EU Chat Control: Scanning Law Expires, Fight Continues
16 Jul 2026
The temporary rules are dead — the permanent ones are stuck
The EU's years-long fight over scanning private messages for child sexual abuse material (CSAM) has hit a messy inflection point. Regulation (EU) 2021/1232, which created a temporary ePrivacy Directive exception allowing platforms to voluntarily scan private communications for CSAM, has legally expired. Cyberinsider dates this to 4 April 2026; heise similarly says it expired "in April," though the two sources describe the surrounding rejection vote slightly differently (heise says Parliament rejected extension "in March and April," cyberinsider says the rejection happened in March).
This so-called "Chat Control 1.0" derogation was originally set to expire 3 August 2024, got pushed to 3 April 2026, and then finally lapsed. In practice, it mainly applied to unencrypted US services — Gmail, Facebook/Instagram Messenger, Skype, Snapchat, iCloud Mail, and Xbox messaging. Notably, Google, Meta, Microsoft, and Snap have all said they'll keep scanning private messages regardless of whether the legal derogation exists — a signal that de facto industry practice may not track the legislative timeline at all.
Meanwhile, the intended replacement — a permanent regulation dubbed "Chat Control 2.0", originally proposed by then-Home Affairs Commissioner Ylva Johansson to make CSAM detection and reporting a legal requirement — remains unresolved after five rounds of trilogue negotiations between Parliament, Council, and Commission. The fifth round, billed as final, collapsed on 29 June 2026.
A chaotic vote count
The legislative back-and-forth has been genuinely volatile:
- LIBE committee rejected an extension, 38–28.
- Parliament later passed a compromise extension with protective conditions, 458–103.
- A separate vote saw 311 MEPs vote against extending the derogation, 228 in favour, with 92 abstentions.
- An amendment rejecting automated assessment of unknown photos and texts (Amendment 34) passed by a razor-thin 307–306.
- An urgency-procedure vote to fast-track revival of the expired rules passed 331–304 (heise reports 11 abstentions; cyberinsider does not mention any).
Under that expedited procedure, opponents now need an absolute majority of 361 votes to reject or amend the revived proposal — a notably high bar. The Council approved its own negotiating position on 2 July, and a decisive vote on allowing voluntary CSAM scanning is scheduled for 9 July (cyberinsider). Heise references a Parliament vote "on Thursday," the last session before summer break — it's unclear whether this is the same date.
Legal and technical warnings pile up
Several serious objections are on the table:
- The Council's own Legal Service has warned that voluntary generalized scanning may breach Article 7 of the EU Charter of Fundamental Rights absent reasonable suspicion and judicial authorization.
- IT security researchers have flagged high error rates in AI-based CSAM detection tools, raising the risk that non-offending users' private communications get flagged and exposed.
- Opposition MEPs allege procedural manipulation. Pirate MEP Markéta Gregorová accused the European People's Party of a procedural "farce" and rule violations. Rapporteur Birgit Sippel called the move an "unfair maneuver" by EU countries and withheld her support. MEP Patrick Breyer described the Council's action as an "unprecedented attempt" to revive legislation Parliament had already rejected.
Sources differ on some procedural details — including exact vote dates and abstention counts — but agree the process has been unusually contentious and legally fraught.
Why founders should care
For early-stage teams building messaging, communication, or social products with EU users, this saga is more than political theater:
- Regulatory uncertainty is likely to persist. Given the repeated cycle of expiration, extension, and collapsed trilogues, it's plausible that compliance requirements around message scanning won't stabilize for some time — founders should probably avoid betting product architecture on any single expected outcome.
- Legal challenges may follow even if the law passes. With the Council's own Legal Service flagging likely Charter incompatibility, there's a reasonable chance that any passed regulation faces court challenges post-enactment, which could mean further delays or amendments down the line.
- De facto scanning norms may outlast the legislation. Since major platforms (Google, Meta, Microsoft, Snap) say they'll continue scanning regardless of the legal derogation's status, founders competing with or interoperating with these platforms should expect scanning-adjacent expectations from users, partners, or regulators even without a finalized law.
- Narrow margins suggest volatility, not settlement. Votes decided by a single seat (307–306) indicate the substantive requirements — what must be scanned, how, and under what safeguards — remain highly contested. Startups should favor flexible, modular compliance architectures over rigid one-time builds.
- There may be a market opening. Uncertainty around mandatory scanning could increase demand for privacy-preserving or on-device detection technology, and for messaging products that differentiate on user trust. Compliance-focused consultancies serving EU digital regulation may also see increased demand as platforms try to navigate the shifting landscape.
What's still unclear
Several open questions remain unresolved in current reporting: the exact legal text and safeguards in the Chat Control 2.0 draft after the collapsed fifth trilogue, how individual member states voted on the Council's 2 July negotiating position, and what the law would mean concretely for encrypted messaging services. It's also unclear whether the "Thursday" vote referenced by heise is the same as the 9 July vote cited elsewhere. Founders operating in this space should treat the coming weeks as a period of active monitoring rather than settled compliance planning.