European Union regulation proposal on child pornography detection
| European Union regulation | |
| Text with EEA relevance | |
| Title | Proposal for a Regulation of the European Parliament and of the Council laying down rules to prevent and combat child sexual abuse |
|---|---|
| Made under | Articles 114 and 294 TFEU |
| Preparative texts | |
| Commission proposal | COM(2022) 209 final |
| EESC opinion | EESC 2022/02804 |
| EP opinion | A9-0364/2023 |
| Reports | A9-0364/2023 |
| Pending legislation | |
The Regulation to Prevent and Combat Child Sexual Abuse (Child Sexual Abuse Regulation, or CSAR) is European Union pending legislation to require digital platforms to assess and mitigate the risk of being used to distribute abuse material or solicit children, enable authorities to remove or block illegal material, and establish a center for regional coordination and victim assistance.[1] It is commonly referred to by critics as Chat Control 2.0 or simply Chat Control.[2][3]
The legislation is supported by child advocacy groups[4] and most EU member states.[5] While compromises have been reached on most provisions in EU negotiations,[6] there is no agreement on the scope and safeguards for controversial mandatory detection measures.[7][8] Civil society and privacy activists argue those measures, affecting social media companies and messaging apps,[9][10][11] could undermine privacy and data protection through indiscriminate surveillance.[16]
The EU response to child sexual abuse has historically been divided between a 2011 criminal-law directive implemented unevenly by member states,[17] voluntary action by online platforms, and disjoint law-enforcement and victim-support programs. Reviews of the 2011 directive identified implementation gaps,[18] while the Council and Parliament called in late 2019 for more coordinated EU action.[19]
The COVID-19 pandemic intensified concerns by moving schooling and social contact online, increasing the time spent online by both children and offenders, and reducing the capacity of hotlines and law-enforcement bodies.[20] The Commission incorporated the issue into its 2020 Security Union programme,[21] and adopted its strategy for "a more effective fight against child sexual abuse" on 24 July 2020. The strategy brought prevention, enforcement, victim support and digital platform responsibilities into one programme, and proposed temporary and permanent legislation to harmonize and then extend voluntary platform detection practices.[22]
In October 2022, Article 18 of the Digital Services Act[23] introduced requirements for some businesses to report conduct threatening to life or safety in a manner broadly compatible with CSAR, but explicitly stopped short of requiring proactive detection.[24]
Voluntary detection of abuse material by digital platforms dates back at least to the mid-1990s, when AOL manually reviewed suspected abuse material and later developed automated processes.[25] By 2015, the Internet Watch Foundation distributed a fingerprint database created from confirmed abuse material, including images obtained through its own investigations, public and industry reports, and the UK police Child Abuse Image Database.[26] Facebook, Google, Microsoft, Twitter and Yahoo helped trial and implement the service, comparing fingerprints generated from newly uploaded images against the database.[27]
Use of automated systems is widespread but uneven, with existing systems providing inconsistent coverage and oversight.[28] In 2020, Facebook submitted 20.3 million reports to NCMEC, compared with 546,704 from Google, 144,095 from Snapchat, 96,776 from Microsoft and 265 from Apple.[29] In one 2023 survey, only 20 of 50 platforms issued transparency reports, and only 10 defined prohibited abuse material in sufficient detail, limiting assessment of the effectiveness of platforms' measures.[30][31] Another study concluded substantial differences in the metrics and reporting methods used prevented assessment of effectiveness.[30]
Existing industry practice relies primarily on automated detection technology, of which the most established is perceptual hashing, while some providers use machine learning to detect previously unknown images, and language models to identify grooming.[32]
One of the most widely used perceptual hashing systems is PhotoDNA, developed by Microsoft in 2009.[33][34] A 2023 analysis of PhotoDNA by Ofcom reported a threshold providing resistance to alterations produced a false positive rate of 0.3% under the study's conditions.[35] Published performance for other commercial classifiers and grooming detection systems have generally been unavailable.[36][37]
Of 4,192 reports assessed by Irish police in 2020, 852 were confirmed abuse material while 471 were false positives,[38] illustrating the potential base-rate problem associated with detection at scale.[39] By contrast, a 2025 European Commission review reported that automated detections were "overwhelmingly confirmed" following human review.[40]
The ePrivacy Directive was adopted in 2002 to protect confidentiality of electronic communication, and extended by the Electronic Communications Code to include interpersonal services like instant messaging in measures that were implemented by December 2020.[41] A temporary derogation was proposed in September 2020[42] enabling platforms to avoid contravening the updated rules through their existing detection mechanisms. Legal uncertainty around detection mechanisms in late 2020 had resulted in a 58% fall in EU-linked abuse reports to NCMEC over 18 weeks.[43][44]
The derogation, often referred to by critics as Chat Control 1.0,[43] entered into effect in 2021,[45][46] allowing digital platforms to resume scanning users' electronic communications for abuse material.[47][48] Meta actioned 3.6 million items of abuse material involving an EU user under the derogation during 2023, with appeals filed by users in 7% of cases, leading to 4.6% of appealed items being restored after detection errors were found.[49]
On 26 March 2026 Parliament rejected a further extension of the derogation,[50] following sustained opposition from privacy activists,[51] causing it to expire on 3 April 2026. On 7 July 2026, Parliament approved an urgent procedure to consider reinstating it, requiring an absolute majority of MEPs to vote against to prevent it from passing.[52][53] The reinstatement passed a second reading on 9 July 2026, with amendments to exclude services employing end-to-end encryption,[54] in a manner compatible with the state of trilogue negotiations on the permanent legislation. The reinstatement is unenacted as of July 2026.[55] A majority of MEPs present voted against the reinstatement on the second reading, prompting criticism by opponents for the use of an urgent procedure.[56][2] The temporary reinstatement is set to expire in 2028.[2]
In furtherance of its 2020 child sexual abuse strategy, the European Commission proposed draft permanent regulation in May 2022.[57] Parliament adopted a substantially narrower negotiating position in November 2023, limiting detection orders and excluding end-to-end encrypted communications.[58] Successive Council presidencies pursued compromises regarding mandatory detection, encryption and proportionality, before the Danish Presidency removed mandatory detection orders in October 2025.[59]
The Council's November 2025 position retained voluntary detection, and strengthened compulsory risk assessment and mitigation duties. Trilogue negotiations began in December 2025, with detection remaining unresolved as of June 2026.[60]
This section needs expansion with: coverage of the provisions is currently incomplete. You can help by adding missing information. Relevant discussion may be found on the talk page. (July 2026) |
Definitions, scope and territorial application
The proposal defines known and unknown abuse material, and grooming, definitions later used to determine risks providers must assess and to which its prevention, reporting and enforcement provisions apply.[61][62] The Council position added risk categories to the assessment framework, with stronger obligations for high-risk services.[63]
Providers of hosting, interpersonal communication, app stores and ISPs anywhere directing service toward the EU are covered,[64] Parliament's position explicitly brought online games into scope.[65]
Non-EU providers must maintain a point of contact within the EU for authorities and the proposed Centre to communicate with,[66] and to support cross-border enforcement.[67]
EU Centre for the Protection of Children from Child Sexual Abuse
The EU currently relies on NCMEC, which has experienced backlogs lasting weeks,[68] to triage reports of suspected abuse occurring in Europe.[69] The proposal establishes a regional Centre to:
- receive, via a secure reporting system,[70] reports to be assessed directly within the EU,[71]
- reject false positives without need for a material investigation,[72] and notify the originating platform enabling it to improve its detection methods.[73]
- route legitimate reports to Europol and any authorities with likely jurisdiction,[74][75]
- maintain databases of known and suspected abuse indicators,[76]
- making detection technologies available to providers for free,[77]
- serve as a knowledge hub,[78]
- support victim assistance,
- help law-enforcement authorities act on reports,[79][80]
- issue an annual transparency report on its own performance.[81]
As of June 2026 most provisions concerning the Centre are agreed, except for its authority to conduct its own searches.[82]
The draft legislation would harmonize industry practice by requiring providers to assess the risk that their services could be misused for abuse, adopt reasonable mitigations,[83] and report their assessments and mitigation measures to the Centre every 3 months.[84]
The legislation requires hosting and interpersonal communications providers report potential abuse incidents arising from their own detection,[85] or from any detection order it has received[86] to the Centre immediately.[87] Reporting mandates sufficient information about an incident to be useful to authorities,[88] and information of sufficient quality.[89]
The proposal limits how abuse incident data can be used and retained by platforms:[90]
- to improve their detection systems,[91] except where it requires retaining personal data, [92]
- when blocking or terminating service to an account associated with abuse, related complaints and legal processes,[93]
- only for as long as strictly necessary, and for no more than 12 months,[94] unless requested by a court,[95]
- and accessed only for the purposes for which it was originally retained.[96]
A court can issue a detection order against a service where its own efforts have failed to mitigate abuse.[97]
A court can also issue a removal order, requiring a hosting provider or communication service to remove content within 24 hours.[98]
A blocking order enabled a court to require an ISP prevent access to material that cannot otherwise be removed.[99]
Search engines can be required to stop surfacing abuse material through a delisting order.[100]
Court orders under the legislation can be challenged by the platform itself or by the users it affects.[101]
The legislation introduces enforcement penalties against services:
- non-compliance fines up to 6% of worldwide annual income,[102]
- fines up to 1% of worldwide annual income for failing to provide, or providing incorrect information,[103]
- periodic fines up to 5% of average daily worldwide turnover for continued non-compliance.[104]
Fines must be calibrated to the seriousness and intentionality of the breach, and the size and financial health of the relevant service.[105]
The proposed legislation requires app stores to stop children installing apps with a significant risk of grooming.[106]
Private message services are also required to use age verification if their assessment identified a significant risk of grooming.[107]
Victims are granted new rights under the proposal to know about incidents involving themselves, to receive support from the Centre, and support to remove abuse material involving them.[108]
Providers are required to operate a user-friendly mechanism to flag potential abuse material on their services.[109]
- 11 May 2022 – The European Commission presented its draft legislation.[110]
- 28 July 2022 – The European Data Protection Supervisor and Data Protection Board issued a joint opinion stating the proposal "could become the basis for de facto generalized and indiscriminate scanning of the content of virtually all types of electronic communications", which could hinder sharing legal content due to the chilling effect.[111][112]
- 21 December 2022 – The Economic and Social Committee issued an opinion supporting the proposal's objective, but warned detection measures were disproportionate, risked widespread monitoring of private communications and could weaken privacy and end-to-end encryption.[113][114]
- 23 March 2023 – The Swedish Presidency of the Council circulated a new compromise text, 7595/23,[115] substantially reworking the May 2022 proposal and earlier Council drafts.[45]
- 13 April 2023 – The Parliamentary Research Service published an impact assessment commissioned by the LIBE Committee.[116] It found no available technology could reliably detect abuse material without substantial error rates, and warned teenagers could "feel uncomfortable when consensually shared images could be classified as abuse material".[117]
- 26 April 2023 – The Council Legal Service issued an opinion concluding detection orders risked amounting to general and indiscriminate scanning that could seriously interfere with the rights to privacy and protection of personal data under Articles 7 and 8 of the Charter of Fundamental Rights.[118] Drawing on Court of Justice of the European Union jurisprudence, it found a serious risk that the proposed regime would compromise the essence of those rights.[119]
- 12 October 2023 – The German government proposed splitting the draft regulation into broadly supported provisions and controversial provisions concerning mandatory detection. It proposed addressing detection measures in a separate regulation and extending the temporary derogation while negotiations continued.[120]
- 14 November 2023 – The LIBE Committee adopted a position limiting detection orders to time-limited, judicially authorized measures of last resort targeting individuals or groups rather than entire services, while excluding end-to-end encryption from their scope.[121]
- 13 February 2024 – The European Court of Human Rights ruled in an unrelated case that requiring degraded end-to-end encryption "cannot be regarded as necessary in a democratic society". The ruling underlined parliament's decision to protect encrypted communications.[122]
- 28 May 2024 – The Belgian Presidency circulated a text proposing "upload moderation" and seeking a majority by limiting scanning to images, videos, and URLs and requiring consent before transmission. Users who refused would lose the ability to share files. Critics argued that scanning before encryption still amounted to client-side scanning.[123]
- 20 June 2024 – The Belgian Presidency abandoned the vote because the proposal lacked the required qualified majority.[124][125][126]
- 12 December 2024 – The Hungarian Presidency's efforts also failed. Hungary continued work on variants of the Belgian approach, but member states remained divided over mandatory detection, encryption, proportionality, and the reliability of scanning technologies.[127]
- 5 June 2025 – The Polish Presidency explored another compromise centred on risk mitigation and a narrower detection system, but again failed to assemble a majority. A June 2025 Council progress document recorded continued disagreement over detection obligations and encrypted services.[128]
- 1 July 2025 – Denmark assumed the presidency, stating in its programme they would "give the work on the Child Sexual Abuse (CSA) Regulation and Directive high priority".[129]
- 8 October 2025 – The German government confirmed it would not support the Danish proposal, preventing it from reaching the required majority.[130][131]
- 30 October 2025 – The Danish Presidency removes mandatory detection orders, circulating a revised text 14092/25[132] abandoning the obligation to conduct mandatory scanning. It retained voluntary detection, strengthened risk-assessment and mitigation duties, and preserved the proposed EU Centre.[59][133]
- 19 November 2025 – Committee of Permanent Representatives endorse the Danish compromise as the basis for final Council approval.[134]
- 26 November 2025 – European Council adopted its negotiating position. It does not require providers to detect abuse proactively, emphasized compulsory risk assessments and mitigation while making the temporary voluntary-scanning regime permanent.[135]
- 9 December 2025 – Parliament, Council and Commission begin trilogues.
- 29 June 2026 – Parliament's negotiating team release a statement indicating negotiations had "managed to reach compromises on almost the entire Regulation", allowing "us to focus on finding balanced solutions on the remaining aspects of the Regulation, in particular on detection, as early as possible".[136]
- 23 July 2026 – European Council gave final approval to the reinstatement of the derogation.[137]
Trilogue meetings began after the Council adopted its negotiating position in November 2025.[138] By April 2026, negotiators had reached consensus on risk assessment, mitigation measures and reporting, while detection measures remained the focus of debate.[139]
As of July 2026, the principal dispute concerned whether detection by platforms should remain voluntary, or could also be required through targeted detection orders as a measure of last resort.[139][140] Open questions included which users or groups could be targeted, how they would be identified and the basis for selection.[141] Negotiation also continues on whether detection should cover known material, previously unknown material and the grooming of children.[142] Reporting has indicated agreement that end-to-end encrypted communications should be excluded from detection technologies.[143]
The proposed regulation has been supported by child advocacy groups including the Internet Watch Foundation and members of the ECLAG coalition.[4][144] In the European Parliament, the European People's Party has been a strong supporter of the proposal.[2]

Opponents of the original Commission proposal often highlight its mandatory detection provisions could impose surveillance of digital private communications, and as such refer to it as Chat Control.[12][145][13] Some civil society organisations and activists have argued it was incompatible with fundamental rights, infringing on the right to privacy.[146][147] Opposition has come from many sides of the political spectrum including from left-wing, liberal and right-wing politicians.[7]
In April 2023, Parliament confirmed they had received messages calling to vote against the Commission's proposal.[148]
EU Commissioner Ylva Johansson has been criticised regarding how the proposal was drafted and promoted. A transnational investigation by European media outlets revealed involvement of foreign technology and law enforcement lobbyists in its preparation.[149] This was also highlighted by digital rights organisations, which Johansson rejected to meet on three occasions.[150] Johansson was also criticised for the use of micro-targeting techniques to promote its controversial draft proposal, which violated the EU's data protection and privacy rules.[151]
Some claims criticizing the proposals, such as that governments would be able to read the messages of individuals at will, have been characterized as false or misleading.[152][153]
A poll released in April 2026 by the Central European Digital Media Observatory found that 58% of respondents across 9 EU states believed the proposal would improve online safety, though only 22% of respondents reported being aware of it. 28% of respondents believed the proposal would threaten freedom of speech.[154]
- General Data Protection Regulation (GDPR) – EU privacy regulation
- Article 8 of the European Convention on Human Rights § Mass surveillance
- Directive on Copyright in the Digital Single Market – EU directive
- Online Safety Act 2023 – UK Act of Parliament
- Patriot Act – US anti-terrorism and surveillance law
- Mass surveillance in China § Internet
- ↑ Chee, Foo Yun (26 November 2025). "EU states back away from forcing Big Tech to detect and remove child pornography". Reuters. Retrieved 15 July 2026.
- 1 2 3 4 Leal, Adnan (18 July 2026). "Why the EU's so-called Chat Control law has privacy experts up in arms". euronews. Retrieved 19 July 2026.
- ↑ "A beginner's guide to EU rules on scanning private communications: Part 2". EDRi. Retrieved 12 July 2026.
The Commission's plans have been coined "Chat Control" by Patrick Breyer, a human rights lawyer and MEP, because they seek to automatically scan the chats, messages and web-based emails of every person in the EU (including young people)
- 1 2 "Letter from ECLAG to MPs" (PDF). Archived (PDF) from the original on 11 April 2024. Retrieved 12 July 2023.
- ↑ "Fight Chat Control - Member State Positions". fightchatcontrol.eu. Retrieved 11 July 2026.
- ↑ "Statement by the EP negotiating team on combatting child sexual abuse online | News | European Parliament". www.europarl.europa.eu. 29 June 2026. Retrieved 15 July 2026.
- 1 2 "Chat Control 1.0 passed the European Parliament — through the back door". euronews. 10 July 2026. Retrieved 12 July 2026.
- ↑ Clark, Sam (10 October 2025). "Why Europe is freaking out about 'chat control'". POLITICO. Retrieved 12 July 2026.
- ↑ "Press corner". European Commission - European Commission. Archived from the original on 27 April 2021. Retrieved 12 July 2023.
- ↑ "EU plans new law to combat child abuse – DW – 01/09/2022". dw.com. Archived from the original on 4 February 2023. Retrieved 4 February 2023.
- ↑ Birchard, Rosie; Braunschweig, Beatrice von (14 October 2025). "EU delays 'chat control' law over privacy concerns". dw.com. Retrieved 12 July 2026.
Under the latest proposal penned by current EU chair Denmark, tech firms deemed high risk could be ordered to scan all links, images and videos — though not texts — shared on their platforms, to report instances of suspected child sexual abuse material to law enforcement ... Most controversially, the rules would also apply to content shared on messengers such as WhatsApp, which use encryption — a technical promise that your message won't be seen by anyone other than the person it's intended for.
- 1 2
- Kabelka, Laura (27 June 2022). "Bundestag quarrels over retaining IP data to fight child abuse". Euractiv. Archived from the original on 4 February 2023. Retrieved 4 February 2023.
- Kabelka, Laura (11 October 2022). "MEPs sceptical on EU proposal to fight online child sexual abuse". Euractiv. Archived from the original on 4 February 2023. Retrieved 4 February 2023.
- Pollet, Mathieu (10 May 2022). "LEAK: Commission to force scanning of communications to combat child pornography". Euractiv. Archived from the original on 4 February 2023. Retrieved 4 February 2023.
- Elena Sánchez Nicolás (5 July 2022). "Report slams German opposition to new child sexual abuse rules". EUobserver. Brussels. Archived from the original on 4 February 2023. Retrieved 4 February 2023.
- "Chat Control: The EU's CSEM scanner proposal". Patrick Breyer. Archived from the original on 10 March 2023. Retrieved 10 March 2023.
- 1 2 Mullin, Joe (19 October 2022). "EU Lawmakers Must Reject This Proposal To Scan Private Chats". Electronic Frontier Foundation. Archived from the original on 15 March 2023. Retrieved 10 March 2023.
- ↑ "Defend encryption! Open letter to the EU urging them to protect your privacy". Retrieved 17 June 2024.
- ↑ "Chat Control: What is actually going on?". European Digital Rights (EDRi). 24 September 2025. Retrieved 12 July 2026.
EU governments will decide whether to endorse or reject a mass surveillance, encryption-breaking and anonymity-ending law: the EU CSA Regulation
- ↑ [12][13][14][15]
- ↑ Directive 2011/93/EU of the European Parliament and of the Council of 13 December 2011 on combating the sexual abuse and sexual exploitation of children and child pornography, and replacing Council Framework Decision 2004/68/JHA, vol. 335, 13 December 2011, retrieved 16 July 2026
- ↑ "Combating child sexual abuse and exploitation" (PDF). European Parliamentary Research Service. September 2024. Retrieved 17 July 2026.
During the previous term, Parliament repeatedly stressed the importance of fully implementing Directive 2011/93/EU.
- ↑ "EU Strategy for a more effective fight against child sexual abuse". European Parliament Legislative Train Schedule. Retrieved 17 July 2026.
The Council ... and the European Parliament ... had urged for such measures.
- ↑ "Curbing the surge in online child abuse: The dual role of digital technology in fighting and facilitating its proliferation" (PDF). European Parliamentary Research Service. November 2020. pp. 2–3. Retrieved 17 July 2026.
The pandemic has created a unique situation that has seen both child sex offenders and minors spending more time online.
- ↑ "Commission adopts strategy for a more effective fight against child sexual abuse". Better Internet for Kids. 2020. Retrieved 17 July 2026.
The strategy was announced ... as part of the European Commission's Security Union Strategy.
- ↑ "Combating child sexual abuse online" (PDF). European Parliamentary Research Service. 30 May 2023. Retrieved 17 July 2026.
- ↑ "Single Market For Digital Services and amending Directive 2000/31/EC". Retrieved 12 July 2026.
Where a provider of hosting services becomes aware of any information giving rise to a suspicion that a criminal offence involving a threat to the life or safety of a person or persons has taken place, is taking place or is likely to take place, it shall promptly inform the law enforcement or judicial authorities of the Member State or Member States concerned of its suspicion and provide all relevant information available
- ↑ "Single Market For Digital Services and amending Directive 2000/31/EC (Digital Services Act)". Retrieved 12 July 2026.
Nothing in this Regulation should be construed as an imposition of a general monitoring obligation or a general active fact-finding obligation, or as a general obligation for providers to take proactive measures in relation to illegal content.
- ↑ "Building a Database of CSAM for AOL, One Image at a Time". Community Signal. Retrieved 14 July 2026.
when he first started at AOL, in the mid-'90s, the work of finding and reviewing CSAM was largely manual
- ↑ "Child sexual abuse 'hash lists' shared with internet giants". Wired. Retrieved 14 July 2026.
The master list is based on content the IWF's own analysts investigations have assessed and confirmed. This content may have been flagged up as a part of their own investigations, warnings from the public, internet companies, or from CAID.
- ↑ "Child sexual abuse 'hash lists' shared with internet giants". Wired. Retrieved 14 July 2026.
When any new image is uploaded onto their services, it will be automatically hashed on their end. Then it can be automatically compared to our hash list.
- ↑ Pingen 2022: "It is submitted that the current system based on voluntary detection and reporting by companies has proven insufficient to adequately protect children"
- ↑ "What Apple Can Do Next to Fight Child Sexual Abuse". Wired. Retrieved 14 July 2026.
Facebook topped the 2020 list-making 20.3 million reports last year. Google made 546,704; Dropbox 20,928; Twitter 65,062, Microsoft 96,776; and Snapchat 144,095. Apple made just 265 CSAM reports
- 1 2 Lu, Mengyao; Lamond, Maria; Fry, Deborah (2024). "A content analysis of metrics on online child sexual exploitation and abuse used by online content-sharing services". Child Abuse & Neglect. 157 107046. doi:10.1016/j.chiabu.2024.107046.
Without such an evidence base, there are no objective measures to assess the progress and effectiveness in addressing OCSEA.
- ↑ Transparency Reporting on Child Sexual Exploitation and Abuse Online (PDF) (Report). OECD. 2023. pp. 6–7. Retrieved 13 July 2026.
Only 10 of the 50 services define CSEA with sufficient detail to understand what is prohibited on their services, and only 20 of the services issue a transparency report on CSEA.
- ↑ "Explaining the technology for detecting child sexual abuse online". Child Rights International Network. 10 November 2023. Retrieved 14 July 2026.
The identification of unknown child sexual abuse material can only be done through artificial intelligence, based on machine learning. [..] The detection of grooming requires the analysis of text through machine learning.
- ↑ "What Apple Can Do Next to Fight Child Sexual Abuse". Wired. Retrieved 14 July 2026.
PhotoDNA, which was developed by Microsoft and Dartmouth College in 2009
- ↑ "Microsoft tackles spread of child abuse imagery with free online tool". Wired. Retrieved 14 July 2026.
PhotoDNA will then be able to identify exploitative imagery whenever it comes across any photo with a signature matching one held in its database of known illegal images.
- ↑ "Protecting people from illegal harms online: Volume 2—Service design and user choice" (PDF). Ofcom. 16 December 2024. p. 183. Retrieved 14 July 2026.
- ↑ "Explaining the technology for detecting child sexual abuse online". Child Rights International Network. Retrieved 14 July 2026.
PhotoDNA, one of the main tools for perceptually hashing photos and videos, has been said to have a false positive rate of 1 in 50 billion. However, there is no independent review of this technology.
- ↑ "Explaining the technology for detecting child sexual abuse online". Child Rights International Network. Retrieved 14 July 2026.
The Commission's Impact Assessment does not provide specific false positive error rates for Thorn's classifier or the other tools it mentions.
- ↑ "An Garda Síochána unlawfully retains files on innocent people who it has already cleared of producing or sharing of child sex abuse material". Irish Council for Civil Liberties. Retrieved 14 July 2026.
Of the 4,192 reports received, only 852 were found to contain child sexual abuse material, while 471 were categorised as false positives.
- ↑ Steel, Chad M.S. (2024). "Artificial intelligence and CSEM - A research agenda". Child Protection and Practice. 2 100043. doi:10.1016/j.chipro.2024.100043. Retrieved 9 July 2026.
- ↑ "COM(2025) 740 final". EUR-Lex. Retrieved 14 July 2026.
The overwhelming majority of content detected using these technologies was confirmed as child sexual abuse material following human review.
- ↑ "establishing the European Electronic Communications Code". Official Journal of the European Union. Retrieved 11 July 2026.
- ↑ "Proposal for a REGULATION OF THE EUROPEAN PARLIAMENT AND OF THE COUNCIL on a temporary derogation from certain provisions of Directive 2002/58/EC of the European Parliament and of the Council as regards the use of technologies by number-independent interpersonal communications service providers for the processing of personal and other data for the purpose of combatting child sexual abuse online". Retrieved 11 July 2026.
- 1 2 "Why the EU's temporary law allowing companies to detect child sexual abuse online must be extended". Internet Watch Foundation. 9 March 2026. Retrieved 14 July 2026.
This legal cover is sometimes nicknamed "chat control 1.0" by those who oppose companies detecting and removing child sexual abuse material online. Many of the claims circulating online reflect a profound misunderstanding about the technologies used and their purpose
- ↑ "'Irresponsible failure': Google, Meta, Snap and Microsoft slam EU over child sexual abuse law lapse". The Guardian. Retrieved 14 July 2026.
reports of such material from EU-based accounts to the National Center for Missing and Exploited Children fell by 58% over a period of 18 weeks
- 1 2 Claburn, Thomas (3 March 2023). "German Digital Affairs Committee hearing heaps scorn on Chat Control". The Register.
- ↑ "Regulation - 2021/1232 - EN - EUR-Lex". eur-lex.europa.eu. Retrieved 13 September 2024.
- ↑ Smalley, Suzanne (10 July 2026). "Europe revives law allowing big tech to scan for CSAM". The Record from Recorded Future News. Retrieved 12 July 2026.
- ↑ Bertuzzi, Luca (6 July 2021). "New EU law allows screening of online messages to detect child abuse". Euractiv.
- ↑ "1.Interim Regulation Report Article 3 1 g vii EU Regulation 2021 1232 Meta Platforms Ireland Limited Ares 2024 3709099.pdf". www.asktheeu.org. Archived from the original on 12 March 2026. Retrieved 12 July 2026.
Between January 1, 2023 and December 31, 2023, we actioned around 3.6M pieces of media constituting CSAM that were detected using our media matching technology, in message threads which included an EU user
- ↑ "CDT Europe's Response to the European Parliament Rejection of the Chat Control 1.0's Extension". Center for Democracy and Technology. Retrieved 14 July 2026.
the European Parliament voted not to extend the temporary derogation
- ↑ "Chat Control: EU Parliament said no to Big Tech mass surveillance of your chats - but the battle for privacy isn't done". TechRadar. Retrieved 14 July 2026.
Amid widespread criticism from privacy experts and civil society
- ↑ "European Parliament, Plenary, Tuesday, 7 July 2026, Results of votes" (PDF). europarl.europa.eu. Retrieved 7 July 2026.
- ↑ Clark, Sam (9 July 2026). "Europe's conservatives revive zombie bill on child abuse scanning". POLITICO. Retrieved 12 July 2026.
- ↑ "Combating child sexual abuse: support for a more limited ePrivacy derogation | News | European Parliament". www.europarl.europa.eu. 9 July 2026. Retrieved 11 July 2026.
- ↑ "Procedure File: 2025/0429(COD) | Legislative Observatory | European Parliament". oeil.europarl.europa.eu. Retrieved 11 July 2026.
- ↑ Ward, Isabella (9 July 2026). "A Majority of European Lawmakers Voted Against Letting Big Tech Read Our Messages. They're Going to Anyway". WIRED. Retrieved 19 July 2026.
- ↑ Scarsini, Mariavittoria (2026). "Chat Control and the Repercussions of Mandatory Communication Detection". Trento Student Law Review. 8 (1): 99–123. doi:10.15168/TSLR.V8I1.3967. Retrieved 14 July 2026.
- ↑ "EU Child Sex Abuse Regulation proposal: European Parliament Committee adopts report". Wiggin LLP. Retrieved 14 July 2026.
Detection orders would only be used as a last resort; must be targeted to individual users or a group of users, or to a specific incident; and should not apply to end-to-end encrypted communications.
- 1 2 Moreau, Claudie. "Danish Presidency backs away from 'chat control'". Euractiv. Archived from the original on 31 October 2025. Retrieved 14 July 2026.
The Danish presidency of the EU Council has dropped mandatory detection obligations from its latest compromise proposal.
- ↑ "CSAM Regulation: Council Position Reached". eucrim. Retrieved 14 July 2026.
The Council position removes mandatory detection orders and instead focuses on risk assessment, mitigation measures and voluntary detection.
- ↑ Pingen 2022: "Providers will have to assess the risk that their services are misused to disseminate child sexual abuse material or for purposes to solicit children, known as grooming"
- ↑ "Combating child sexual abuse online" (PDF). European Parliamentary Research Service. January 2026. p. 4. Retrieved 15 July 2026.
The general objective of the proposal is to improve the functioning of the internal market ... by introducing consistent mandatory EU rules to prevent and combat child sexual abuse online, covering both old and new CSAM as well as grooming.
- ↑ Pingen 2025: "The Council text introduces three risk categories for online services, allowing proportional obligations – particularly for high-risk platforms, which may be required to contribute to the development of mitigation technologies."
- ↑ "EU Proposes Legislation Targeting Online Child Sexual Abuse Material". Orrick. 10 August 2022. Retrieved 16 July 2026.
If a covered service has an establishment in Europe, or targets its activities towards one or more Member States, then it will have to comply with the Regulation.
- ↑ "How the EU is fighting child sexual abuse online". European Parliament. 26 June 2025. Retrieved 16 July 2026.
The regulation would also introduce specific mandatory mitigation measures for services directly targeting children, platforms primarily used for the dissemination of pornographic content, and certain chat services within games.
- ↑ "EU Proposes Legislation Targeting Online Child Sexual Abuse Material". Orrick. 10 August 2022. Retrieved 16 July 2026.
Non-EU covered services will also be obligated to appoint a European representative to serve as a point of contact for regulators.
- ↑ "Obligations of Online Service Providers to Fight Against Child Sexual Abuse Material in the European Union". Journal of Human Trafficking. 2026. Retrieved 16 July 2026.
OSPs might establish their CSAR Proposal point of contact in Country A to receive removal orders while receiving European investigation orders in Country B.
- ↑ "Report urges fixes to online child exploitation CyberTipline before AI makes it worse". AP News. 22 April 2024. Retrieved 13 July 2026.
It took them weeks to get through that backlog.
- ↑ Quintel, Teresa (18 November 2025). "Europol's Data Dominance: The Multifaceted Involvement and Impact of Data Analytics Across Sectors". European Papers. 10 (3): 747–778. doi:10.15166/2499-8249/853. ISSN 2499-8249.
The EU Centre will substitute the EU law enforcement's reliance on the NCMEC as it would provide a triage role for reports of potential CSAM from providers.
- ↑ Global Response Against Child Exploitation: Legal Report (PDF) (Report). GRACE. 2024. p. 77. Retrieved 16 July 2026.
These European CSA reports are shared at first solely with the EU Centre via a secure information sharing system.
- ↑ Pingen 2022: "The EU Centre will support national law enforcement and Europol by reviewing the reports from the providers to ensure that they are not submitted in error. It will channel reports quickly to law enforcement"
- ↑ Global Response Against Child Exploitation: Legal Report (PDF) (Report). GRACE. 2024. p. 77. Retrieved 16 July 2026.
Having received such a report, the EU Centre has to assess whether the report is "manifestly unfounded" in order to avoid obvious false positives.
- ↑ Global Response Against Child Exploitation: Legal Report (PDF) (Report). GRACE. 2024. p. 77. Retrieved 16 July 2026.
When the EU Centre considers a report to be "manifestly unfounded", the EU Centre has to inform the reporting provider to that extent and specify the reasons.
- ↑ Pingen 2022: "The EU Centre will support national law enforcement and Europol by reviewing the reports from the providers to ensure that they are not submitted in error. It will channel reports quickly to law enforcement"
- ↑ Global Response Against Child Exploitation: Legal Report (PDF) (Report). GRACE. 2024. p. 77. Retrieved 16 July 2026.
The EU Centre has to forward the report to Europol and to the competent national LEA(s) likely to have jurisdiction.
- ↑ Pingen 2025: "It also confirms the creation of a new EU agency ... to support implementation, maintain a central database of verified CSAM indicators, and channel reports to Europol and national law enforcement."
- ↑ Pingen 2022: "It will also make detection technologies available to providers free of charge so that detection orders addressed to providers can be executed."
- ↑ "Controversial Proposal on Combating Child Sexual Abuse Online". eucrim.eu. Retrieved 18 July 2026.
"It will .. support Member States by serving as a knowledge hub for best practices on the prevention of child sexual abuse and assistance to victims."
- ↑ Pingen 2022: "It will channel reports quickly to law enforcement and support Member States by serving as a knowledge hub for best practices on the prevention of child sexual abuse and assistance to victims. It will also make detection technologies available to providers free of charge"
- ↑ Transparency Reporting on Child Sexual Exploitation and Abuse Online (PDF) (Report). OECD. 2023. p. 32. Retrieved 13 July 2026.
The proposed EU Centre will coordinate actions to fight against child sexual abuse, from detection and reporting, to prevention and assistance to victims. It will support law enforcement to act on reports.
- ↑ "Fundamental rights assessment of the framework for detection orders under the CSAM proposal" (PDF). Institute for Information Law. April 2023. Retrieved 18 July 2026.
The EU Centre would publish annual transparency reports, compiling and analysing information from service providers and coordinating authorities, as well as information on its own activities
- ↑ Proposal for a Regulation laying down rules to prevent and combat child sexual abuse: State of play of interinstitutional negotiations (PDF) (Report). Council of the European Union. 22 June 2026. p. 2. Retrieved 13 July 2026.
Provisional agreement has been reached on almost all the provisions related to the EU Centre, with the exception of own-initiative searches
- ↑ Pingen 2022: "Providers will have to assess the risk that their services are misused to disseminate child sexual abuse material or for purposes to solicit children, known as grooming; providers must also take reasonable mitigation measures tailored to the risk identified"
- ↑ des Hommes, Terre. "THE PROPOSED EU CHILD SEXUAL ABUSE REGULATION" (PDF). Retrieved 18 July 2025.
Provider reports risk assessment and mitigation to CA every 3 months
- ↑ LIBE 2023a: "Upon obtaining actual knowledge on potential online child sexual abuse on their services, they should act expeditiously ... and ... report it to the EU Centre"
- ↑ Witting, Sabine K.; Malgieri, Gianclaudio (15 May 2023). "Voluntary detection orders under the proposed EU Child Sexual Abuse Regulation violate EU (privacy) law". European Law Blog. doi:10.21428/9885764c.1294c4df. Retrieved 18 July 2026.
If a provider receives a detection order, it is obliged to use technologies to detect and report specific types of online CSA to a newly established 'EU Centre'.
- ↑ LIBE 2023a: Providers "should act expeditiously to remove or to disable access to that content and to report"
- ↑ LIBE 2023a: "Those reports should ... contain a minimum of information as specified in this Regulation, and providers should ensure the quality of the information submitted"
- ↑ LIBE 2023a: "Providers should ensure the quality of the information submitted so the EU Centre can conduct its assessment"
- ↑ "Joint Opinion 04/2022 on the Proposal for a Regulation of the European Parliament and of the Council laying down rules to prevent and combat child sexual abuse" (PDF). europea.eu. EDPB & EDPS. Retrieved 18 July 2026.
Article 22 of the Proposal limits the purposes for which the providers subject to the Proposal may keep the content data and other data processed in connection to the measures taken to comply with the obligations set out in the Proposal
- ↑ "Joint Opinion 04/2022 on the Proposal for a Regulation of the European Parliament and of the Council laying down rules to prevent and combat child sexual abuse" (PDF). europea.eu. EDPB & EDPS. Retrieved 18 July 2026.
The Proposal indicates that providers may also preserve this information for the purpose of improving the effectiveness and accuracy of the technologies to detect online child sexual abuse for the execution of a detection order
- ↑ "Joint Opinion 04/2022 on the Proposal for a Regulation of the European Parliament and of the Council laying down rules to prevent and combat child sexual abuse" (PDF). europea.eu. EDPB & EDPS. Retrieved 18 July 2026.
They shall not store any personal data for that purpose
- ↑ "D2.3 Research Report on Legislation" (PDF). CESAGRAM. 20 March 2024. Retrieved 18 July 2026.
The purposes concern … measures against users, handling complaints and redress, and responding to competent authorities
- ↑ "D2.3 Research Report on Legislation" (PDF). CESAGRAM. 20 March 2024. Retrieved 18 July 2026.
The data may be retained for as long as strictly necessary, but the retention period will never be more than 12 months
- ↑ "D2.3 Research Report on Legislation" (PDF). CESAGRAM. 20 March 2024. Retrieved 18 July 2026.
The data retention period may be extended upon request by a competent national authority or court where necessary for ongoing administrative or judicial redress proceedings
- ↑ "D2.3 Research Report on Legislation" (PDF). CESAGRAM. 20 March 2024. Retrieved 18 July 2026.
The data may only be accessed and processed for the purposes for which it was preserved
- ↑ Pingen 2022: "Detection orders will be issued by courts or independent national authorities."
- ↑ "The proposed EU Child Sexual Abuse Regulation" (PDF). Terre des Hommes. Retrieved 14 July 2026.
order the removal of CSAM from a platform within 24 hours
- ↑ "Member States want internet service providers to do the impossible in the fight against child sexual abuse". European Digital Rights. 1 February 2023. Retrieved 17 July 2026.
Under the Commission proposal, ISPs can be ordered to block Uniform Resource Locators (URLs) for known CSA material which is hosted outside the European Union if voluntary removal of the material is not possible.
- ↑ "Eurochild reacts to the Council's position on the Regulation to Prevent and Combat Child Sexual Abuse". Eurochild. 8 December 2025. Retrieved 16 July 2026.
The competent national authorities will be empowered to require companies to remove content or, in the case of search engines, to delist search results.
- ↑ "Controversial Proposal on Combating Child Sexual Abuse Online". eucrim.eu. Retrieved 18 July 2026.
Both providers and users will have the right to challenge any measure affecting them in court
- ↑ Lannier, Salomé (3 April 2026). "Obligations of Online Service Providers to Fight Against Child Sexual Abuse Material—a Systematization of EU Law". Victims & Offenders. pp. 506–534. doi:10.1080/15564886.2025.2557901. Retrieved 18 July 2026.
In case of noncompliance, penalties must be passed at the national level, with fines up to "6% of the annual income or global turnover of the preceding business year," or period payments of up to "5% of the average daily global turnover […] in the preceding financial year per day
- ↑ "Legislative Overview" (PDF). Online Trust Coalition. 1 January 2026. Retrieved 19 July 2026.
Sanctions for providing incorrect, incomplete or misleading information, for failing to respond, failing to rectify incorrect, incomplete or misleading information or refusing to submit to an on-site inspection, shall not exceed 1% of the provider's annual income or total turnover.
- ↑ "Obligations of Online Service Providers to Fight Against Child Sexual Abuse Material - a Systematization of EU Law". Taylor & Francis Online. 23 March 2026. Retrieved 19 July 2026.
Authorities may impose periodic penalty payments of up to 5% of the provider's average daily worldwide turnover for each day of continued non-compliance
- ↑ "Last attempt at chat control: Hungary to force approval to scan". netzpolitik.org.
Member States should ensure that the competent authorities, whether to impose a penalty and when determining the type and level of, penalty is account is taken of all relevant circumstances, including: the nature, gravity and duration of the infringement; whether the infringement was intentional or negligent; any previous infringements by the provider or the other person; the financial strength of the provider or the other person; the level of cooperation of the provider or the other person with the competent authorities; the nature and size of the provider or the other person, in particular it is a micro, small or medium-sized enterprise; the degree of fault of the provider or other person, taking into account the technical and organizational taking measures by the provider it to with this regulation.
- ↑ "Online age verification and children's rights" (PDF). EDRI. 4 October 2023.
Article 6 requires app stores ... to block 'child users' ... from downloading apps with a 'significant' risk of grooming ... and to use ... age assessment measures
- ↑ "Online age verification and children's rights" (PDF). EDRI. 4 October 2023.
Article 4.3 requires private message services, including those offered via gaming platforms, to use document-based age verification or age estimation measures if they have identified a risk of grooming
- ↑ Apostle, Julia (10 August 2022). "EU Proposes Legislation Targeting Online Child Sexual Abuse Material". www.orrick.com. Orrick. Retrieved 18 July 2026.
a victim's right to information ... [and] a right of assistance and support for removal of such content.
- ↑ Gates, K&L. "Global Platform for Child Exploitation Policy, Legal Q&A: European Union" (PDF). Global Platform for Child Exploitation Policy. p. 31. Retrieved 18 July 2026.
Article 12(3) of the Proposal requires providers to 'establish and operate an accessible, age-appropriate and user-friendly mechanism that allows users to flag to the provider potential online child sexual abuse on the service,' ... thereby establishing a direct pathway for victims and the general public to report suspected CSAM or solicitation of children to platforms
- ↑ Pingen 2022.
- ↑ Finlay, McCann FitzGerald LLP-Adam (29 August 2022). "EDPB and EDPS opine on proposed further online content regulation to prevent and combat child sexual abuse". Lexology. Retrieved 12 July 2026.
- ↑ "EDPB-EDPS Joint Opinion 4/2022 on the Proposal for a Regulation of the European Parliament and of the Council laying down rules to prevent and combat child sexual abuse" (PDF). European Data Protection Supervisor. 28 July 2022. p. 20. Archived (PDF) from the original on 21 September 2023. Retrieved 16 October 2023.
- ↑ "Opinion of the European Economic and Social Committee on the Proposal for a Regulation laying down rules to prevent and combat child sexual abuse". Official Journal of the European Union (C 486). 21 December 2022. Retrieved 16 July 2026.
- ↑ "This EU law could end online privacy". Context. 10 November 2022. Retrieved 16 July 2026.
- ↑ "Proposal for a Regulation of the European Parliament and of the Council laying down rules to prevent and combat child sexual abuse - Presidency compromise texts". Retrieved 13 July 2026.
- ↑ "EU Parliament study slams online child abuse material proposal". www.euractiv.com. 13 April 2023. Archived from the original on 2 June 2023. Retrieved 2 June 2023.
- ↑ EPRS 2023a
- ↑ "EU Council's legal opinion gives slap to anti-child sex abuse law". Euractiv. 9 May 2023. Archived from the original on 1 June 2023. Retrieved 2 June 2023.
- ↑ "Opinion of the Legal Service: Proposal for a Regulation laying down rules to prevent and combat child sexual abuse" (PDF). Council of the European Union. 26 April 2023. Archived (PDF) from the original on 1 June 2023. Retrieved 2 June 2023.
- ↑ "Germany suggests splitting up child sexual abuse material regulation". Euractiv. 12 October 2023. Retrieved 17 July 2026.
- ↑ "Detect child abusers without mass scanning". EPP. 14 November 2023. Archived from the original on 18 November 2023. Retrieved 18 November 2023.
- ↑ Claburn, Thomas (15 February 2024). "European Court of Human Rights declares backdoored encryption is illegal". The Register. Archived from the original on 18 February 2024. Retrieved 18 February 2024.
- ↑ Castro, Chiara (7 June 2024). "Proposed EU Chat Control law wants permission to scan your WhatsApp messages". TechRadar. Retrieved 12 July 2026.
- ↑ Leloup, Damien (21 June 2024). "« Chat control »: dans la lutte contre la pédopornographie, revers pour le projet de règlement européen de surveillance des messageries". Le Monde (in French). ISSN 1950-6244. Retrieved 12 July 2026.
- ↑ Ivanovs, Alex (20 June 2024). "EU Council has withdrawn the vote on Chat Control". Stack Diary. Retrieved 21 June 2024.
- ↑ "EU 'chat-control' plan goes back to drawing board". Brussels Signal. 20 June 2024. Retrieved 21 June 2024.
- ↑ Euractiv (13 December 2024). "EU interior ministers remain deadlocked on CSAM detection bill". Euractiv. Retrieved 12 July 2026.
- ↑ "Online child sexual abuse material; lack of progress prompts Polish Presidency of EU Council to recommend extending transitional solution". agence europe. Retrieved 13 July 2026.
- ↑ "A strong Europe in a changing world" (PDF). 1 July 2025. Retrieved 6 September 2025.
- ↑ "Germany will not support 'Chat Control' message scanning in the EU". therecord.media. Retrieved 12 July 2026.
- ↑ Jones, Connor (8 October 2025). "Germany slams brakes on EU's Chat Control device-scanning snoopfest". The Register. Retrieved 1 November 2025.
- ↑ "Proposal for a Regulation of the European Parliament and of the Council laying down rules to prevent and combat child sexual abuse - Presidency compromise texts". Retrieved 13 July 2026.
- ↑ Castro, Chiara (5 November 2025). "Chat Control isn't dead, Denmark has a new proposal − here's all we know". TechRadar. Retrieved 12 July 2026.
- ↑ "Proposal for a Regulation of the European Parliament and of the Council laying down rules to prevent and combat child sexual abuse - Partial mandate for negotiations with the European Parliament | Parlament Österreich". www.parlament.gv.at (in German). Retrieved 12 July 2026.
- ↑ Pingen 2025
- ↑ "Statement by the EP negotiating team on combatting child sexual abuse online | News | European Parliament". www.europarl.europa.eu. 29 June 2026. Retrieved 13 July 2026.
- ↑ "Fighting child sexual abuse online: interim measure protecting children now reinstated". Consilium (in German). Retrieved 24 July 2026.
- ↑ Parodi, Alessandro; Chee, Foo Yun (26 November 2025). "EU states back away from forcing Big Tech to detect and remove child pornography". Reuters. Retrieved 17 July 2026.
EU countries will now have to thrash out details of the draft legislation with EU lawmakers before it can become law.
- 1 2 "CSAM regulation – interinstitutional negotiations progress, disagreements persist over voluntary nature of content detection". Agence Europe. 17 April 2026. Retrieved 17 July 2026.
Nevertheless, the measures governing content detection continue to be the focus of debate.
- ↑ Meister, Andre (12 June 2026). "Trilog zur Chatkontrolle geht in entscheidende Phase". netzpolitik.org (in German). Retrieved 17 July 2026.
Aufdeckungsanordnung: Freiwillig oder als letztes Mittel verpflichtend
- ↑ Meister, Andre (12 June 2026). "Trilog zur Chatkontrolle geht in entscheidende Phase". netzpolitik.org (in German). Retrieved 17 July 2026.
Es sei auch nicht klar, wer diese Personen oder Gruppen identifiziere und auf welcher Basis.
- ↑ Meister, Andre (12 June 2026). "Trilog zur Chatkontrolle geht in entscheidende Phase". netzpolitik.org (in German). Retrieved 17 July 2026.
LVA sprach sich für einen weiten Anwendungsbereich (bekanntes Material, neues Material, Grooming) aus.
- ↑ Meister, Andre (12 June 2026). "Trilog zur Chatkontrolle geht in entscheidende Phase". netzpolitik.org (in German). Retrieved 17 July 2026.
Einigkeit besteht zwischen den Ko-Gesetzgebern, dass Ende-zu-Ende verschlüsselte Kommunikationsinhalte von Aufdeckungstechnologien ausgenommen bleiben sollen.
- ↑ "Online child sexual abuse: The EU has a choice. Not between privacy and protection, but between indifference and compassion". Eliminating Child Sexual Abuse Online. 10 November 2025. Retrieved 19 July 2026.
- ↑ "A beginner's guide to EU rules on scanning private communications: Part 2". European Digital Rights (EDRi). Archived from the original on 10 March 2023. Retrieved 10 March 2023.Vincent, James (11 May 2022). "New EU rules would require chat apps to scan private messages for child abuse". The Verge. Archived from the original on 10 March 2023. Retrieved 10 March 2023.
- ↑ "European Commission must uphold privacy, security and free expression by withdrawing new law, say civil society". European Digital Rights (EDRi). Archived from the original on 7 April 2023. Retrieved 7 April 2023.
- ↑ "Chat control: incompatible with fundamental rights". GFF – Gesellschaft für Freiheitsrechte e.V. Retrieved 18 June 2024.
- ↑ "Citizens' enquiries on the EU's proposal to address child sexual abuse online". Epthinktank. 4 April 2023. Archived from the original on 6 April 2023. Retrieved 7 April 2023.
- ↑ Zandonini, Giacomo; Fotiadis, Apostolis; Stavinoha, Luděk (25 September 2023). "'Who Benefits?' Inside the EU's Fight over Scanning for Child Sex Content". Archived from the original on 17 November 2023. Retrieved 18 November 2023.
- ↑ "Commissioner Johansson cannot be trusted with the EU's proposed CSA Regulation". European Digital Rights (EDRi). Archived from the original on 18 November 2023. Retrieved 18 November 2023.
- ↑ Tar, Julia (16 October 2023). "EU Commission's microtargeting to promote law on child abuse under scrutiny". www.euractiv.com. Archived from the original on 18 November 2023. Retrieved 18 November 2023.
- ↑ "What is 'chat control', the EU's contentious plan to fight online child abuse?". TheJournal.ie. 11 July 2026. Retrieved 17 July 2026.
- ↑ "Did the European Parliament Adopt a Law Allowing Online Platforms to Monitor Private Chats?". Myth Detector. 14 July 2026. Retrieved 17 July 2026.
- ↑ "Chat Control 2.0: Six out of ten Europeans believe it will improve online safety, while one-fifth are willing to protest against this regulation". CEDMO. Retrieved 12 July 2026.
- Pingen, Anna (27 July 2022). "Controversial Proposal on Combating Child Sexual Abuse Online". eucrim.eu. Retrieved 12 July 2026.
- Pingen, Anna (22 December 2025). "CSAM Regulation: Council Position Reached". eucrim.eu. Retrieved 12 July 2026.
- EPRS (April 2023). "Proposal for a regulation laying down rules to prevent and combat child sexual abuse: Complementary impact assessment" (PDF). europa.eu. Archived from the original (PDF) on 3 June 2023.
- LIBE (16 November 2023). "REPORT on the proposal for a regulation of the European Parliament and of the Council laying down rules to prevent and combat child sexual abuse". europa.eu. COM(2022)0209.