All NewsEducationTV
Equities & FundsCrypto & Digital AssetsAI & TechnologyBusiness & CorporateUS Politics & PolicyGeopolitics & Global RiskMacro, Rates & FXCommodities & EnergyEuropean Politics & MarketsAsia-PacificReal Estate & Property
Story archiveAll categories
← All Stories

EU's 'Chat Control' proposal: Scanning private messages for CSAM

Created at 30 Jul · 5:51 AM1 source↑ Market-relevant
IN SHORT

The EU's 'Chat Control' debate centers on detecting child sexual abuse material (CSAM) in private messages. While current voluntary measures and a permanent proposal are being negotiated, the key unresolved question is whether encrypted chats will be scanned, raising significant digital rights concerns.

✉Newsletter

PiQ Daily

Pick your topics. Get only what matters, on your cadence.

Key Numbers

2028expiration of temporary regulation
50 percentfalse positive rate in German reports

Who's Involved

Patrick Breyer
digital rights activist, jurist, and former MEP
European Parliament
negotiating the permanent 'Chat Control 2.0' proposal
European Commission
proposing digital rights legislation
EU's 'Chat Control' proposal: Scanning private messages for CSAM

↳ Why This Matters

The EU's 'Chat Control' debate highlights a critical tension between combating online child exploitation and protecting fundamental digital privacy rights. The outcome of these negotiations could set a precedent for mass surveillance of private communications across Europe and potentially globally, impacting how secure messaging services operate and how users communicate online.

Key facts

  • The EU is debating 'Chat Control' legislation to detect child sexual abuse material (CSAM) in private messages.
  • Current regulations allow voluntary scanning of private messages for CSAM, with exceptions for end-to-end encrypted services.
  • A permanent proposal, 'Chat Control 2.0', is being negotiated, and its impact on encrypted communications is a central issue.
  • Detection methods include hash matching and AI-driven text analysis, which critics argue have high false positive rates.
  • Client-side scanning on devices is proposed for encrypted services, raising privacy concerns.
  • Digital rights advocates propose targeted scanning based on court orders rather than mass surveillance.
  • The European Union is grappling with the implications of its proposed 'Chat Control' legislation, which aims to combat child exploitation online by scanning private digital communications. The core of the debate lies in how to achieve this without undermining the privacy of legitimate user communications, particularly those protected by end-to-end encryption.

    Currently, a temporary regulation allows platforms to voluntarily scan private messages for child sexual abuse material (CSAM) until 2028. However, this does not apply to end-to-end encrypted services like Signal or WhatsApp in the same manner as other platforms. A more permanent proposal, dubbed 'Chat Control 2.0', is still under negotiation, with the critical question remaining whether it will extend to scanning encrypted chats.

    Detection tools primarily use hash matching, which compares content against a database of known illegal material, or machine-learning classification to identify grooming language patterns. Patrick Breyer, a digital rights activist, argues that both methods are prone to high rates of false positives, citing German figures where over 50% of reports were not criminally relevant. He also points to issues with how databases are vetted against European law.

    For end-to-end encrypted services, where providers cannot access messages after encryption, scanning would need to occur on the user's device before encryption is applied, a process known as client-side scanning. This is a major point of contention, as it involves inspecting messages while they are still readable.

    After a match is flagged, it is typically reviewed by human moderators before being reported to authorities. However, Breyer contends that this review process is also flawed, with varying legal standards and misclassifications of ordinary teenage communications. He advocates for scanning only when an independent court confirms reasonable suspicion, comparing it to a warrant for opening mail, rather than mass scanning.

    As an alternative, Breyer suggests proactive scanning of the open and dark web for known illegal material and implementing 'security by design' features that warn users before sharing sensitive content, without the content leaving their device. For now, the fate of private messages under 'Chat Control' depends on the app used, but the ongoing negotiations for a permanent proposal could significantly alter this landscape.

    Frequently asked questions

    'Chat Control' refers to proposed EU legislation aimed at detecting and combating child sexual abuse material (CSAM) in digital communications. The debate centers on how to achieve this without compromising user privacy.

    Tools use hash matching to compare content against databases of illegal material or machine-learning classification to identify suspicious language patterns. For encrypted services, client-side scanning on devices is a proposed method.

    Concerns include the potential for mass surveillance, high rates of false positives leading to wrongful accusations, and the undermining of end-to-end encryption and digital privacy.

    This is the central unresolved question. Current temporary rules largely exempt encrypted services, but the permanent proposal's scope for encrypted chats is still under negotiation.

    What Happens Next

    01Negotiations on the permanent 'Chat Control 2.0' proposal are ongoing.
    02The scope of the legislation regarding encrypted chats remains to be determined.

    Get the newsletter.

    Pick the topics you actually care about. We'll email when there's news worth your time, on the cadence you choose. Cancel any time from your account.

    Cadence

    How It Developed

    A temporary EU regulation allows platforms to voluntarily scan private messages for CSAM until 2028.
    This regulation does not apply to end-to-end encrypted services in the same way as other platforms.
    A permanent proposal, 'Chat Control 2.0', is under negotiation, with its scope for encrypted chats undecided.
    Detection methods include hash matching and machine-learning classification for text patterns.
    Digital rights activists argue these methods have high false positive rates and lack legal assessment of intent.
    On encrypted services, scanning would require client-side scanning before messages are encrypted.
    Flagged content is typically reviewed by human moderators before being reported to authorities.
    Activists propose scanning only upon court confirmation of reasonable suspicion, not bulk scanning.

    Sources

    T1
    What happens to your private messages under ‘Chat Control’?Euronews

    Related Stories

    Eiopa faces credibility questions after IT security audit
    30 Jul · 3:37 AM
    Trump considering AI controls after cybersecurity incidents
    30 Jul · 12:51 AM
    Australia sues Telegram over alleged failure to remove 'pro-terror' material
    30 Jul · 3:07 AM
    Hackers steal sensitive data from Department for Education and police
    29 Jul · 7:21 PM
    Trump's Mail Ballot Scrutiny Puts Postal Service at Center of Midterm Elections
    29 Jul · 10:36 AM