This is about a new temporary measure to legally allow instant-messaging providers to scan their users' messages. Providers lost that legal right when the previous interim act (the Interim Derogation of the ePrivacy Directive, sometimes called "Chat Control 1.0") expired on 4 April 2026. Several large providers have said they'll keep scanning regardless.
This is only one piece of a bigger effort. For years the Commission has been trying to put a more permanent regime in place (the CSA Regulation, or "Chat Control 2.0") without success.
As both a lawyer and a software engineer, I don't understand why big tech and EC want to scan messages, if they actually want to combat online abuse. The research points the other way:
- Most messages on these services are end-to-end encrypted, so they can't be scanned at all (assuming the E2EE is implemented correctly). The Commission itself says 70% of messages on popular chat platforms are E2EE [1].
- Instant messaging isn't the main distribution channel for CSAM in the first place, per data from the US National Center for Missing and Exploited Children [2].
So the evidence points to low overall efficacy for message scanning against its stated goal of combating online child sexual abuse.
I don't think it'll pass this time. What worries me more is the spread of mandatory age-verification laws worldwide. That train is already going full steam ahead..
[1] https://home-affairs.ec.europa.eu/policies/internal-security...
[2] Page 18, https://eur-lex.europa.eu/legal-content/EN/TXT/PDF/?uri=CELE...