@PikaSim_esim: "Voluntary scanning" is the polite phrase for a machine reading your messages before you've done anything wrong. The re…

X AI KOLs Timeline News

Summary

The EU Parliament passed Chat Control 1.0 by default, allowing voluntary mass scanning of private messages for CSAM until 2028, despite a majority of voting MEPs rejecting it—a procedural loophole set a controversial precedent.

"Voluntary scanning" is the polite phrase for a machine reading your messages before you've done anything wrong. The regulation assumes every private conversation is evidence waiting to be collected. A message that was never tied to your name is a lot harder to file away.
Original Article
View Cached Full Text

Cached at: 07/22/26, 08:28 AM

“Voluntary scanning” is the polite phrase for a machine reading your messages before you’ve done anything wrong. The regulation assumes every private conversation is evidence waiting to be collected. A message that was never tied to your name is a lot harder to file away.


EU Parliament Passes Chat Control by Default: 314 MEPs Couldn’t Block Scanning Law

Source: https://www.techtimes.com/articles/320010/20260709/eu-parliament-passes-chat-control-default-314-meps-couldnt-block-scanning-law.htm The EU Parliament passed Chat Control 1.0 into law Thursday afternoon without a majority of its members ever voting for it. Of the 607 MEPs who cast a vote in Strasbourg, 314 voted to reject the measure — a clear majority of those present. They fell 47 votes short of the 361-vote absolute majority required to stop it under second-reading procedural rules, and the law passed by default. Voluntary mass scanning of private messages on platforms including Gmail, Snapchat, Facebook Messenger, and Skype is now a legal activity in the EU until April 3, 2028.

The result closes a three-month gap created when Parliament voted down the same measure in March — and sets a precedent for how EU legislation that loses a floor vote can be revived without ever winning one.

How Parliament Rejected a Law It Had Already Rejected

The history of Chat Control 1.0 turns on a deceptively simple legal mechanism. The regulation, formallyRegulation (EU) 2021/1232, created a temporary exception to the EU’s ePrivacy Directive allowing messaging platforms to voluntarily scan private communications for child sexual abuse material (CSAM). It was first adopted in 2021, when Google, Meta, and Microsoft opted in immediately.

On March 26, 2026, the EU Parliament voted against extending it: 311 MEPs opposed, 228 were in favour, and 92 abstained. The derogation expired April 3. That appeared to be the end. It was not.

On July 2 — 90 days after Parliament’s rejection — the EU Council adopted the Commission’s original text as its official second-reading position. That single procedural step transformed the entire legislative arithmetic. UnderEU Parliament second-reading rules, Parliament can reject or amend a Council second-reading position only by an absolute majority of all members — currently 361 of 720 — not just a majority of those voting. Absences and abstentions effectively count as support for the Council’s text.

On July 7, the European People’s Party (EPP), the Parliament’s largest group, moved under Rule 170 of Parliament’s Rules of Procedure to invoke an urgency procedure, bypassing the standard committee review stage and sending the proposal directly to a plenary vote before the summer recess. Parliament President Roberta Metsola — herself an EPP member — initiated the process. The urgency vote passed 331 to 304. Then, on the last sitting day before summer, with fewer MEPs present than on a normal plenary day, the threshold arithmetic proved decisive.

“This is unprecedented,” said Greens/EFA MEPMarkéta Gregorová, Parliament’s negotiator on the file. “This is no longer just about protecting privacy — it is about protecting our democracy.”

What the Law Permits — and What It Does Not

Chat Control 1.0 authorizes but does not require platforms to scan private messages using three detection methods: perceptual hash-matching against databases of known CSAM images maintained by organizations such as NCMEC and the Internet Watch Foundation; AI-based image classification for previously-unseen material; and text analysis for grooming-pattern detection in chat conversations. TheInternet Society has detailedthe technical implications of each method and the risks each poses to user privacy.

Critically, the regulation does not apply to end-to-end encrypted communications — and it never did. Services such as WhatsApp and Signal encrypt messages between sender and recipient with keys that only those two parties hold, making server-side scanning technically impossible. An amendment explicitly exempting end-to-end encrypted services from the derogation’s scope was adopted today alongside the main vote. According toBreyer’s post-vote analysis, the platforms scanning under Chat Control 1.0 are unencrypted or server-side-encrypted US services: Gmail, Facebook Messenger (pre-2023), Instagram DMs (post-May 2026, after Meta removed E2E encryption), Skype, Snapchat, iCloud Mail, and Xbox.

The technical distinction matters to users choosing messaging tools. WhatsApp, Signal, iMessage (when iCloud backup is disabled), and similar E2EE-first services were not covered by Chat Control 1.0 before today, and the adopted amendment confirms they remain outside its scope. Scanning-as-usual resumes for the unencrypted services that had been operating without legal basis since April 3.

The accuracy record of these scanning systems is, however, genuinely contested. The European Commission’s own implementation report found that AI-based classifiers for unknown material produced a false positive rate “as high as 20 percent” — meaning one in five flagged conversations was not actually CSAM. Germany’s Federal Criminal Police Office (BKA) has reported that 48 percent of all Chat Control intelligence alerts it receives are “not criminally relevant.” Former MEPPatrick Breyer, citing the same official data, noted that 40 percent of investigations triggered by Chat Control flags actually target minors themselves — not perpetrators — and that an estimated 99 percent of the reports generated by Meta consist of previously known material that does little to identify active, ongoing abuse.

Why Researchers Say Scanning Rates Above Zero Are Still Too High

The proportionality concern raised by Prof. Bart Preneel of KU Leuven and other cybersecurity researchers is not just about the false-positive rate in isolation — it is about who bears the cost when that rate applies to 450 million EU users communicating daily. Preneel and Prof. Carmela Troncoso of the Max Planck Instituteco-authored an urgent appealto MEPs urging a no vote on the urgency procedure, warning that currently available detection technologies exhibit “unacceptably high error rates.”

End-to-end encryption works because the platform cannot read messages in transit. Client-side scanning — the method that would be required if the permanent Chat Control 2.0 regulation ever required E2EE platforms to comply — works by checking message content on the user’s device before it is encrypted and sent. As theInternet Society has documented, this creates a surveillance hook in the device’s software that can, in principle, be updated to scan for any content category the hash database contains, without the user’s knowledge or additional legislation.

The EU Charter of Fundamental Rights, Article 7, guarantees respect for private communications. The Council of the EU’s own Legal Service issued an opinion — later leaked and independently reported — stating that the regulation as written is incompatible with Article 7. That finding is the foundation of what legal observers expect will be a challenge before the Court of Justice of the European Union (CJEU). The European Court of Human Rights has also ruled, in aECHR 2024 encryption rulinginvolving Russia’s SORM surveillance law, that requiring degraded end-to-end encryption “cannot be regarded as necessary in a democratic society” — a ruling that carries persuasive authority for the CJEU even though ECHR and CJEU are separate bodies.

Procedural Template That Could Outlast This Vote

The mechanism that allowed Chat Control 1.0 to pass today is not specific to this legislation. UnderArticle 294 TFEU second reading, any proposal that Parliament fails to reject by absolute majority at second reading is deemed adopted. That rule exists because second-reading positions have, in the ordinary legislative procedure, already been through extensive trilogue negotiations — the intent is to give a negotiated text the benefit of the doubt when Parliament cannot muster a supermajority against it.

What happened today was different. The Council adopted its position on July 2 not after a negotiated trilogue but precisely to trigger the second-reading arithmetic after Parliament had already voted down the measure at first reading. Five trilogue rounds on the permanent Chat Control 2.0 regulation had failed to reach agreement. Rather than pursuing a sixth, the Council used the 1.0 derogation’s procedural path to restore the status quo without Parliament’s affirmative support.

Gregorová was not alone in naming this as a democratic problem. MEPFidias Panayiotouwrote Thursday: “The EU Parliament REJECTED Chat Control, but now they are forcing us to vote on the same issue over and over until they get the result they want. What kind of democracy is this?”

Breyer’s assessmentwas blunter: “The fact that Chat Control is moving forward against the will of the majority of voting MEPs is a farce and damages democracy.”

EPP leader Manfred Weber and four European Commissioners who wrote to MEPs ahead of the vote offered a different framing. The Commissionerswrote to MEPsarguing that disrupting detection “seriously weakens our collective ability to identify abuse, support victims, and stop offenders.” The EPP had opposed the March 2026 version of the extension because of amendments introduced by the Socialist rapporteur that restricted its scope; Weber’s goal was to restore the Commission’s original, unrestricted text — and the second-reading route achieved it.

What the Adopted E2EE Amendment Actually Does — and Doesn’t Do

One procedural wrinkle emerged in today’s vote that is not yet resolved. Parliament adopted, alongside the main text, an amendment explicitly exempting end-to-end encrypted services from the derogation’s scope. That amendment was approved by a majority of MEPs voting — but the question of what happens next is complicated.

Because Parliament adopted amendments to the Council’s second-reading position, the amended text must now return to the Council, which has three months — until approximately October 9, 2026 — to either accept the amendment or reject it. If the Council accepts, the E2EE exemption becomes part of the law. If the Council rejects it, a Conciliation Committee process begins. In the meantime, the core regulation — the mass-scanning authorization — is already in force. TheEU second-reading amendment rulesgoverning this three-month window are defined under the ordinary legislative procedure.

Critics note that the E2EE exemption is largely symbolic in any case: Breyer’s office points out that end-to-end encrypted services were never scanning under Chat Control 1.0, because the technical design of E2EE makes it impossible without client-side scanning, which the 1.0 framework did not require. The exemption clarifies the existing practice in statute; it does not create new protection.

Chat Control 2.0 Is the Bigger Fight — and Today’s Vote Complicates It

Thursday’s vote concerns only the temporary “1.0” derogation. The permanent regulation — the Child Sexual Abuse Regulation (CSAR), known as Chat Control 2.0 — remains under negotiation and would, in its most contested form, require even E2EE platforms to scan private messages, most likely through client-side scanning. Five trilogue rounds between Parliament, Council, and Commission have failed to produce a deal, with the fifth — on June 29, 2026 — collapsing specifically over the question of suspicionless scanning. The sixth round is expected under the Irish Presidency, likely in September 2026.

Digital rights advocates argue that restoring Chat Control 1.0 today has removed the Council’s primary incentive to compromise. So long as unencrypted-platform scanning proceeds under the existing voluntary framework, the Council faces less political pressure to accept Parliament’s insistence that any permanent regulation restrict scanning to individuals identified by judicial authority.Patrick Breyerstated the dynamic directly: “The Council will never agree to a desperately needed paradigm shift as long as they can simply stick to the old approach of suspicionless scanning at the whim of the tech industry.”

Parliament’s stated position in the Chat Control 2.0 negotiations — as developed by the LIBE committee’s November 2023 report — is that scanning of private communications must be limited to specific individuals or groups under judicial authorization, and that end-to-end encryption must be protected. Those positions stand going into the September talks, but with reduced procedural leverage.

What EU Users on Unencrypted Platforms Should Know

For users of the platforms that do scan under Chat Control 1.0, the practical effect as of today is that Gmail, Snapchat, Facebook Messenger, and similar services may continue using automated tools to flag messages that match databases of known CSAM or that AI classifiers identify as potential abuse material. The scanning is voluntary from the platform’s perspective; no platform is legally required to scan. In practice, the major US-based platforms that had opted in before April 3 are expected to resume.

Users concerned about private communications have several options that remain outside Chat Control 1.0’s scope: Signal and WhatsApp (with E2EE backup disabled) provide end-to-end encryption that the current framework explicitly does not cover. The distinction between Chat Control 1.0 — which applies only to unencrypted or server-decryptable messages — and Chat Control 2.0 — which could require scanning of E2EE services through client-side mechanisms — is the central reason that Signal and WhatsApp have not threatened to exit the EU over today’s vote specifically, though both services have previously indicated they would withdraw from any jurisdiction requiring backdoors into E2EE.

The Council’s Legal Service opinion flagging the regulation’s incompatibility with Article 7 of the EU Charter creates a realistic pathway for a legal challenge before the CJEU. Any EU resident or organization with standing — including privacy advocacy groups such as GFF (Gesellschaft für Freiheitsrechte) — could initiate proceedings. A successful challenge would invalidate the derogation regardless of its parliamentary passage. Separately, users who believe they were scanned illegally between April 3 and July 9 — the period when Chat Control 1.0 had lapsed but some platforms continued scanning — can file a complaint with their national data protection authority under Article 5 of the ePrivacy Directive.


Frequently Asked Questions

Why did Chat Control pass when most MEPs voted against it?

Under the EU’s ordinary legislative procedure, when the Council of the EU adopts a “second-reading position” — which it did on July 2 after Parliament’s March rejection — Parliament can only block the measure by an absolute majority of all its members: 361 of 720 MEPs, regardless of how many are present or voting. On July 9, 314 MEPs voted to reject it — a majority of those who voted, but 47 short of the required 361. The remaining MEPs were absent, abstaining, or in favour, and their non-opposition counted as acquiescence. The law passed without Parliament ever affirmatively voting for it, establishing a template that critics argue could be used to resurrect any rejected EU legislation through the same Council-first procedural route.

Does Chat Control 1.0 affect WhatsApp, Signal, or iMessage?

No. Chat Control 1.0 applies to messaging and email services that are not end-to-end encrypted, or where the platform can access message content server-side — primarily Gmail, Snapchat, Facebook Messenger, Skype, and Xbox. WhatsApp uses end-to-end encryption by default; Signal is fully E2EE; iMessage is E2EE when not backed up to iCloud. An amendment explicitly exempting E2EE services was adopted in today’s vote, though it must still return to the Council for acceptance. The more significant threat to encrypted messaging comes from the permanent Chat Control 2.0 regulation, still under negotiation, which proposes to require scanning even on E2EE platforms via client-side scanning technology.

What is the evidence that Chat Control scanning actually protects children?

The efficiency question is genuinely contested. Supporters point to millions of CSAM reports generated annually, contributing to investigations and rescues. Critics, including Breyer citing official EU and German police data, argue the system’s effectiveness is overstated: the BKA reports that 48 percent of Chat Control intelligence alerts are not criminally relevant, 40 percent of investigations target minors rather than offenders, and approximately 99 percent of reports from Meta concern previously known material that law enforcement already has. The EU Commission’s own implementation report found AI classifiers for unknown material produced false positives in up to 20 percent of cases. Parliament’s stated alternative — targeted scanning of specific individuals under judicial authorization — would, advocates argue, deliver more actionable intelligence with fewer civil liberties costs.

What happens next, and when will this be decided again?

Three processes run concurrently. The E2EE exemption amendment Parliament adopted today returns to the Council, which has until approximately October 9, 2026, to accept or reject it. Chat Control 2.0 trilogue negotiations are expected to resume in September under the Irish Presidency; the sixth round will again face the unresolved question of whether E2EE platforms can be required to implement client-side scanning. A legal challenge before the Court of Justice of the EU remains likely, given the Council’s own Legal Service opinion that the regulation is incompatible with Article 7 of the EU Charter. And the current derogation, absent a successful legal challenge, runs until April 3, 2028 — at which point the legislative cycle would repeat unless the permanent regulation is in place.

Similar Articles

EU Parliament greenlights Chat Control 1.0 – Breyer: "Our children lose out"

Hacker News Top

The EU Parliament approved an interim regulation allowing suspicionless mass scanning of private communications (Chat Control 1.0) despite majority opposition, due to a procedural rule requiring absolute majority. The measure will remain in effect until 2028, sparking criticism from civil rights activists who warn it undermines democracy and privacy.

EU Council forces Chat Control via fast-track

Hacker News Top

The EU Council is using a fast-track procedure to reinstate a temporary regulation that allows voluntary scanning of private messages by tech companies to detect child abuse material, bypassing the EU Parliament and raising concerns about digital privacy and democratic oversight.

Chat Control 1.0 and 2.0 Explained

Hacker News Top

Timeline of EU's Chat Control regulations, covering the voluntary scanning regime (1.0) expiration and the proposed permanent regulation (2.0) with encryption concerns.

Chat Control passed first round in EU Parliament

Hacker News Top

The European Parliament voted to revive the expired Chat Control regulation, allowing tech companies to voluntarily scan private chats for child sexual abuse material, sparking controversy over privacy and surveillance.

EU to legislate about Chat Control behind closed doors

Hacker News Top

EU faces a double threat to private communications as European Parliament President Roberta Metsola pushes to resurrect Chat Control 1.0 and upcoming trilogue negotiations on Chat Control 2.0 risk imposing mass surveillance, warrantless scanning, and the end of anonymous communication. Civil rights activists have relaunched fightchatcontrol.eu to mobilize citizens against these undemocratic backroom deals.