Some thoughts on Chat Control 2.0

14 July 2026

What it is, and why it is technically impossible to circumvent

Behind the media label ‘Chat Control’ lie two different measures, and the confusion between the two – fuelled more or less deliberately – is the first ally of those who wish to push the legislation through quietly. Let’s set the record straight: we are not talking here about the temporary exemption extended to July 2026, but about its older sibling, the permanent one. The CSAR (Child Sexual Abuse Regulation, Regulation 2022/0155), known to critics as Chat Control 2.0.

It is a proposal from the European Commission, presented on 11 May 2022 by the then Commissioner for Home Affairs, Ylva Johansson. The stated aim is noble and beyond dispute: to prevent and combat online sexual abuse of children. The method, however, is what has made it one of the most contested proposals in the history of European digital rights.

In its original form, the CSAR requires digital platforms (messaging, email, social media) to detect and report child sexual abuse material through so-called ‘detection orders’: orders by which an authority can compel a service to scan its users’ communications. This applies not only to content that is already known and catalogued, but also to material never seen before and attempts at grooming. Added to this is mandatory age verification for all European users and, according to the Council’s position, the possibility that these orders could also affect end-to-end encrypted services. It is precisely for this reason that the European Parliament had already rejected the proposal in November 2023, openly describing it as ‘mass surveillance’.

Everything revolves around end-to-end encryption, the system that ensures a message is readable only on the sender’s and recipient’s devices: not even the service provider can access it. To analyse content protected in this way, there is only one possible point of intervention: the user’s device, before the message is encrypted. This is known as client-side scanning: a piece of code embedded in the app that reads everything we type a split second before encryption takes place. The political promise that ‘encryption will not be touched’ is therefore a play on words, because there is no need to break it if you read the message whilst it is still in plain text. Technically, this amounts to widespread and permanent interception on every device.

This is not a problem that can be circumvented with a few tweaks, but a structural feature: there is no such thing as client-side scanning that opens a backdoor ‘only for the good guys’. Once created, that backdoor is open to everyone – today’s authorities, tomorrow’s governments with other intentions, and the first attacker capable of exploiting it. This is why Meredith Whittaker, president of Signal, stated as early as 2024 that the app would leave the European market rather than introduce such a mechanism: it is not a negotiating tactic but an engineering precondition. And the backdoor, in the text, remains ajar even when it appears closed: Article 85(1a) of the draft mandates the Commission to periodically assess detection technologies for encrypted services, effectively reserving the right to reintroduce scanning in the future.

To find one, it must monitor them all

This is the crux of the matter that makes the regulation so serious, even before any technical details are considered. To intercept child sexual abuse material circulating amongst a minority of criminals, the system must analyse everyone’s communications. There is no way to ‘look only at the guilty’: an algorithm searching for illegal content must first read, classify and categorise every photo, every message and every file belonging to every user, before deciding whether it is suspicious. The logic of the presumption of innocence is turned on its head. Everyone becomes a potential suspect whose correspondence must be sifted through as a preventive measure, without any evidence or warrant. It is the difference between a targeted search authorised by a judge on a suspect and a permanent, simultaneous search of the pockets of 450 million people.

And since that screening process must be applied to billions of pieces of content every day, the only feasible tool is artificial intelligence: every private communication, in order to be deemed lawful, must first pass through a machine that labels it. Personal data is not merely intercepted; it is profiled. Photos, words, relationships, habits: everything becomes material to be classified by a model, because this is the only way in which universal scanning can be practically viable.

The real harm: being labelled by an algorithm

False positives are the most frequently cited criticism, and remain a real problem: over 500 cryptographers and security researchers from 34 countries have estimated that, with an error rate of just 0.1 per cent on WhatsApp traffic alone, there would be over a million false positives a day. Supporters argue that the models are improving and that the error rate is falling, and this is true. But the point is not how often the algorithm gets it wrong, but what it does when it works.

To decide whether content is permissible, the system must first assign it a label. Every photo, every message, every conversation is analysed, classified and, in effect, judged by a model: suspicious or not, at risk or not, to be reported or not. This means that every citizen is continuously assigned a profile generated by a machine, built on their most intimate content. We are no longer dealing with surveillance aimed at finding a culprit, but with the permanent categorisation of everyone, in which each person is reduced to a series of labels decided by an algorithm that will never be held to account.

And this is where the problems become enormous. Once a wrong label has been applied, it is almost impossible to challenge: the user often does not even know they have been flagged, is unaware of the criteria the model used to make its decision (these are proprietary algorithms, black boxes without independent audits) and has no real way of defending themselves against a suspicion generated by a machine. Furthermore, classification errors do not affect everyone in the same way: the models reflect the biases in the data on which they are trained, and end up penalising certain languages, communities or cultural contexts more frequently. A family photo, a medical report or an intimate exchange between partners can turn into a report to the authorities, with consequences for one’s life and reputation that no subsequent retraction can truly erase. The logic of the presumption of innocence is turned on its head: it is no longer the state that must prove guilt; it is the citizen who must prove they are ‘in the clear’ every time they send a message.

Closing the net even further is a parallel trend moving in the same direction: the end of anonymity as the internet’s default setting. A growing number of websites now require users to prove their identity or age in order to grant access. In Italy, from 12 November 2025 (and from 1 February 2026 for websites based in other EU countries as well), AGCOM Resolution 96/25/CONS will oblige pornographic websites to verify that users are of legal age, with fines of up to 250,000 euros and the possibility of the site being blocked; and the CSAR itself provides for mandatory age verification for all European users. It must be acknowledged that the Italian model is based on the principle of ‘double anonymity’ and requires neither documents nor SPID: the website does not know the user’s identity, and the verifier does not know which website the user is visiting. But the fundamental issue remains: the groundwork is being laid for a network in which, to access content, you must first undergo a check that verifies who you are or how old you are. And once that infrastructure is in place (age verification apps, the European digital identity wallet expected by the end of 2026), transforming ‘prove your age anonymously’ into ‘prove your identity’ becomes a political decision, not a technical constraint. Combined with content scanning, this de-anonymisation completes the picture: a network in which every user is, at the same time, identified and scrutinised.

Added to all this is ‘function creep’: once the infrastructure capable of labelling people based on the content of their communications has been built – however odious and widely supported the initial objective may be – nothing prevents it from being extended tomorrow to other categories, from terrorism to copyright to political dissent. The legal precedent is the real Trojan horse, as highlighted by the European Data Protection Supervisor (joint opinion EDPB–EDPS 4/2022), dozens of NGOs, legal experts and cybersecurity specialists.

Among the clearest voices in the sector is that of Pavel Durov, founder of Telegram, who has announced that the app will not scan private messages and has branded the legislation a ‘banana republic’ ploy. Back in the message he posted on his birthday in October 2025, Durov had issued what he described as a ‘digital call to arms’, warning that governments are transforming the internet from a promise of free exchange into a tool of control, through dystopian measures such as mass surveillance of private messages, digital identities and online age verification. This is the same line of argument used by Signal and WhatsApp when they threatened to leave the European market: not hostility in principle to the fight against abuse, but the conviction that this specific measure is incompatible with the privacy of communications.

The manoeuvre: ‘voluntary’ compliance that is not voluntary

And this is where the method becomes more insidious than the substance. Faced with opposition from the Parliament and criticism from much of civil society, the proposal was not abandoned but rewritten to appear less aggressive. Under the Danish Presidency of the Council, at the end of 2025, the mandatory scanning requirement was removed from the text. On 26 November 2025, the Council approved its position, with only four countries voting against: the Czech Republic, Italy, the Netherlands and Poland.

On paper, scanning becomes voluntary; each provider can choose whether to implement it. In substance, the text retains mandatory risk assessment measures; if a service is classified as ‘high risk’, the authorities can impose corrective measures on it; and from an economic and reputational standpoint, the most prudent choice is to implement the scanning anyway. Although the Council has removed the formal obligation, it has established a system of incentives that pushes everyone in the same direction. It is voluntary in name only: no one is forcing you, but the cost of saying no is designed to be unsustainable.

That this is not a malicious interpretation by critics is confirmed by an unimpeachable source within the institutions. In 2026, the Council’s Legal Service noted on the record that the ‘voluntary’ scanning still constitutes a blanket scanning of communications and is incompatible with Article 7 of the Charter of Fundamental Rights of the EU in the absence of reasonable suspicion and prior judicial authorisation. In other words, the Council’s own legal experts state that the ‘watered-down’ version remains, from a rights perspective, just as unlawful as the original.

This is not an isolated case of overreach. Commissioner Johansson herself had already come under fire for the way in which the proposal had been drafted and promoted: a micro-targeted advertising campaign to sway public opinion in favour of the regulation, which, according to the European Digital Rights (EDRi) association, violated the very rules on privacy and data protection that the regulation claimed to safeguard. This approach alone speaks volumes about the relationship between the bill’s proponents and the principles they claim to uphold.

September, and the response that hasn’t come from Brussels

The CSAR is not yet law. Its adoption depends on trilogues – three-way negotiations between the Parliament, the Council and the Commission. Five such rounds have already failed in succession, the latest on 29 June 2026 under the Cypriot Presidency, because the sticking point remains the same: the scope of surveillance powers and the fate of encryption. The Parliament continues to argue that surveillance must be limited to individuals or groups under reasonable suspicion, and only following a court order; the Council and the Commission are pushing for a broader scope. The next trilogue is scheduled for late September, under the Irish Presidency, and voting will resume from there: it is the final quarter of 2026, not the summer media hype, that represents the real window for decision-making.

To be fair, it must be acknowledged that the proponents put forward a significant argument: according to the Commission, in some EU countries up to 80 per cent of investigations into online abuse stem from reports by service providers. But that result can also be achieved through targeted measures (surveillance of suspects identified with judicial authorisation, enhanced cooperation between Europol and national authorities, and technologies that analyse data without decrypting it) without undermining the privacy of 450 million people. The point is that the political decision in Brussels could go either way, and no one can take the outcome for granted at this stage.

And this is precisely where the most important issue lies for the reader: passively waiting for the vote is not the only option. Much of our vulnerability stems from a choice we ourselves have made, not Brussels: having concentrated our entire private lives on a handful of centralised platforms, almost all of which are in the hands of a few large corporations. WhatsApp, Instagram and Messenger all belong to the same company; when the correspondence of hundreds of millions of people passes through a single point, that point becomes exactly what a surveillance law can compel, or persuade, to scan. A centralised infrastructure is, by definition, a single switch: all it takes is a press of a button.

The practical solution – the one that doesn’t depend on how the Council votes – is to start reducing this dependence. It means switching to tools that aren’t owned by a single giant: applications with end-to-end encryption enabled by default, with open-source code that anyone can inspect (so that no one can secretly insert a client-side scanning mechanism), and ideally built on decentralised or federated networks, where there is no single company to which a surveillance order can be imposed. Signal, the Matrix protocol and its clients, or self-hosted solutions are moving in this direction; the apps of the major social media platforms, by virtue of their architecture and business model, are not. None of these tools is a magic wand, nor do they replace the political struggle: but digital sovereignty, even before it is a demand made of legislators, is a daily habit. The more distributed, open and verifiable people’s communications are, the harder it becomes to turn them, with a single vote or a single order, into an archive to be sifted through.

Because ultimately, the question posed by Chat Control 2.0 is not just about what Europe will decide in September, but how much we are willing to depend on platforms which, the day a law requires it, could read everything for us. In this scenario, privacy is no longer just a right to be defended in the chamber: it is a technical choice we must make every time we open an app.