Two 'Chat Control' laws, not one: why the EU's message-scanning fight looks contradictory
The confusion around “Chat Control” comes from there being two separate EU proposals moving at once. Chat Control 1.0 was Regulation (EU) 2021/1232, a temporary, voluntary carve-out from the ePrivacy Directive that let providers — mostly unencrypted US services like Gmail, Messenger, Skype, and iCloud Mail — scan private messages for child sexual abuse material. Parliament refused to extend it, and it legally expired on 4 April 2026. Rather than accept that, the Council is now attempting an unprecedented fast-track revival: because an expired regulation can’t be extended, it is pushing a formally “new” law with identical content through an expedited procedure. A Parliament urgency vote on that revival is imminent, and if urgency passes the measure could be treated as a second reading, requiring an absolute majority of all MEPs to stop or amend it — a deliberately high bar.
Chat Control 2.0 is the CSA Regulation (CSAR), a permanent proposal that would make detection and reporting of abuse material a legal obligation for platforms. The original Commission version, unveiled by Ylva Johansson in 2022, would have required bypassing end-to-end encryption. The Council’s 2025 position softened mandatory detection orders into “voluntary” suspicionless scanning plus broad risk-mitigation duties that critics say incentivize scanning anyway; Parliament insists scanning be limited to specific suspects under a court order. Encryption remains the red line, and inclusion of end-to-end encrypted messengers is still unresolved.
The stakes are underscored by the Council’s own Legal Service, which warned that the “voluntary” model still amounts to generalized scanning incompatible with Article 7 of the EU Charter absent reasonable suspicion and judicial authorization. Five trilogue rounds have failed; the supposedly final session on 29 June 2026 collapsed over suspicionless scanning, and talks now continue under the Irish presidency. Meanwhile Google, Meta, Microsoft, and Snap have said they will keep scanning regardless of 1.0’s expiry — meaning the legal fight and the operational reality have diverged.
Read the full article
Continue reading at Hacker News →This is an AI-generated summary. Read the original for the full story.