Key facts
- EU governments confirmed an interim 'Chat Control' regime allowing platforms to scan private messages for child sexual abuse material (CSAM).
- The measure is effective until April 3, 2028, and excludes end-to-end encrypted services.
- The Commission's proposal, nicknamed 'Chat Control 2.0', aims to replace a temporary 2021 law.
- Supporters cite over 20.5 million suspected CSAM cases in 2024 and argue voluntary reporting is insufficient.
- Critics argue the proposal constitutes mass surveillance and undermines privacy protections and end-to-end encryption.
- The debate involves differing views on the balance between child protection and digital rights.
EU governments have confirmed an interim 'Chat Control' regime, allowing platforms to voluntarily scan private messages for child sexual abuse material (CSAM) until April 3, 2028. The measure, approved by written procedure with broad support, aligns with a version passed by MEPs and notably excludes end-to-end encrypted services like WhatsApp and Signal.
This decision marks a significant step in the ongoing debate over digital rights and child protection, shaping the larger, unresolved fight for a permanent, potentially mandatory scanning law. The European Commission's proposal, nicknamed 'Chat Control 2.0', aims to replace a narrower, temporary 2021 law and would apply EU-wide, establishing an EU Centre on Child Sexual Abuse to coordinate detection technology and forward cases to Europol and national police.
Supporters, including the Commission and some MEPs, argue that the scale of the problem, with over 20.5 million suspected CSAM cases reported in 2024, necessitates stronger measures. They contend that voluntary reporting is too fragmented and that such tools are crucial for prosecuting crimes against children. Lena Düpont, MEP, emphasized that while not the only tool, it is one of the most important for prosecuting online abuse.
However, the proposal faces strong opposition from digital rights groups and privacy advocates. Critics argue that child protection is used as a pretext for mass surveillance, potentially undermining privacy protections guaranteed by the EU Charter. Patrick Breyer, a digital rights activist, points to high rates of false positives from hash scanning, even for known material, and argues that minors are often caught up due to typical teenage behavior. He also highlights that inspecting messages before encryption compromises true end-to-end encryption, creating risks for journalists and whistleblowers.
Breyer suggests alternatives such as proactive and systematic searching of the open and dark internet for known illegal material, and security-by-design features that warn users before sharing sensitive content, without requiring access to encrypted communications. He distinguishes between targeted, court-authorised surveillance of suspects and indiscriminate scanning of all communications.
Supporters counter that existing voluntary tools are insufficient and could be discontinued, leaving law enforcement without crucial tips. They argue for replacing the improvised system with EU-wide rules, judicial authorization, and defined limits, while acknowledging the need for stronger safeguards. Many critics, while supporting child protection, advocate for measures that target specific suspects rather than scanning everyone by default.
