edit: How will it work in practice? Say I make some Open Source messaging app. Now I need to add some/the government approved algorithm to detect malicious content and then feed this to some government instance. I guess the government will provide me some key/certificate to ensure that my reports of malicious content are legit. But how will this work if this is public, the signing stuff can be abused to file false reports. I have no clue how this will work in practice. The death of Open Source email, chat and messaging apps?