Three hundred and fourteen members of the European Parliament voted to reject the return of message scanning. Two hundred and seventy-six voted to keep it. Seventeen abstained. The rejection failed.

That is not a typo, and it is not a scandal either; it is second-reading arithmetic. Rejecting a Council position at second reading requires an absolute majority of all 720 MEPs, which is 361 votes, not a majority of those in the room. The motion fell forty-seven short. A separate amendment restricting scanning to individuals identified by a judicial authority also drew more votes for than against, 322 to 255, and also failed for the same reason.

So on 9 July 2026, suspicionless scanning of private messages became legal again across the European Union until April 2028, having been voted down by most of the people who showed up.

There are two laws, and almost nobody separates them

This is why the coverage is a mess, so it is worth being pedantic about it.

Chat Control 1.0 is Regulation (EU) 2021/1232, a temporary derogation from the ePrivacy Directive. It does not require anything. It permits providers to voluntarily scan unencrypted private messages for child sexual abuse material without that scanning being illegal under EU confidentiality rules. It applies to Gmail, Instagram DMs, Discord DMs, Snapchat, Skype, Xbox messaging, and iCloud Mail. It has never applied to end-to-end encrypted services, simply because server-side scanning of E2EE content is not technically possible.

Chat Control 2.0 is the Child Sexual Abuse Regulation, CSAR, proposed by the Commission on 11 May 2022. It is permanent, and in its original form it made detection and reporting a legal obligation enforced through detection orders. It contains three detection routes: hash-matching of known material, AI classification of previously unseen material, and text analysis for grooming patterns. That’s why cryptographers have been unanimous since 2021: detecting grooming on an encrypted messenger requires reading the message before encryption, on the device.

When someone tells you Chat Control passed, or that it is dead, the first question is always which one. In July, headlines announced that Parliament had passed Chat Control. Parliament had failed to block the temporary one. The permanent one was not on the ballot and still is not law.

How 1.0 died and came back in ninety-six days

The sequence deserves recounting because the procedure is the story.

On 25 March 2026, Parliament voted 311 to 228 with 92 abstentions against extending the derogation. The LIBE committee had already rejected it 38 to 28. On 3 April the regulation expired. For the first time since 2021, platforms had no legal basis to scan private messages in the EU.

Google, Meta, Microsoft and Snap kept scanning anyway. By their own statements. No legal basis, no enforcement action, no consequence. I find that the single most under-discussed fact in this entire file: a law lapsed, four of the largest companies on earth announced they would continue the activity the lapsed law had authorized, and nothing happened. Whatever you think of the scanning itself, that is not how a rule of law is supposed to behave.

Then on 2 July the Council revived the textually identical proposal under an urgent procedure. On 7 July Parliament approved treating it as urgent, 331 to 304 with 11 abstentions. On 9 July came the vote described at the top of this piece. EDRi says the President of the Parliament suggested governments ignore Parliament’s position, after which governments pushed MEPs to vote again. Timing a contested file into a period of thinner attendance is a familiar move, and it worked.

One thing did survive: an amendment explicitly excluding end-to-end encrypted services from the derogation’s scope was adopted. That is a real win, and it is worth understanding exactly how much it is worth. It applies to 1.0 only. It creates political pressure on the permanent regulation and no legal precedent binding those negotiators. Anyone reading the encryption carve-out as closure on CSAR has conflated the tracks again.

Where the permanent regulation actually stands

Five trilogue rounds. December 2025, February, April, May, and the supposedly final one on 29 June 2026. None produced agreement. The June round collapsed specifically over suspicionless scanning. A sixth round is expected in September under the Irish presidency, which took the Council chair on 1 July.

The Council’s position, agreed on 26 November 2025 under the Danish presidency and endorsed by COREPER without debate, dropped explicit detection orders mandating the scanning of private communications. Reading that as a retreat would be a mistake. What replaced the mandate is broad risk assessment and mitigation duties on providers, combined with a permanent voluntary detection framework. Platforms must evaluate how their services could be misused and apply measures to reduce those risks.

Think about what that does to a compliance officer. There is no order to scan. There is an open-ended obligation to mitigate risk, enforced by a regulator, with scanning sitting right there as the most legible way to show you mitigated it. Breyer’s framing is that the structure produces mass surveillance without formally mandating it, and on this narrow point he describes the incentive correctly. A duty to mitigate with a menu of one option is a mandate wearing a different hat.

Parliament’s position, adopted in November 2023 and defended since, is the opposite shape: scanning of private communications limited to specific users or groups suspected of links to child sexual abuse, with a court order required, and mandatory implementation once ordered. That is targeted surveillance with judicial authorization, which is what the rest of criminal procedure looks like. The gap between the two positions has not moved in eight months of negotiation.

The numbers everyone should have to read

The Commission published its implementation report on the voluntary regime on 27 November 2025, COM(2025) 740 final. It is the closest thing this debate has to an audit, and it was written by the institution that wants the permanent regulation.

The proportion of globally scanned content confirmed as CSAM: 0.000002735 percent. The share originating in the EU is smaller still. Error rates for AI classifiers detecting unknown material range from 13 to 20 percent, meaning as many as one in five flagged items are not what the system said they were. The report is candid about the underlying trade-off, noting that reducing false positives typically increases false negatives, and that providers tune the balance themselves.

Former Commissioner Ylva Johansson’s own figure: roughly 75 percent of flagged chats, out of around 300,000 reported EU chats a year, are not actionable.

Then the national operational data. German police logged 99,375 wrongly reported private chats and photos of innocent people in 2024, up nine percent year on year. Ireland: 852 of 4,192 automated reports in 2022 involved illegal content. Germany’s BKA reports 48 percent of alerts as not criminally relevant, and around 40 percent of resulting investigations target minors themselves, which is to say the system’s most common enforcement outcome is investigating the children it exists to protect, generally over their own self-generated images. In North Rhine-Westphalia alone, roughly 2,300 investigations against innocent people were opened and closed in 2024 after a wave of hijacked Facebook accounts was used to post illegal material.

And the accuracy claim underpinning the Commission’s confidence in hash matching has a crack in it. PhotoDNA’s creator Hany Farid has put the false-match rate at one in fifty billion, a figure the Commission has leaned on. LinkedIn’s own published help documentation reports a 59 percent false-positive rate for its voluntary PhotoDNA deployment. Both can be true if you are measuring different things, and the fact that nobody has forced a common definition after four years is itself a finding.

In fairness, the counter-evidence exists and should be stated. Meta’s own derogation report for 2024 covers around 1.5 million actioned pieces of media, of which about 1,800 were restored on appeal, an overturn rate of 0.12 percent. That is a very different picture from the German police numbers, and the difference is mostly that Meta is measuring its own review pipeline while the police are measuring what lands on their desks.

The honest split

Here is where I think the debate goes wrong on both sides.

Hash-matching of known material, on infrastructure that is already unencrypted to the provider, is defensible. The target is precisely defined. The test is close to exact for that population. A specialist prosecutor quoted in Vera Wilde’s research framed it as telling services not to process information they already know is illegal, which is about right. Even at 75 percent not-actionable, that is base-rate arithmetic doing what base-rate arithmetic does at the favorable end of a screening problem.

AI classification of unknown material, applied to general communications at population scale, is a different animal entirely, and not because the engineering is sloppy. It is a mathematical consequence of screening for a rare condition with an imperfect test. Run a generous 90 percent true-positive rate against a base rate somewhere around one in ten thousand, and the false alarms swamp the true ones by orders of magnitude. No threshold avoids both failure modes, because tightening one loosens the other. You cannot calibrate your way out of it.

The capacity side makes it worse. ZAC NRW runs roughly thirteen specialist prosecutors against about fourteen thousand cases a year. Scale that to the EU and you do not change the order of magnitude of the bottleneck. Every false positive consumes a search warrant, a cloud data request, and prosecutorial review before innocence is established. The scarce resource in child protection is not detection. It is the human capacity to act on detection, and flooding it is not neutral.

The open letter signed by more than five hundred cryptographers and security researchers across 34 countries puts the same conclusion in colder language: state-of-the-art detectors produce false-positive and false-negative rates that make them unsuitable for large-scale detection at the scale of hundreds of millions of users.

This position annoys everyone. The privacy camp does not want to hear that known-hash matching survives scrutiny. The child-safety camp does not want to hear that the ambitions of the permanent regulation overshoot the evidence. Which is probably why it has no political constituency and keeps losing to arguments that fit on a placard.

The case for the other side, stated properly

The harm is not abstract, and the urgency is not manufactured. NCMEC’s CyberTipline took over 20.5 million reports of suspected online CSAM in 2024. Reports of AI-generated material went from roughly 4,700 in 2023 to about 67,000 in 2024, and past 1.5 million by 2025. That last curve matters technically as well as morally: hash matching is structurally blind to material that has never been seen before, which is precisely the fastest-growing category. A regime built entirely on known-hash matching has a widening hole, and pointing to the error rates of the tools that could fill it is not the same as having an answer.

When the derogation lapsed in April, NCMEC recorded a measurable decline in European referrals. Meta paused voluntary scanning in the EU immediately after the vote. Whatever the false-positive numbers say, some real reports stopped being made during those three months.

More than fifty children’s rights organizations under the ECLAG umbrella have backed the regulation throughout. Their argument is that a voluntary regime is one a company can abandon at any moment for commercial reasons, which is not a foundation for child protection. That is a serious point, and the Meta pause proved it in a week.

I do not think the people pushing this file are acting in bad faith. I think they were handed a technology story that doesn’t do what they were told it does.

The clause that gives the game away

Article 7 of the Danish compromise text exempted the communications of police officers, military personnel, and intelligence agents from scanning. The stated rationale was protecting confidential and classified information.

Take that seriously as an engineering statement, not a gotcha. The people writing the law believe scanning creates a confidentiality risk severe enough that certain categories of communication must be kept out of it. They are right. That is exactly what client-side scanning does: it places an inspection mechanism inside the trusted portion of the pipeline, before encryption, whereby by construction it must be able to read plaintext. Once that mechanism exists on every phone, the questions become who controls the target list, how the list is audited, and what stops it being extended.

Nobody has answered those questions in four years, which is why more than eighty percent of respondents to the Commission’s own public consultation opposed applying this to end-to-end encrypted communications, and why Parliament positioned itself almost unanimously against indiscriminate scanning back in 2023. The history of how hard it has been to keep a mail provider genuinely end-to-end encrypted under legal pressure is worth reading alongside this, and I went through every bug, block and milestone in Proton Mail’s security record last month for exactly that reason.

There is a French echo here too. The article 16 bis fight inside the French Résilience bill, which would bar anyone from requiring providers to deliberately weaken their own encryption, is the same argument at national scale, and it is currently blocking a text that otherwise just transposes the NIS 2 cybersecurity directive and its continent-wide security floor. The same governments arguing in Brussels that scanning is compatible with security are arguing in their own capitals that their own services need protection from it.

What happens next

The Council has until roughly 9 October 2026 to accept or reject Parliament’s E2EE exemption amendment on the temporary regulation. The sixth trilogue on the permanent one is expected in September under the Irish presidency, and Ireland has historically sat with the pro-scanning bloc, so the autumn push is likely to be harder, not softer. Germany’s position remains the hinge, since a blocking minority in Council depends on it.

The strategic dynamic after July is worse than it looks, and this is the part I would flag to anyone tracking the file. Reviving 1.0 until 2028 removed the Council’s deadline. As the derogation neared its end, the Council needed a deal. Now unencrypted-platform scanning runs regardless, so the Council can simply wait out Parliament’s insistence on judicial authorization. Breyer’s version is blunt: the Council will not accept a paradigm shift while it can keep suspicionless scanning at the tech industry’s discretion. Digital rights groups treated the July vote as a defeat mainly for this reason, not for the scanning itself.

The other thread to watch is litigation. The Council’s own legal service has warned that the voluntary approach still amounts to generalized scanning of communications and is incompatible with Article 7 of the Charter absent reasonable suspicion and prior judicial authorization. The EDPB has formally opposed the detection mandate in 2023, 2024 and 2025. A former CJEU judge published an assessment years ago concluding that generalized and indiscriminate CSAM filtering conflicts with the Court’s own case law. MEP Ignazio Marino put the practical version during the July debate: no child is helped by a law that gets annulled in Luxembourg. If 1.0 stands, someone will litigate it, and on the current record I would not bet on the Council.

This is also becoming a pattern rather than an incident. The AI Act went live in August minus the parts that bite, and its liability plumbing was withdrawn while the standards it depends on still do not exist. Brussels keeps shipping frameworks whose hardest mechanisms are deferred, softened, or left to a later text, and then measuring success by adoption rather than by whether the mechanism works.

I am leaving age verification out of this, along with the EU Center that CSAR would create in The Hague. Both are substantial, both got almost no scrutiny while everyone argued about encryption, and mandatory age verification in particular is quietly one of the largest identity-infrastructure decisions Europe is making this decade. It needs its own post.

What I keep coming back to

Not the surveillance argument. The vote.

A clear majority of members present voted to end suspicionless scanning of private messages, and a clear majority voted to require judicial authorization, and both lost on a threshold nobody outside Brussels could name. Then the same institutions spent the summer explaining that Parliament had approved it.

That is not a scandal in the legal sense. Absolute-majority thresholds at second reading exist for good reasons, and everyone knew the rules going in. But it does mean this file has now produced a permanent regulation nobody can agree on, a temporary regulation a majority of voting MEPs opposed, three months during which the largest platforms in the world simply ignored the absence of a legal basis, and a set of accuracy figures published by the Commission that would fail a first-year statistics seminar.

Meanwhile the actual number of European children helped by any of it remains, in the Commission’s own implementation report, unestablished. That report admits there is no demonstrated link between scanning private messages and convictions or children rescued. Four years in, that sentence should be the headline.

Sources

  • Commission proposal COM(2022) 209 final, the Child Sexual Abuse Regulation, EUR-Lex
  • Commission implementation report COM(2025) 740 final, 27 November 2025, EUR-Lex
  • EDRi, CSA Regulation Document Pool and the full negotiating texts
  • Patrick Breyer, running document trail on the CSAM scanner proposal
  • The Register, MEPs fail to prevent Chat Control revival, 9 July 2026
  • Euronews, Why is Chat Control one of the EU’s biggest digital rights fights, 28 July 2026
  • Global Encryption Coalition steering committee statement on the Council position
  • Meta, EU CSAM Derogation Report 2025 (transparency center)
  • EU Perspectives, LIBE rejects message-scanning extension, March 2026
  • Vera Wilde, base-rate analysis of mass CSAM screening
  • Irish Presidency of the Council of the European Union, July to December 2026