EU Extends Chat Control Message Scanning to 2028
11 Jul 2026
What happened
The European Parliament has voted to extend Chat Control 1.0, the regulation permitting mass scanning of private communications, until 2028. The vote itself was tight: 314 MEPs voted against continuing the measure, 276 voted in favor, and 17 abstained. Notably, more MEPs voted against the regulation than for it — but under the procedural rules governing this stage, the Council's position could only be blocked by an absolute majority of 361 votes, a threshold that wasn't reached. As a result, the measure passed despite lacking majority support among those who voted.
A separate vote to restrict scanning specifically to suspects identified by judiciary authorities also failed, losing 322 to 255.
Dr. Patrick Breyer, a vocal critic, called the outcome "a farce" that "damages democracy," arguing that Chat Control moved forward against the will of the majority of voting MEPs.
The timeline behind the vote
- End of 2020: Internet-based communication services became subject to strict provisions of the European E-Privacy Directive.
- 2021: A temporary exemption was created, giving rise to Chat Control 1.0.
- April 3: The transitional regulation for voluntary monitoring expired.
- Thursday: The EU Council adopted its position on a new Chat Control regulation via written procedure.
- The following Tuesday: The draft regulation was placed on Parliament's agenda under an urgent procedure.
- Vote result: 314 against, 276 in favor, 17 abstentions — the regulation passed.
- September: Negotiations on a permanent regulation are set to resume.
Under the new rules, processed content and traffic data must be irrevocably deleted no later than twelve months after detection — unless a "concrete suspicion" is confirmed. The report does not specify what legally constitutes a concrete suspicion, leaving that threshold undefined for now.
The numbers raising questions
The report flags data suggesting the scanning system may be inefficient in practice:
- 48% of all incoming alerts to Germany's Federal Criminal Police Office are not criminally relevant.
- 99% of reports generated by Meta are estimated to consist of previously known material.
- 40% of resulting investigations end up targeting minors themselves.
- Mass scanning accounted for 36% of all abuse reports in 2024.
- Since 2022, suspected abuse reports from the US have dropped 50%, attributed to growing use of message encryption.
Under the regulation, US tech companies are permitted to scan private messages across platforms including Instagram, Discord, Snapchat, Skype, Xbox, Gmail, and iCloud.
Voices on both sides
Alexander Hanff, describing himself as a survivor, said confidential communications were essential to his ability to find justice for 28 schoolboys, a case that resulted in convictions of multiple offenders — an argument for why encrypted, unscanned communication channels matter.
Breyer's criticism focuses on the procedural mechanics of the vote itself — noting that the measure advanced despite more MEPs voting against it, due to the absolute-majority requirement for blocking the Council's position.
Sources do not present a formal rebuttal to either position within this report, but the framing throughout emphasizes the tension between child-safety justifications for scanning and privacy/efficacy concerns raised by the vote data.
Why founders should care
For startups building messaging, communication, or social platforms with EU users, this vote likely signals continued and possibly increasing regulatory exposure through at least 2028, with a permanent regulation still under negotiation starting in September. Founders should treat current compliance obligations as provisional rather than settled.
The high false-positive rates reported by German authorities suggest that scanning-based compliance systems may impose meaningful operational overhead — engineering time, review processes, and false-alert handling — without a clear reduction in this report's data on whether such systems are proportionally effective.
Because the vote outcome hinged on a narrow procedural technicality rather than clear majority support, founders planning multi-year compliance roadmaps should treat regulatory direction in this space as unsettled. It is plausible that the permanent regulation, once negotiated, could look meaningfully different from Chat Control 1.0 — but the report gives no indication of what changes are likely.
At the same time, the unresolved status of the permanent framework may create a window for founders to engage in policy conversations now, before final rules are locked in, and to evaluate whether privacy-preserving or encryption-forward product architectures could become a differentiator as user awareness of scanning practices grows.
Open questions
Several important details remain unclear from the current reporting:
- What legal or technical criteria will define a "concrete suspicion" sufficient to prevent data deletion?
- How the permanent regulation negotiations in September will differ from Chat Control 1.0.
- Whether smaller or non-US messaging providers face different or additional obligations.
- How compliance costs and technical requirements will be enforced across platforms of varying size.
- What recourse users or companies have if scanning systems generate errors.
Founders operating in this space should watch the September negotiations closely, as the permanent regulation could reshape compliance requirements in ways not yet visible from Chat Control 1.0's extension.