably as damaging, is the age verification requirement.
To identify minors, every citizen would have to prove their age with an ID or a face scan for an email or messenger account. This threatens whistleblowers, journalists, and people seeking help.
The current text of Chat Control 2.0 has dropped mandatory client-side scanning of end-to-end encrypted messages, but retains a requirement that users verify their age before accessing encrypted messaging services. Anonymous encrypted communication, under that framework, ends. The encryption “survives,” but the anonymity doesn’t.
Think about what this means for a moment. Dissidents in EU member states. Domestic abuse survivors. Journalists with sources. LGBTQ+ teenagers in unsupportive households. Anonymous whistleblowers. Every one of them currently relies on the ability to communicate privately and without identifying themselves. Journalists, whistle-blowers, LGBTQ+ youth, and political dissidents may face new barriers to secure communication if anonymous accounts are no longer possible.
And there’s a basic technical problem: over 400 scientists have warned that “age assessment cannot be performed in a privacy-preserving way with current technology due to reliance on biometric, behavioural or contextual information. In fact, it incentivises children’s data collection and exploitation.”
You cannot verify age without collecting invasive data about everyone who tries to communicate.
Cloud Storage and Other Provisions
The proposal doesn’t stop at messaging. Other aspects of the proposal include ineffective network blocking, screening of personal cloud storage including private photos, mandatory age verification resulting in the end of anonymous communication, app store censorship, and excluding minors from the digital world.
The planned age control would exclude users under 17 from everyday apps like WhatsApp, Instagram, and online games.
That’s not child protection. That’s children’s digital exclusion.
There’s also a detail that went largely unnoticed: the proposal exempted government and military communications from scanning. States do not want Chat Control for their own communications, but the chats of others should be monitored. The people who designed this system exempted themselves from it.
Why the Technical Experts Say It Won’t Even Work
Let’s set aside the legality and ethics for a moment and just look at whether mass scanning actually catches abusers.
The math is the problem. Even a 99.5% accuracy rate would lead to billions of incorrect identifications daily, overwhelming investigators and wrongly flagging innocent users, according to Callum Voge of the Internet Society.
When you scan billions of messages a day, you’re looking for an extremely rare event. Basic probability means the system will generate far more false positives than true detections. When the actual prevalence of the phenomenon is low, even a 1% false positive rate generates a deluge of incorrect reports that swamp investigators and ruin innocent lives.
High false-positive rates in practice are not theoretical: high false-positive rates up to 80% have been documented in countries like Switzerland.
And the abusers most likely to be caught? The least sophisticated ones, who were already detectable through targeted investigations. Europol’s work on child sexual exploitation focuses on networks, identifiers, and investigative partnerships, not on redesigning every citizen’s device into a sensor. Anyone serious about hiding will just use a different service – one outside EU jurisdiction the moment scanning becomes mandatory.
The Commission claims the scanning would be targeted, but under the proposal, private communications of innocent people would be scanned with unreliable AI filters just in case they’re spreading CSAM.
The UN agrees. Child protection organisations, including the UN’s own Office of the High Commissioner for Human Rights, have warned that mass surveillance fails to prevent abuse and actually makes children less safe by weakening security for everyone and diverting resources from targeted investigations that actually work.
The Full Timeline
This legislation has been fighting to exist since 2021. Here’s the full chronological record.
Legislative record
Chat Control: the full timeline
Every significant event from the 2021 temporary derogation to the fifth and final scheduled trilogue on June 29, 2026.
● Chat Control 1.0 ● Chat Control 2.0 (CSAR) ● Critical moment ● Today / upcoming
2021
July 2021
Temporary derogation passes — Chat Control 1.0 begins
EU passes a temporary derogation to the ePrivacy Directive, allowing platforms to voluntarily scan for CSAM. Google, Meta, and Microsoft opt in immediately. Chat Control 1.0
2022
May 11, 2022
CSAR formally proposed — Chat Control 2.0 begins
The European Commission proposes the Child Sexual Abuse Regulation (CSAR) — a permanent, mandatory scanning framework to replace the temporary derogation. Chat Control 2.0
September 2022
Public consultation closes: 80%+ oppose E2EE scanning
Over 80% of respondents to the public consultation oppose applying scanning to end-to-end encrypted communications. Chat Control 2.0
2023
November 2023
LIBE committee votes to protect encryption
The Parliament’s Civil Liberties Committee (LIBE) votes to remove indiscriminate scanning — allowing only targeted surveillance of specific individuals with reasonable suspicion and judicial authorisation. Parliament’s position explicitly protects encryption. Chat Control 2.0
2024
2024
Multiple Council attempts blocked
Belgium and Spain push different compromise texts — including a version rebranding mandatory scanning as “upload moderation,” which Signal president Meredith Whittaker called “rhetorical games.” Germany, the Netherlands, Poland, and Austria repeatedly block qualified majorities in the Council. Chat Control 2.0
2025
July 2025
Denmark takes presidency, makes CSAR a top priority
Denmark assumes the Council Presidency and immediately signals CSAR is a legislative priority for their term. Chat Control 2.0
September 9, 2025
500+ cryptographers warn measures are technically unfeasible
Over 500 cryptographers and security researchers sign an open letter warning the scanning measures are technically unfeasible and would “completely undermine” privacy and security for all European citizens — creating vulnerabilities exploitable by hackers or hostile states. Critical moment
October 8, 2025
Council vote pulled at last minute — Germany blocks majority
A scheduled Council vote is withdrawn after Germany declares opposition. Without Germany, a qualified majority is unreachable. Chat Control 2.0
October 2025
Denmark backs down — shifts to “voluntary” scanning with backdoor mandate
Denmark drops mandatory scanning but attaches risk mitigation requirements to voluntary scanning — what critics call a backdoor mandate in different packaging. Chat Control 2.0
November 26, 2025
Council adopts general approach — trilogue can begin
The Council adopts the revised Danish text as its general approach at a COREPER II meeting — without debate. With both institutions now holding formal positions, trilogue negotiations with Parliament officially begin. Chat Control 2.0
December 9, 2025
Trilogue 1 — first formal negotiation
First trilogue negotiation on Chat Control 2.0 takes place between Parliament, Council, and Commission. Trilogue 1 of 5
December 19, 2025
Commission proposes extending Chat Control 1.0 to April 2028
The European Commission proposes a further two-year extension of the expired voluntary scanning regime — now targeting April 2028. Chat Control 1.0
2026
February 5, 2026
Parliament rapporteur publishes extension draft mandate
Parliament’s rapporteur publishes a draft mandate for extending Chat Control 1.0, setting out Parliament’s negotiating position. Chat Control 1.0
February 26, 2026
Trilogue 2
Second trilogue negotiation on Chat Control 2.0. Trilogue 2 of 5
March 11, 2026
Parliament passes targeted extension (458–103) — Council rejects it
Parliament votes to extend Chat Control 1.0 only to 2027, with mandatory judicial authorisation and no mass scanning. MEPs vote 458–103 in favour. The Council rejects it — they want mass scanning without judicial oversight. Critical moment
March 26, 2026
Parliament kills Chat Control 1.0 extension — passes by a single vote
Parliament votes to reject any further extension of Chat Control 1.0. The critical Amendment 34 — rejecting automated assessment of unknown photos and texts — passes by a single vote. The extension is dead. Critical moment
April 3, 2026
Chat Control 1.0 legally expires
The derogation lapses. Platforms no longer have a legal basis for mass message scanning in the EU. Google, Meta, Microsoft, and Snap continue scanning anyway — without consequences while CSAR is negotiated. Chat Control 1.0 — expired
April 16, 2026
Trilogue 3
Third trilogue negotiation on Chat Control 2.0. Trilogue 3 of 5
May 11, 2026
Trilogue 4
Fourth trilogue negotiation on Chat Control 2.0. Trilogue 4 of 5
Today — June 27, 2026
Backroom deal reportedly underway to revive Chat Control 1.0
Reports emerge of a deal to revive the expired Chat Control 1.0 voluntary scanning regime through a separate legislative route — bypassing the Parliament vote that killed it. Today
Monday — June 29, 2026
Trilogue 5 — final scheduled negotiation
Cyprus, holding the Council Presidency, has scheduled the fifth and final trilogue on Chat Control 2.0. This is the decisive session. Trilogue 5 of 5 — final
July 2026 (expected)
Formal adoption — binding across all 27 member states
If a deal is reached Monday, formal adoption by Parliament and Council is expected in July. The law would take binding effect across all 27 member states immediately — no national implementation required. Pending outcome
5
Trilogue rounds
5 yrs
In legislation
1 vote
Margin on Amdt. 34
27
States affected
thecybersecguru.com
July 2021 – The EU passes a temporary derogation to the ePrivacy Directive, allowing platforms to voluntarily scan for CSAM. This becomes known as Chat Control 1.0. Google, Meta, and Microsoft opt in immediately.
May 11, 2022 – The European Commission formally proposes the Child Sexual Abuse Regulation (CSAR) – Chat Control 2.0 – to create a permanent, mandatory scanning framework.
September 2022 – Public consultation closes. Over 80% of respondents oppose applying scanning to end-to-end encrypted communications.
November 2023 – The European Parliament’s Civil Liberties Committee (LIBE) votes to remove indiscriminate chat control and allow only targeted surveillance of specific individuals and groups where there is reasonable suspicion, and only with judicial authorisation. Parliament’s position also protects encryption.
2024 – Multiple Council Presidency attempts to pass the proposal fail. Belgium and Spain try different compromise texts, including a version that called mandatory scanning “upload moderation,” which Signal president Meredith Whittaker described as “rhetorical games.” Germany, the Netherlands, Poland, and Austria repeatedly block qualified majorities.
July 2025 – Denmark takes over the Council Presidency and makes CSAR a top priority.
September 9, 2025 – Over 500 cryptographers and security researchers sign an open letter warning the measures are technically unfeasible and would “completely undermine” the privacy and security of all European citizens by creating vulnerabilities that hackers or hostile nations could exploit.
October 8, 2025 – A scheduled Council vote is pulled at the last minute after Germany declares opposition. Without Germany, there’s no qualified majority.
October 2025 – Denmark backs down from mandatory scanning. The proposal shifts toward “voluntary” scanning with risk mitigation requirements attached – the version critics call a backdoor mandate.
November 26, 2025 – The Council adopts its general approach – the revised Danish text – without debate at a COREPER II meeting. With the Council’s position finally agreed, trilogue negotiations with Parliament can officially begin.
December 9, 2025 – First trilogue negotiation on Chat Control 2.0.
December 19, 2025 – The European Commission proposes extending Chat Control 1.0 by another two years, to April 2028.
February 5, 2026 – Parliament’s rapporteur publishes a draft mandate for extending Chat Control 1.0.
February 26, 2026 – Second trilogue negotiation on Chat Control 2.0.
March 11, 2026– The Parliament passes a compromise position on extending Chat Control 1.0: extend it to 2027, but require judicial authorisation and limit scanning to targeted cases – no mass scanning of unencrypted messages. MEPs vote 458-103 in favour. The Council rejects it – they want mass scanning without judicial oversight.
March 26, 2026 – The European Parliament votes to reject any further extensions of Chat Control 1.0. The critical amendment 34, rejecting automated assessment of unknown photos and texts, passes by a single vote. Chat Control 1.0’s extension is dead.
April 3, 2026 – Chat Control 1.0 legally expires. Platforms operating in the EU no longer have a legal basis for mass message scanning. But the permanent replacement (CSAR, Chat Control 2.0) is very much alive.
April 16, 2026 – Third trilogue negotiation on Chat Control 2.0.
May 11, 2026 – Fourth trilogue negotiation on Chat Control 2.0.
June 27, 2026 (today) – A backroom deal is reportedly underway to revive Chat Control 1.0 – the expired voluntary scanning regime – through a separate legislative route.
June 29, 2026 (Monday) -The government of Cyprus, currently holding the Presidency of the Council, has planned the very final negotiations to happen on June 29, 2026. This is the fifth and final scheduled trilogue on Chat Control 2.0.
July 2026 (expected) – If a deal is reached Monday, formal adoption by Parliament and Council is expected in July. The law would take binding effect across all 27 member states without any national implementation required.
The Double-Attack Happening Right Now
Here’s the part that requires attention right now – this weekend.
We face a double-attack on private communication: a backroom deal to revive Chat Control 1.0 this Friday, and on Monday June 29, the final trilogue for permanent mass scanning.
Track one is the Chat Control 2.0 trilogue on Monday – the permanent regulation that’s been in negotiation since December 2025. Four rounds in, they haven’t found a final text. Discussions are reportedly still slow. With discussions already reportedly facing delays, a summer deal seems increasingly at risk.
But track two is the one that caught privacy advocates off guard. Someone is trying to bring Chat Control 1.0 back through a separate legislative manoeuvre – before the Parliament gets another chance to vote on it. The previous plenary vote on March 26 killed the extension by a single vote. A backdoor revival would circumvent that democratic decision entirely.
The Council has explicitly signalled it wants mass scanning without judicial gatekeeping. The Commission has supported the Council’s position throughout. That leaves Parliament as the only institution with any interest in defending privacy and the pressure to reach a deal before the Cypriot Presidency ends is enormous.
The Council’s own Legal Service put it bluntly: in an opinion on June 10, 2026, it stated that the latest “own-initiative” scanning proposal still constitutes generalised scanning of interpersonal communication, and that accessing private communications without reasonable suspicion and prior judicial authorisation is incompatible with Article 7 of the EU Charter of Fundamental Rights.
Their own lawyers told them it won’t survive a court challenge. They’re proceeding anyway.
Why It Keeps Coming Back
If Chat Control has failed so many times, why does it keep returning?
Part of it is institutional persistence. The Commission has invested enormous political capital in this proposal since 2022. The rotating Council Presidencies of Spain, Belgium, Hungary, Denmark, Cyprus each have treated CSAR as a priority file. There’s a bureaucratic logic to closing it.
Part of it is lobbying. A transnational investigation by European media outlets revealed the close involvement of foreign technology and law enforcement lobbyists in the preparation of the original proposal. Commissioner Johansson was also criticised for using micro-targeting techniques to promote its controversial draft proposal, which violated the EU’s data protection and privacy rules.
And part of it is the framing problem. “Child protection” is the stated justification. Anyone who opposes the method gets painted as opposing the goal. That’s a difficult political position, which is why privacy advocates have been careful to frame their opposition around the technical ineffectiveness of the proposal, not just its rights implications.
The honest version of the disagreement is this: supporters believe some capability to detect CSAM online is worth accepting reduced privacy for everyone. Opponents believe mass surveillance of the innocent is categorically wrong, and that targeted investigations with judicial oversight would actually catch more criminals without building a surveillance apparatus that, once constructed, will be used for other purposes.
History has consistently supported the second position. Surveillance infrastructure has never stayed limited to its original stated purpose.
What’s at Stake for Encryption
Meredith Whittaker, president of Signal, has said plainly that Signal would leave Europe before implementing client-side scanning. She made clear this isn’t out of principle alone. Signal can’t keep its security promises if it’s forced to install surveillance mechanisms on users’ devices. Will Cathcart of WhatsApp echoed this, describing it as “the end of end-to-end encryption as we know it.”
If Chat Control becomes law, American technology companies will face an impossible choice. US companies would face conflicting legal obligations they cannot simultaneously satisfy. US users would find their communications subject to systematic European surveillance.
And beyond the companies: once client-side scanning infrastructure exists anywhere, it’s a target. When Apple proposed a related mechanism for photo scanning, the backlash was immediate because security engineers saw the same pattern: once a scanning pipeline exists, it becomes an attractive target for attackers and a tempting lever for governments.
Privacy-rights groups warn that even without explicit mass scanning, the framework could normalize surveillance-by-default if risk-mitigation rules are interpreted broadly.
The long-term concern is precedent. The EU setting this framework gives authoritarian governments cover to do the same and far more aggressively. China, Russia, and others have already cited European data regulation as partial justification for their own internet control regimes. A working CSAM scanning infrastructure in Europe becomes the template.
Where the Institutions Stand
The European Parliament has been the most consistent defender of privacy throughout this process. Their 2023 mandate explicitly rejected indiscriminate scanning, protected encryption, and required judicial warrants before any scanning could take place. The March 2026 vote showed they’ll hold that line – barely, by a single vote on the key amendment.
The EU Council (representing member state governments) wants broad scanning capability. The Council’s position still allows “voluntary” mass scanning, mandatory age verification, and AI analysis of unknown content. 23 of 27 member states currently support the proposal. Only the Czech Republic, Italy, the Netherlands, and Poland oppose.
The European Commission has backed the Council throughout. Four EU Commissioners signed a statement insisting the protection of children, not the protection of perpetrators, must remain the guiding principle. Framing opposition to Chat Control as protecting criminals is a rhetorical move, not an argument.
The Council’s Legal Service issued an opinion on June 10 stating the proposal violates Article 7 of the EU Charter. They said it plainly: without a court order based on reasonable suspicion, you cannot authorise access to private communications. Any deal that ignores this finding will be challenged in the CJEU and will likely lose
What You Can Do
What can you do?
If you’re an EU citizen or resident, what happens Monday is partly within your reach. MEPs are accessible, and the Parliament is the last real firewall here.
Contact your MEPs – The negotiators shaping the final Chat Control 2.0 text are called the Trilogue Shadows. You can find them by country at fightchatcontrol.eu. A short, direct email explaining that you oppose mass scanning and mandatory age verification, and want targeted, judicially authorised alternatives is extremely important to send before Monday.
Contact your country’s Permanent Representation – These are the diplomats representing your government in Brussels. They influence the Council’s negotiating position.
What to ask for:
- No generalised scanning of private communications, voluntary or otherwise
- No mandatory age verification for encrypted services
- Any interception of private messages to require a court order based on specific, reasonable suspicion
- Judicial authority, not private companies or administrative bodies to authorise access to private chats
The alternative that actually works: targeted investigations with proper legal authority, supported by more resources for specialised police units, international cooperation, and addressing illegal content at its source rather than trying to catch it in transit across encrypted channels.
The Bottom Line
Chat Control is not dead. It came close to dying. Chat Control 1.0 expired in April, and Parliament rejected its extension by one vote. That was a genuine win.
But the permanent regulation is now in its final negotiating session Monday. And today, Friday, a separate attempt is apparently underway to bring Chat Control 1.0 back through a procedural workaround, bypassing the Parliament vote that killed it.
The proposal as the Council wants it would give tech companies – including US companies with no particular democratic accountability to European citizens the ability to read your messages before you send them. It would require you to prove who you are before you’re allowed to use encrypted communication. And it would do all this while exempting government communications from the same scrutiny.
The technical experts say it won’t catch the sophisticated abusers it’s supposedly targeting. The EU’s own Legal Service says it violates the EU Charter. The European Parliament has repeatedly rejected its core mechanisms. None of this has stopped the push.
The fight isn’t over. After years of political deadlock, 2026 is the year we will learn how far the EU is willing to go. Monday is when we find out
Track the negotiations live at fightchatcontrol.eu. Follow Patrick Breyer’s comprehensive tracker at patrick-breyer.de for document-level updates. EDRi’s Stop Scanning Me campaign at edri.org has the most detailed legal analysis.
FAQs
What is EU Chat Control?
“Chat Control” is the informal name for the EU’s proposed Child Sexual Abuse Regulation (CSAR), which would require digital communication platforms to scan users’ private messages and files for child sexual abuse material. The stated goal is child protection, but critics argue the method amounts to mass surveillance of all 450 million EU citizens.
What is the difference between Chat Control 1.0 and 2.0?
Chat Control 1.0 was a temporary derogation to the EU’s ePrivacy Directive, active from 2021 to April 3, 2026, which allowed platforms like Gmail and Facebook Messenger to voluntarily scan unencrypted messages. Chat Control 2.0 (the CSAR) is the proposed permanent regulation that would make scanning mandatory and extend it to cover encrypted communications as well.
Does Chat Control break end-to-end encryption?
Not directly but instead it proposes client-side scanning, which checks messages on the sender’s device before they’re encrypted. This effectively bypasses encryption without technically cracking it. Security researchers and over 500 cryptographers have warned this approach “inherently undermines” the protections encryption provides and creates new vulnerabilities that hackers and hostile governments could exploit.
Which EU countries oppose Chat Control?
As of June 2026, the Czech Republic, Italy, the Netherlands, and Poland formally oppose the proposal. 23 other member states support it, meaning there is currently a qualified majority in the Council behind the regulation.
Why did Chat Control 1.0 expire in April 2026?
The European Parliament voted 311-228 on March 26, 2026 to reject a proposed extension of Chat Control 1.0. The key amendment – rejecting automated assessment of unknown photos and texts – passed by a single vote. Without parliamentary approval of an extension, the derogation expired as scheduled on April 3, 2026.
What is trilogue in EU law?
Trilogue is the informal three-way negotiation process between the European Parliament, the Council of the EU (representing member state governments), and the European Commission. It’s used to reconcile different positions between the institutions and reach a final agreed text before formal adoption of EU legislation.
What is mandatory age verification in Chat Control?
The current Council position on Chat Control 2.0 requires providers of encrypted communication services to verify the age of users. In practice, this means every EU citizen would need to submit an ID, biometric data, or equivalent proof before accessing encrypted email or messaging apps. Privacy advocates argue this ends anonymous digital communication in Europe entirely and creates major risks for journalists, whistleblowers, and vulnerable people.
Will Signal leave Europe if Chat Control passes?
Signal has stated publicly it will leave Europe before implementing client-side scanning. WhatsApp’s parent company Meta has also warned it cannot maintain meaningful encryption if forced to insert scanning infrastructure. Both apps have a policy of not compromising their encryption model regardless of legislative pressure.
What happens if Chat Control passes despite legal concerns?
The Council’s own Legal Service warned in June 2026 that the current proposal violates Article 7 of the EU Charter of Fundamental Rights (right to privacy) and would likely be struck down by the EU Court of Justice. If passed, legal challenges from civil society organisations and potentially member state courts would likely follow within months of adoption.
What can I do to oppose Chat Control?
EU citizens and residents can contact their MEPs and their country’s Permanent Representation to the EU before the June 29 trilogue. The campaign site fightchatcontrol.eu provides contact tools and a pre-written message that can be customised. Requests should specifically ask for: no generalised scanning, no mandatory age verification, and judicial authorisation requirements for any access to private communications.
new ArcaneChat channel for you:
Buni - Buni is a dark comic about an optimistic bunny with terrible luck.
Artist: Ryan
Website: https://www.bunicomic.com
here is the invite link 👇
https://i.delta.chat/#EB87F92DC57303205E7F3ACB6DAA06D8FE761414&v=3&x=Y3pDrb-vc-TBru-KS5H0F_25&j=7d-o0B4hvWwxianajAFyvfXm&s=Q0lLQSPxZn495mdZ7G_zoQqM&a=6j2tb0xyz%40arcanechat.me&n=ChannelsBot&b=Buni
#ArcaneChat #DeltaChat #chatmail #buni #comics #comic #meme #decentralization #encryption #privacy #e2ee #autonomy #digitalindependence #europe #european #webcomic #email #channels #channel
We Can Still Stop California’s 3D Printer Surveillance Scheme
https://www.eff.org/deeplinks/2026/06/we-can-still-stop-californias-3d-printer-surveillance-scheme
#tech #technology #news #technews #security #privacy #3dprinting #Surveillance
Citizen Lab confirmed this week that Russian authorities used Cellebrite to extract a detained activist’s phone, then searched it for political contacts to build a prosecution.
This is the exact threat Zerion was built for. Forensic tool detection (Cellebrite, GrayKey, ADB) locks the app instantly. Hidden profiles keep separate identities behind separate passwords. Auto-wipe triggers on failed unlocks.
Encryption isn’t enough when they hold the device.
zerion.chat
Hate “The Algorithm?” #RSS Is One of the Tools You’ve Been Looking For
https://www.eff.org/deeplinks/2026/06/hate-algorithm-rss-one-tools-youve-been-looking
Lawmakers Must Act Now to Prevent Armed #Police Drones
https://www.eff.org/deeplinks/2026/06/lawmakers-must-act-now-prevent-armed-police-drones
Nearly a million passports just exposed on the public internet—and anyone could access them with a simple URL
🔮ArcaneChat Spoilers✨
some say first impressions are important, more when you are trying to convince friends and family to join you in ArcaneChat
that is why the next ArcaneChat version comes with a new revamped welcome screen!
bonus: the logo levitates smoothly, to give it that magic touch ✨
#ArcaneChat #ArcaneChatSpoilers #decentralization #opensource #design #UI #privacy #security #encryption #e2ee #android #anonymous #SoftwareDevelopment #androiddev #europe #european #autonomy #diday
#tyranny #Corruption #surveillance #privacy #california
(LEGALLY PROTECTED FREE SPEECH)
California wants to implement 24/7 surveillance for every 3d printer to scan for 'guns', but the implications on privacy and offline printing are too huge. It will also monopolize 3d printer making, since only the big companies can comply. This is too much, and besides that 3d printing a gun is already illegal.
ACT NOW!!!
https://www.eff.org/deeplinks/2026/06/we-can-still-stop-californias-3d-printer-surveillance-scheme
Thinking of introducing DuckDuckGo AI CLI into my minimalist bashcore CLI distros 🐧
I know, adding cloud AI to a sec-focused distro is controversial. But thanks to DDG's proxy, IP addresses are stripped for maximum privacy.
"That's one small step for a dev, one giant leap for CLI-kind"? 🌕🚀
What do my fellow linux friends think about this big step? Worth it?
#SysAdmin #Privacy #AI #CLI #Bash #Distro #Infosec #DevOps #Linux
Information Security and Privacy Quick Reference: The Essential Handbook for Every CISO, CSO, and Chief Privacy Officer by Mike Chapple et al, 2025
A fast, accurate, and up-to-date desk reference for information security and privacy practitioners everywhere Information security and privacy roles demand up-to-date knowledge coming from a seemingly countless number of sources.
The “nothing to hide” argument—that you shouldn’t fear surveillance unless you’re hiding wrongdoing—is a fallacy. Privacy protects everyday life from misuse, errors, and abuse. #Privacy #Surveillance https://en.wikipedia.org/wiki/Nothing_to_hide_argument 🤔🛡️
🔐 #Privacy news & updates from @privacyguides:
“🚨 This Week In Privacy #59 will be live in 30 minutes, it's a quiet news week, so we'll be taking questions from the community and covering the latest privacy & security news. Join us live and chat with the community! ...”
https://mastodon.neat.computer/@privacyguides/116818313296620312
🤖 via RSS feed. May not reflect our views.
Data brokers re-list you after removal. We send a new guide every Friday. #databrokers #privacy #indigoprivacy
new ArcaneChat channel for you:
Leftist Gamer Memes: Crafting memes, comrade. ☭ content provided by https://leftistgamermemes.com
here is the invite link!
https://i.delta.chat/#EB87F92DC57303205E7F3ACB6DAA06D8FE761414&v=3&x=-FVyUanRixV_lqFCSrh9ZLmA&j=QY9vRTOyE_A3M7lwOJKO8UBi&s=NmIRaJZpEoPTwepRda5VYAg8&a=6j2tb0xyz%40arcanechat.me&n=ChannelsBot&b=Leftist+Gamer+Memes
#communism #transRights #trans #gay #LGBT #LGBTQ #leftist #leftwing #communist #games #gamer #artist #workersRights #workers #ArcaneChat #decentralization #security #privacy #encryption #european #europe #openSource #autonomy #anonymous #DeltaChat #meme #memes #capitalism #politics
On the Fediverse, it is common to come across discourse on the critical importance of “privacy” for “democracy” and for “human rights”. How the liberal notion of privacy arose is rarely, if ever, interrogated. The liberal advocates of privacy do not even register the dialectic of privacy and surveillance in a capitalist system.
Given this context, I think the following passages from the second edition of Christian Fuchs’s book, “Social Media: A Critical Introduction”, are worth sharing.
From page 187:
The problem of secret bank accounts/transactions and the intransparency of richness and company profits is not only that financial privacy can support tax evasion, black money and money laundering, but also that it hides wealth gaps. Financial privacy reflects the classical liberal account of privacy. So, for example, John Stuart Mill formulated a right of the propertied class to economic privacy as “the owner’s privacy against invasion” (Mill 1965, 232). Economic privacy (the right to keep information about income, profits or bank transactions secret) protects the rich, companies and the wealthy. The anonymity of wealth, high incomes and profits makes income and wealth gaps between the rich and the poor invisible and thereby ideologically helps legitimizing and upholding these gaps. It can therefore be considered an ideological mechanism that helps to reproduce and deepen inequality.
From page 189:
Capitalism is grounded in the idea that the private sphere should be separated from the public sphere and should not be accessible by the public, and that therefore autonomy and anonymity of the individual are needed in the private sphere. The rise of the idea of privacy in modern society is connected to the rise of the central ideal of the freedom of private ownership. Private ownership is the idea that humans have the right to as much wealth as they want, as long as it is inherited or acquired through individual achievements. There is an antagonism between private ownership and social equity in modern society. Many contemporary societies treat how much and what exactly a person owns as an aspect of privacy. Keeping ownership structures secret is a precautionary measure against the public questioning of or the political and individual attack against private ownership.
Capitalism requires anonymity and privacy in order to function. But full privacy is also not possible in modern society because strangers enter social relations that require trust or enable exchange. Building trust requires knowing certain data about other persons, especially in capitalist market relations. It is therefore checked with the help of surveillance procedures whether or not a stranger can be trusted. This means that companies try to find out as much as possible about job applicants, workers, consumers and competitors and that various forms of monitoring and espionage are common means for doing so. Corporations have the aim of accumulating ever more capital. That is why they have an interest in knowing as much as possible about their workers (in order to control them) and the interests, tastes and behaviours of their customers. This results in the surveillance of workers/employees and consumers.
The ideals of modernity (such as the freedom of ownership) also produce phenomena such as income and wealth inequality, poverty, unemployment, precarious living and working conditions, crime and so on. The establishment of trust, socio-economic differences and corporate interests are three qualities of modernity that necessitate surveillance. Therefore, on the one hand modernity advances the ideal of a right to privacy, but on the other hand it must continuously advance surveillance that threatens to undermine privacy rights. An antagonism between privacy ideals and surveillance is therefore constitutive of capitalism.
We Can Still Stop California's 3D Printer Surveillance Scheme
https://www.eff.org/deeplinks/2026/06/we-can-still-stop-californias-3d-printer-surveillance-scheme
#HackerNews #3Dprinting #Surveillance #California #Privacy #TechForGood #EFF
#Polymarket says hackers stole users’ funds
https://techcrunch.com/2026/06/25/polymarket-says-hackers-stole-users-funds/
TikTok collects keystroke patterns, clipboard contents, and device identifiers beyond what most users realize when they agree to its terms. #privacy #tiktok #tracking #surveillance #indigoprivacy
The #FCC’s #Spam Call Proposal Is Just a Data Collection Scheme
https://www.eff.org/deeplinks/2026/06/fccs-spam-call-proposal-just-data-collection-scheme
Hacked #Klue says criminals are deleting stolen customer data, but now other hackers are making threats
Are Your Local #Police Using #Flock Safety ALPRs to Scan for Immigrants?
https://www.eff.org/deeplinks/2026/06/are-your-local-police-using-flock-safety-alprs-scan-immigrants
It’s interesting how many people think wanting privacy means you’re doing something nefarious. The fact is, privacy is about sharing what you want with whom you choose.
(I don’t recall who wrote the words I used in the graphic here or where I originally saw them. I just made it from my paraphrased version.)
🔊 Anita Nickerson of Fair Vote Canada on voter #privacy: “It is common sense that there shouldn't be privacy rules that apply to almost every organization in Canada, and no rules for political parties": https://action.voterprivacy.ca/page/194272/action/1
Help change that and sign Petition e-7237 by July 4! #cdnpoli
California’s attack on 3D printing is heading to the Senate. Here’s how it has changed, and why we still oppose it. https://www.eff.org/deeplinks/2026/06/we-can-still-stop-californias-3d-printer-surveillance-scheme #privacy #opensource #3dprinting
Finally, I'm really excited to mention that I've been invited to speak at a small hacker conference in Las Vegas later this summer.
I don't want to say too much so I'll leave it there. But I wanted to let folks know that your support on the above issues directly helps me to continue to do some really cool cybersecurity work.
If you'd like to help me get to Vegas and make more cybersecurity content happen be sure to follow me on Ko-Fi.
#Cellebrite said it cut off #Russia, but Russia used its tools anyway
https://techcrunch.com/2026/06/25/cellebrite-said-it-cut-off-russia-but-russia-used-is-tools-anyway/
Radaris pulls together addresses, phone numbers, relatives, social profiles, and photos into one searchable record. Today's guide walks you through the free opt-out process step by step. #privacy #databrokers #optout #radaris #indigoprivacy
The #KIDSAct Would Require Age Checks To Get Online
https://www.eff.org/deeplinks/2026/06/kids-act-would-require-age-checks-get-online
OpenWrt is a free and open-source Linux operating system for supported routers and embedded devices.
Unlike stock router firmware, it provides a fully writable system with package management, letting you install WireGuard, AdGuard Home, VPNs, mesh networking, custom firewalls, and hundreds of additional packages.
https://digitalescapetools.com/tools/tool.html?id=openwrt
#OpenSource #OpenWrt #Linux #SelfHosting #Privacy #Networking #Router #FOSS
🚨 They are bringing back #ChatControl 🚨
Metsola doesn't understand that no means no.
Discussion is scheduled for Monday, so act now: https://fightchatcontrol.eu/
Start with the free audit, then remove your listings. Everything we publish is free. #privacy #databrokers #indigoprivacy
"Today (Wednesday 24 June) the European Commission announced a new reform proposal for Europol – the EU’s policing agency – expanding Europol’s operational powers and weakening key data protection safeguards to the tune of €3 billion.
This is the 3rd Europol reform in six years changing Europol’s mandate to increase its powers and budget. This puts the European Commission increasingly at odds with the boundaries set in the EU treaties, which provide only for Europol to remain in a supportive role to Member States’ police authorities and competent solely for serious forms of criminality.
The Commission’s proposal claims that “interference with the rights to privacy and protection of personal data… remains both necessary and proportionate,” however under the proposed changes, anyone could have their personal data stored and processed by this obscure EU police cooperation agency.
Despite acknowledging the most recent Europol reform in 2022 already massively expanded the agency’s mandate, the proposal charges ahead with significant deregulatory measures to further weaken data protection laws and expand operational powers:"
https://protectnotsurveil.eu/resources/press-release-europol-mandate-overhault-2026/
#EU #PoliceState #Europol #Surveillance #Privacy #FundamentalRights
The 'papers, please' era of the internet will decimate your privacy
https://expression.fire.org/p/the-papers-please-era-of-the-internet
#HackerNews #privacy #internet #security #surveillance #digitalrights
FinFisher and Hacking Team commercial spyware sold to governments have been used to surveil civil society organizations in over 30 countries. #privacy #surveillance #indigoprivacy
Synthetic voice AI has been used in phone scams to impersonate relatives claiming to be in distress and request emergency wire transfers. #privacy #AIethics #indigoprivacy
woah!! it is hot... just like this new ArcaneChat channel:
Twonks: a funny, offbeat webcomic series combining rude and twisted humor with a cast of cute but ultimately stupid characters.
you can join via this invite link:
https://i.delta.chat/#EB87F92DC57303205E7F3ACB6DAA06D8FE761414&v=3&x=F7hsuSLrI6-oOt2vYtZyHni8&j=ouhN66ogZdpwhHhxtiHYHo7N&s=WKRB0o4bjlUWQamUwag9nt9G&a=6j2tb0xyz%40arcanechat.me&n=ChannelsBot&b=Twonks
#ArcaneChat #DeltaChat #chatmail #twonks #comics #comic #meme #decentralization #encryption #privacy #e2ee #autonomy #digitalindependence #europe #european #webcomic #email
Nope, digital sovereignty isn't just a struggle between the US and Europe. The DC-based big-tech sales organization, formerly known as the US Government, is fighting with all our allies over espionage and privacy.
#digitalsovereignty #privacy
https://eastasiaforum.org/2026/06/25/south-korea-juggles-digital-sovereignty-and-alliance-politics/
🧐 Headlines in #privacy from @thenewoil
“Healthtech firm # Xolis suffers # DataBreach impacting 1.4 million people https://www. bleepingcomputer.com/news/secu rity/healthtech-firm-xolis-suffers-data-breach-impacting-14-million-people/ # privacy ...”
https://mastodon.thenewoil.org/@thenewoil/116806385799585445
🤖 via RSS feed. Not an endorsement.
"...The Federal Communications Commission wants to require telecommunications providers to collect vast amounts of personal information from every person who wants a phone number in the name of combatting scam and spam calls. ..."
https://www.eff.org/deeplinks/2026/06/fccs-spam-call-proposal-just-data-collection-scheme
Collateral Damage: #Claude #Mythos and the #Privacy Risks of #AI
https://privacyinternational.org/long-read/5792/collateral-damage-claude-mythos-and-privacy-risks-ai
The #Trump Administration’s New #Census Data Rules Are a Policy Disaster
https://www.404media.co/census-data-privacy-trump-policy-change-noise-infusion/