EU Chat Control Law: Scanning Private Messages Until 2028 – What It Means
EU lawmakers approve scanning private chats for child abuse material, but exempt end-to-end encryption.
The European Parliament has approved a regulation that allows tech companies to scan private messages for child sexual abuse material (CSAM), with a temporary exemption for end-to-end encrypted chats until 2028. The law has ignited a fierce debate between child safety advocates and privacy defenders.
What the Law Actually Does
The regulation requires messaging platforms to detect and report known CSAM in private communications. It permits scanning of images, URLs, and text messages, but explicitly exempts end-to-end encrypted content—though only until 2028. During this period, the European Commission must evaluate and propose a technical solution for scanning encrypted messages without breaking encryption.
Supporters' Arguments
- Child safety groups say the law is essential to combat the massive scale of online CSAM, which has surged in recent years.
- EU lawmakers backing the measure argue that voluntary efforts by tech companies have failed, and mandatory detection is the only way to protect children.
- Proponents insist the encryption exemption preserves security while the EU searches for a privacy-preserving scanning method.
Critics' Concerns
- Privacy advocates warn that any scanning of private messages, even for legitimate purposes, creates a surveillance infrastructure that could be expanded.
- Encryption experts argue that scanning content—even client-side—weakens the confidentiality of communications and sets a dangerous precedent.
- Digital rights organizations like EFF and others have called the law 'a backdoor to encryption' and worry it could be used to target other types of content in the future.
The Encryption Exemption: A Temporary Truce
The exemption for end-to-end encrypted chats expires in 2028, giving the EU time to develop a technical solution that enables scanning without breaking encryption. Critics say no such solution exists today without compromising security; supporters point to ongoing research into 'privacy-preserving' detection methods. The law requires the Commission to report on available technologies by 2027.
What to Watch Next
Implementation will now shift to EU member states, which must transpose the regulation into national law. The most critical milestone will be the 2027 Commission report on scanning encrypted content. If no viable solution emerges, the encryption exemption could become permanent—or the law could force a stark choice between eroding encryption or abandoning the mandate for encrypted chats.
Does the EU Chat Control Law ban end-to-end encryption?
No. The law explicitly exempts end-to-end encrypted chats from scanning requirements until 2028. However, critics fear that the exemption is temporary and that future requirements could force platforms to weaken encryption.
What does the law require tech companies to do?
It requires platforms to detect and report known child sexual abuse material (CSAM) in private messages, including images, videos, and URLs. Scanning of unencrypted content is mandatory; encrypted content is exempt until a technical solution is found.
When does the encryption exemption expire?
The exemption is valid until 2028. The European Commission must evaluate detection technologies by 2027 and propose a permanent solution. If no privacy-preserving method is available, the exemption may be extended.
What do supporters say about the law?
Supporters argue it is necessary to tackle the massive scale of online child sexual abuse material. They claim voluntary measures have failed, and mandatory detection—with privacy safeguards—is the best way to protect children.
What do critics say?
Critics argue that scanning private messages undermines privacy and could be expanded to other content. They warn that even client-side scanning creates a surveillance infrastructure and that no truly privacy-preserving scanning of encrypted content exists.