Hacker News
This article was shared on Hacker News.
It gained significant traction with over 1100 upvotes, 630 comments and 120 000 unique page views.
The European Union wants to force tech companies to scan your private messages & images, even in your favorite encrypted apps.
Introduction#
The 🇪🇺 European Union is advancing legislation that could fundamentally change how we communicate online. ChatControl would require all messaging platforms to automatically scan their users’ private messages and images.
Yes, even encrypted ones like Signal, WhatsApp and Telegram. No, you can’t opt out.
This isn’t just another privacy policy update you can ignore. If passed, this EU regulation (strongest and most binding legal instrument in EU law) would automatically apply to all member states without any wiggle room for national interpretation. It would even override constitutional protections for communication privacy and establish unprecedented mass surveillance of private communications.
The official justification? Fighting child sexual abuse material (CSAM). Protecting children is undeniably crucial, but the proposed methods would eliminate digital privacy for 450 million Europeans and set a global precedent for mass surveillance.
This surveillance trend extends beyond Europe: 🇨🇭 Switzerland is advancing metadata retention requirements, the 🇬🇧 UK is implementing comprehensive age verification systems and now the 🇪🇺 EU proposes to scan every private message. Each initiative is positioned as child protection policy, but the implications reach far beyond their stated goals.
What is ChatControl#
ChatControl is what critics call the EU’s proposed Regulation to Prevent and Combat Child Sexual Abuse, also known as CSAR (Child Sexual Abuse Regulation).
The proposal builds on surveillance techniques already deployed by major tech companies. Meta analyzes all Facebook Messenger conversations and unencrypted WhatsApp data (profile photos, group descriptions). Apple announced similar scanning for iCloud content in 2021, though they later suspended the program.
This turns voluntary corporate surveillance into mandatory government-ordered scanning. A temporary 2021 EU regulation allowed platforms to scan content voluntarily for three years. That authorization expired in 2024, which is why CSAR was proposed. The temporary regulation merely permitted scanning; CSAR would make detection obligatory under certain conditions.
There’s also the Roadmap for Lawful Access to Data which has an even bigger goal: making all our digital data readable by authorities upon request. We’ll dive deeper into this broader surveillance agenda later.
Scope and Coverage#
CSAR casts an extremely wide net. The regulation would apply to all interpersonal communication service providers, not just obvious targets like Signal, WhatsApp, or Telegram, but also:
- Email providers
- Dating apps
- Gaming platforms with chat features
- Social media platforms
- File hosting services (Google Drive, iCloud, DropBox…)
- App stores
- Even small community hosting services run by associations
This means virtually any digital service that allows people to communicate or share content would fall under surveillance requirements. The scope extends far beyond what most people imagine when they hear messaging apps.
How it Works#
ChatControl relies on Client-Side Scanning. Your device becomes a monitoring station that analyzes your content before encryption happens.
This represents a fundamental shift away from targeted surveillance based on court orders or reasonable suspicion. Unlike airport security (where you consent to specific, limited searches for immediate safety), ChatControl would automatically scan all private communications of all citizens, all the time.
Effectively reversing the presumption of innocence by treating everyone as a potential criminal. It’s the digital equivalent of permanently installing monitoring devices in every home and office, well… just in case.
Technical Implementation#

The system would automatically scan for three categories of content before encryption:
Known illegal content: Images or videos already catalogued by authorities as CSAM. Your device creates hash fingerprints of your content and compares them against databases of known illegal material.
Unknown potential content: Photos or videos that might constitute CSAM but haven’t been previously identified. AI algorithms analyze visual elements (like exposed skin) to flag potentially problematic content based on statistical models.
Grooming behavior: Text analysis using AI to identify communication patterns that match predefined indicators of adults soliciting children. This involves scanning the actual content of your private conversations.
If something gets flagged, it automatically gets reported to authorities. No human checks it first, that would be impossible given the billions of daily messages. This would be mandatory for all messaging platforms in 🇪🇺 Europe.
Why This Breaks Encryption#
ChatControl doesn’t break encryption, it bypasses it entirely. While your messages still get encrypted during transmission, the system defeats the purpose of end-to-end encryption by examining your content before it gets encrypted. True E2EE means only you and your recipient can read messages: no government, no company, no algorithm should peek inside. This surveillance violates that principle by inserting monitoring at the source.
Privacy-focused companies like Proton point out this approach might be worse than encryption backdoors. Backdoors give authorities access to communications you share with others. This system examines everything on your device, whether you share it or not.
Your encrypted messaging app becomes spyware. Supporters claim this protects privacy because scanning happens locally, but surveillance built into your device makes it impossible to escape.
Governance Structure#
The proposal would create a centralized EU Centre on Child Sexual Abuse to receive all reports, but EU institutions wouldn’t control the scanning technology itself.
Service providers would face additional obligations beyond scanning. They would need to conduct risk assessments to evaluate and minimize the potential for illegal content sharing on their platforms. This requires collecting detailed information about their users (age groups, content types) that many privacy-focused services deliberately avoid gathering.
The regulation also pushes for mandatory age verification systems. While some privacy-preserving age verification concepts exist (like zero-knowledge proofs), no viable, scalable solutions have been deployed at internet scale. Current implementations either compromise user privacy through identity collection or lack the accuracy needed for legal compliance.
Real-World Impact#
Encryption Concerns#
ChatControl fits into a broader political strategy. Since the 1990s crypto wars, certain states have argued that privacy-protecting technologies, especially encryption, obstruct police investigations. These technologies are designed to do exactly that, protect everyone’s ability to control their expression and communication.
The European Commission’s Roadmap for Lawful Access to Data wants to make all digital data accessible to authorities by 2030. This involves systematically weakening encryption rather than simply bypassing it.
Edward Snowden’s revelations ten years ago led to widespread adoption of encryption and institutional consensus supporting the right to encrypted communication. But governments remain frustrated by their inability to access private communications. We’re seeing a return to authoritarian positions using terrorism, organized crime and child exploitation as justifications for undermining encryption.
🇩🇰 Danish Minister of Justice Peter Hummelgaard, chief architect of the current ChatControl proposal, recently stated: “We must break with the totally erroneous perception that it is everyone’s civil liberty to communicate on encrypted messaging services.” Well, there you have it folks: encrypted communication isn’t a civil liberty anymore. You cypherpunks were wrong all along. /s
Similarly in 🇫🇷 France, both Bernard Cazeneuve and Emmanuel Macron have explicitly stated their desire to control encrypted messaging, seeking to pierce the privacy of millions who use these services.
CSAR provides the perfect opportunity for member states to finally design and implement a generalized surveillance tool for monitoring population communications. Crossing this threshold means eliminating all confidentiality from communications using digital infrastructure.
False Positives#
These scanning systems have a big accuracy problem. When content gets flagged, it’s wrong most of the time. 🇮🇪 Irish law enforcement confirms that only 20.3% of 4,192 automated reports actually contained illegal material, meaning 79.7% were false positives.

Even with hypothetical 99% overall accuracy (which current systems don’t achieve), scanning billions of daily messages would generate millions of false accusations that overwhelm police resources.
Innocent content regularly triggers these systems: family photos, teenage conversations, educational materials and medical communications. Consider this real case: a father was automatically reported to police after sending photos of his child’s medical condition to their doctor. Google’s algorithms flagged this legitimate medical consultation as potential abuse, permanently closed his account and refused all appeals. His digital life was destroyed by an algorithm that couldn’t distinguish between medical care and criminal activity.
Scientific Opposition#
For the third time in three years, over 600 cryptographers, security researchers and scientists across 35 countries have co-signed an open letter explaining why this mass scanning project is “technically unfeasible”, constitutes a “danger to democracy” and would “completely compromise” the security and privacy of all European citizens.
The letter emphasizes that client-side scanning cannot distinguish between legal and illegal content without fundamentally breaking encryption and creating vulnerabilities that malicious actors can exploit.
Meanwhile, the Commission has provided no serious studies demonstrating the effectiveness, reliability or appropriateness of these intrusive measures for actually protecting children. Industry claims appear to have taken precedence over evidence-based policy-making.
Genuine security emerges through thoughtful design where security measures and civil liberties function as complementary forces, not opposing ones.
Easily Defeated#
The fundamental flaw in ChatControl becomes clear when examining how easily determined actors can circumvent these scanning systems. Criminals don’t need sophisticated techniques to bypass client-side scanning; they use well-documented public knowledge already employed by malicious actors.
Layered Encryption
Encrypt files with standard tools like GPG before messaging. Hell, even a basic Caesar cipher would be sufficient to bypass detection. Since client-side scanning occurs after user encryption but before transport encryption, pre-encrypted content looks like random data to detection algorithms. Recipients decrypt locally with shared keys.
External Platform Bypass
Upload content to any third-party platform (Dropbox, OneDrive, anonymous file hosts, or obscure hosting services) and share links instead of files. The scanner sees innocent text containing a URL while the actual content sits untouched on external servers.
Custom Messaging Clients
Open-source protocols like XMPP and Matrix allow custom client development. Modified clients can automatically implement cloud storage and encryption workflows transparently. Users experience normal messaging while completely evading surveillance infrastructure.
Digital Steganography
Steganographic techniques embed data within innocent images. Family photos can carry hidden payloads invisible to both human operators and AI systems. Tools like OpenStego make this accessible to average users.
Platform Migration
Criminal networks can shift to decentralized platforms, peer-to-peer networks or services outside EU jurisdiction. Tor-based messaging, blockchain communications or servers in non-compliant countries remain beyond ChatControl’s reach.
ChatControl catches only amateur criminals who directly attach problematic content to messages. Professional networks already employ these evasion techniques as standard practice. EU legislation won’t make them forget how computers work.
The system fails at protecting children while succeeding at mass civilian monitoring. It’s not a bug, it’s a feature.
Business Interests#
Industry Players#
The child protection narrative masks concerning business interests. The European Commission based its CSAR proposal primarily on claims from industry players rather than independent research.
Commercial surveillance companies would manage the technology with guaranteed access to the European market. Organizations like Thorn (co-founded by actor Ashton Kutcher), Microsoft’s PhotoDNA and other tech companies develop these detection systems while simultaneously lobbying for regulations that would require their adoption across Europe.
These companies develop the detection technologies and lobby for laws mandating their adoption, creating a profitable feedback loop. The proposal would secure privileged market positions for surveillance companies across hundreds of millions of European users. Pretty nice, isn’t it?
These systems would be:
- Unverifiable: Operating without meaningful external examination or accountability.
- Legally powerful: Capable of starting criminal proceedings through algorithmic decisions.
- Proprietary: Built on closed-source code with methods hidden from public view.
We cannot audit what these algorithms would actually do. While companies claim they only detect illegal content, the closed-source nature makes verification impossible. The same scanning infrastructure could easily be repurposed to track political dissidents or journalists, monitor specific keywords or phrases, flag content based on changing political priorities or share data with intelligence agencies beyond stated purposes.
Rhetorical Tactics#

Commissioner Ylva Johansson consistently emphasizes this narrative in her communications:

“Think of the children” is a well-documented political rhetoric technique that appeals to emotion rather than evidence. While child protection is genuinely important, this approach frames any opposition as being against child welfare, making nuanced discussion more difficult.
This creates a false choice. Privacy isn’t a luxury for troublemakers, it’s a fundamental right that protects journalists, whistleblowers, activists and ordinary people from unwarranted intrusion.
Critics aren’t opposing child protection. We’re questioning whether undermining privacy rights for 450 million 🇪🇺 Europeans is the most effective approach when targeted alternatives exist that preserve rights.
Consequences#
The effects of these proposals go beyond individual privacy concerns.
Cybersecurity gets compromised
Adding deliberate vulnerabilities to encryption creates weaknesses that everyone can exploit. Any backdoor for authorized access becomes a potential entry point for criminals and foreign intelligence services. In February 2024, the 🇪🇺 European Court of Human Rights already determined that mandating weakened encryption “cannot be regarded as necessary in a democratic society”.
Innovation suffers
🇪🇺 European cybersecurity companies would face an impossible situation in global markets. How could they credibly sell security solutions when regulations require them to build in access mechanisms that undermine those very protections?
Tech companies will leave Europe
Privacy-focused services that moved to 🇪🇺 Europe after the Snowden revelations are already signaling they might leave. Signal has explicitly said it would stop operating in 🇪🇺 Europe rather than compromise its security.
Even 🇨🇭 Switzerland, traditionally seen as a privacy haven, is facing severe legislative pressures that are forcing tech companies to relocate. Proton has confirmed it has begun moving some of its physical infrastructure out of Switzerland due to “legal uncertainty” over the proposed surveillance law amendments. Lumo, their AI chatbot, became the first product to relocate, moving to Germany instead of Switzerland specifically because of these legislative concerns.
The Swiss OSCPT (Ordinance on the Surveillance of Correspondence by Post and Telecommunications) revision would require VPNs and messaging apps to identify users and retain data for up to six months, plus decrypt communications upon authority request. As Proton’s CEO Andy Yen explained, these are proposals that “have been outlawed in the EU” but could soon become reality in Switzerland.
Other privacy-focused providers like Tuta have expressed similar concerns and contingency plans to leave 🇨🇭 Switzerland if the surveillance laws pass.
Europe might become dependent on US surveillance
I’m not so sure on this one, but by outsourcing surveillance technology to American companies, 🇪🇺 Europe may create dangerous dependencies. These companies operate under 🇺🇸 US jurisdiction and the CLOUD Act, potentially allowing 🇺🇸 Washington to access data collected on 🇪🇺 European citizens. Under the pretense of child protection, the 🇪🇺 EU risks handing surveillance keys to foreign powers.
Social behavior changes
When people know they’re being watched, they change how they communicate. People start self-censoring, avoiding certain topics and carefully choosing their words even in private conversations.
This is called the chilling effect. Rights don’t disappear overnight: they erode gradually as people change their behavior to avoid potential problems.
EU Country Positions#
Understanding how 🇪🇺 EU member states position themselves on this legislation is crucial, as their votes will determine whether ChatControl becomes reality.
Vote Breakdown#
Countries that support ChatControl (12): 🇧🇬 Bulgaria • 🇭🇷 Croatia • 🇨🇾 Cyprus • 🇩🇰 Denmark • 🇫🇷 France • 🇭🇺 Hungary • 🇮🇪 Ireland • 🇱🇹 Lithuania • 🇲🇹 Malta • 🇵🇹 Portugal • 🇷🇴 Romania • 🇪🇸 Spain
Countries that oppose ChatControl (9): 🇦🇹 Austria • 🇨🇿 Czech Republic • 🇪🇪 Estonia • 🇫🇮 Finland • 🇩🇪 Germany • 🇱🇺 Luxembourg • 🇳🇱 Netherlands • 🇵🇱 Poland • 🇸🇮 Slovenia
Countries still undecided (6): 🇧🇪 Belgium • 🇬🇷 Greece • 🇮🇹 Italy • 🇱🇻 Latvia • 🇸🇰 Slovakia • 🇸🇪 Sweden
National Stances#
If you’re interested, here’s a full up-to-date timeline of events.
Take Action#
Here’s how you can contribute to defending our digital freedoms:
- Share this article and educate your network: Use hashtags like
#ChatControlor#StopScanningMe. Forward resources to friends, family and colleagues. - Sign the petition: against ChatControl at change.org.
- Stay informed and follow updates: @chatcontrol@mastodon.social, x.com/nonchatcontrol, patrick-breyer.de and fightchatcontrol.eu.
- Contact your national representatives (MEPs) to convince your country to oppose ChatControl, if it’s not already the case.
- Adopt privacy tools and infrastructure: Use Signal and other privacy-respecting alternatives. Host your own services or support privacy-focused providers.
Conclusion#
The irony is kinda painful: the continent that built GDPR to protect digital privacy now designs ChatControl to dismantle it systematically. What was once a fundamental right could become mandatory surveillance.
ChatControl represents a historic choice for 🇪🇺 Europe. Either we become the first democracy to normalize mass surveillance of private communications or we defend the digital rights that made Europe a global privacy leader.

This decision deserves close attention: authoritarian regimes worldwide are watching, ready to justify their own programs with: “Eh, if Europe does it, why shouldn’t we?”
What happened since#
October 2025: Victory#
October 7, 2025: 🇩🇪 Germany officially declared opposition to ChatControl. October 8, 2025: 🇪🇺 EU diplomats failed to reach agreement. 🇩🇰 Denmark’s compromise proposal collapsed and the scheduled vote at the next EU Interior Ministers meeting was cancelled.
ChatControl supporters now definitively lack the qualified majority needed (15 of 27 countries representing at least 65% of 🇪🇺 EU population). With 🇩🇪 Germany’s 83 million citizens joining the opposition, supporters can’t reach the population threshold required for adoption.
🇪🇺 Europeans can now keep their communication privacy intact… but for how long?

These ideas will return, dressed differently each time. Future 🇪🇺 EU presidencies will try revised approaches: narrower technical scope, different legal frameworks, new justifications.
Each attempt will require the same vigilance and organization. Democracy requires constant maintenance, including the digital kind.
March 2026: It came back#
Called it. It took less than two months.
- July 2025: 🇩🇰 Denmark takes over the 🇪🇺 EU Council Presidency and makes ChatControl a top priority. The revised “Chat Control 2.0” makes scanning voluntary for providers, but the regulatory framework strongly incentivizes it.
- November 26, 2025: The 🇪🇺 Council endorses Chat Control 2.0. All but four countries (🇨🇿 Czech Republic, 🇮🇹 Italy, 🇳🇱 Netherlands, 🇵🇱 Poland) back the text. 🇩🇪 Germany, whose opposition had been the decisive blow just weeks earlier, reverses course.
- December 9, 2025: First trilogue negotiations begin. The Commission also proposes extending Chat Control 1.0 voluntary scanning by another two years (until April 2028).
- March 11, 2026: The 🇪🇺 European Parliament votes to end untargeted mass scanning of private communications.
- March 22, 2026: The conservative EPP group moves to force a repeat vote to overturn Parliament’s decision.
Where we stand, as of March 26, 2026:
Countries that still oppose (4): 🇨🇿 Czech Republic • 🇮🇹 Italy • 🇳🇱 Netherlands • 🇵🇱 Poland
Everyone else endorsed. The picture is much grimmer than it was in October 2025.
Negotiations are ongoing, with a third session scheduled for May 4, 2026 and a potentially final one on June 29, 2026. The 🇨🇾 Cypriot Presidency has indicated it will push to finalize the regulation.
The 🇪🇺 European Parliament remains the last line of defense.
July 2026: Farce#
Remember the “voluntary” Chat Control 1.0? It expired in April 2026. It should have quietly died. Instead, it came back through the front door.
- July 7, 2026: The conservative 🇪🇺 EPP, the largest group in Parliament, triggers an urgency procedure to drag the expired rule back for a snap vote before summer recess, skipping the committees that would normally pick it apart.
- July 9, 2026: The vote itself. Of the 607 MEPs in the room, a clear majority (314) say no to bringing mass scanning back. Sounds like a win, right?
Except it wasn’t. Once the 🇪🇺 Council had rubber-stamped the Commission’s original text as its second-reading position, throwing it out required an absolute majority of the whole chamber: 361 of 720 seats, not a majority of whoever bothered to turn up. With roughly 112 MEPs absent (right as the summer break kicked in, funny that), the 314 “no” votes landed 47 short. Every empty chair and every abstention quietly counted as a vote for surveillance, and the dead rule reinstated itself.
The same day, MEPs also voted on an amendment to scan only the messages of people a judge already suspects, instead of scanning everyone. That’s the targeted, warrant-based approach critics have been asking for all along. It won an even wider majority than the rejection, 322 in favor, and it also fell short of 361 and failed. So a majority of Parliament said no to blanket scanning in two separate votes, and got blanket scanning anyway.
There’s one small mercy: MEPs did vote to keep end-to-end encrypted messages out of scope, so a genuinely encrypted chat can’t be scanned. Meta switched off end-to-end encryption in Instagram DMs on May 8, 2026 and told everyone to just move to WhatsApp, which it conveniently also owns. An encryption carve-out is worth nothing the day the biggest platforms decide to flip encryption off. So I’ll keep repeating the dull advice: drop the GAFAM apps for anything private. Use Signal instead, and your chats stay safe. For now.
And does any of this actually catch predators? The receipts say otherwise. Only about a third of last year’s abuse reports came out of this scanning machinery in the first place, and in 🇩🇪 Germany roughly half of those alerts turned out to have no criminal relevance at all. Meanwhile 🇺🇸 US reports have fallen by half since 2022, precisely as encryption became the default. Nobody has produced a single number showing that scanning everyone put more offenders behind bars or pulled one more child out of harm.
So we break privacy for 450 million 🇪🇺 Europeans to run a system that flags innocent people half the time and catches almost nobody. Looks good to me.
The real fight isn’t over either. Negotiations for the permanent Chat Control 2.0 resume in September 2026. Parliament still wants targeted scanning of actual suspects only, member states still want to scan everyone. Same standoff, higher stakes.
To be continued.
I’ll keep this post updated as the big moments land, so check back or follow along if you want to track where Chat Control goes next.
If you’ve found this article meaningful, you can support me, share it or follow me on your favorite platform. 🙏