By Maria Entuc
On 26th November 2025, the Council of the European Union finally reached an agreement on something that has haunted European tech policy for more than three years: mandatory scanning. As part of the European proposal on The Regulation to Prevent and Combat Child Sexual Abuse (Child Sexual Abuse Regulation or CSAR), its desired outcome was to reduce the risk that illegal material circulates online, by enabling authorities to block and remove it.
The agreement reached was based on a risk assessment obligation for online service providers and the possibility of maintaining content scanning on a voluntary basis. Such revisions deviate from the Commission’s original framework (COM(2022) 209 final), which required the scanning of private end-to-end encrypted messages. Gone was the requirement that platforms like WhatsApp and Signal scan every private message on a user’s phone before it was encrypted.
Nevertheless, the decision to abandon required scanning is not what it appears to be. It’s a more nuanced and challenging version of the same idea that relies more on incentive design than on legal coercion. Where the earlier proposal would have compelled scanning, the current framework instead constructs a regulatory environment in which ‘not scanning’ becomes the disadvantageous choice.
Providers remain formally free to decline detection activity, but why would they?
In this way, criminal justice is being privatized. The algorithms of corporations may decide which user is a suspect or not, since there are no transparency requirements for the algorithms used. Furthermore, the proposed legislation includes the authority to order adjustments to mitigation measures, and the power to restrict user access to the service altogether.
The distinction between a provider being formally permitted to scan and a provider being practically advised to scan collapses under these conditions.
A quick rewind: the 2021 Interim Regulation was introduced as a temporary derogation from the ePrivacy Directive. Known by critics as “Chat Control 1.0”, it created a limited legal framework under which providers of independent interpersonal communications services could continue voluntary detection, reporting, and removal of child sexual abuse material (CSAM). In 2022, the European Commission proposed a permanent successor (the CSA Regulation, known as “Chat Control 2.0”) built around mandatory detection orders of client-side scanning, including encrypted services. In November 2025, after sustained protest, the Council removed the mandatory detection obligation from its negotiating mandate, dropping client-side scanning from the Council text in favor of a compromise centred on voluntary detection and risk-mitigation obligations.
Meanwhile, the interim voluntary regime kept needing to be renewed, and renewal kept nearly failing. Having already been extended once in 2024 to April 2026, the European Parliament rejected a second extension in March 2026, and the derogation lapsed on 3 April 2026, leaving platforms without a legal exemption to scan. That lapse didn’t hold: the Council pushed through an emergency revival in late June/early July 2026. On 9 July 2026 Parliament passed the reinstated “Chat Control 1.0” through an unusual procedure requiring an absolute majority to block it, one where more present members voted against it than for it, but it passed anyway because absentees counted as yes votes. Voluntary scanning is now extended until April 2028, while the permanent framework (2.0) remains stuck after trilogue talks collapsed in June 2026, with negotiations expected to resume around September 2026 under the incoming Irish presidency.
The word ‘mandatory’ that vanished for now from this debate gave relief to the press and political classes, as if the core issue had been defused. However, the infrastructure of mandatory scanning did not disappear from the 2025 adopted negotiating mandate. Consequently, the ‘voluntary’ clause is sitting inside a framework that empowers authorities to demand risk assessments, order mitigation measures, and threaten platform access restrictions for non-compliance is voluntary in name only if the practical cost of not scanning keeps rising. Further, the persistence of large-scale scanning by major platforms even after the legal derogation briefly lapsed in April 2026 is itself suggestive. After all, digital services providers operate under commercial, political, and now regulatory incentives that make scanning look less like a choice with each passing year. For instance, Google, Meta, Microsoft, and Snap continued their scanning of private messages according to their own statements even after the legal basis had lapsed.
None of these tensions are new to this debate. What’s new is how little attention they’re getting now that the word ‘mandatory’ is gone. And nearly four years into this fight, there is a question that actually matters now: when does ‘voluntary’ stop meaning voluntary?
Background: from 2021 Temporary Derogation towards 2026 Updates
The debate originated with the direct response to the dramatic increase in online child sexual exploitation, based on numbers that are genuinely hard to look away from. According to a 2020 Communication from the European Commission, reports of child abuse online concerning EU victims have dramatically increased over the last few years: “23 000 in 2010 to more than 725 000 in 2019”, with a majority hosted on EU servers. Faced with pressures, the European Commission introduced the 2021 temporary derogation (Regulation 2021/1232), also referred to as “Chat Control 1.0” by critics. It allowed providers to voluntary scan messages and content to detect child sexual abuse material (CSAM), as an exception to the ePrivacy rules on confidentiality of communications.
This derogation was intended as a bridge measure and has been extended several times until its expiration on 3rd April 2026. The reason was because the permanent legislation proposed by the Commission in 2022, which shifted from voluntary detection to blanket obligations for detection, reporting, and removal, including potential orders targeting encrypted services, was unable to reach a consensus in the EU institutions until November 2025.
The 2022 proposal was based on four pillars. First, every major platform (messaging apps, app stores, cloud services) would be required to conduct its own risk assessment once a year. Second, if a court or independent authority judged that risk significant enough, it could order the company to scan every single message passing through its service, regardless of whether the apps are protected by end-to-end encryption. The inspection would happen directly on a user’s personal phone, examining the content before it was ever locked behind encryption, by building a checkpoint into the device itself. Third, a new EU Centre would be implemented to maintain databases of known abusive material and build detection tools for platforms to deploy. Fourth, an additional set of child-protection measures would be considered, such as mandatory age verification, restrictions on which apps minors could access, and a requirement that privacy settings default to their strictest form.
It became one of the most invasive digital surveillance proposals a democracy had ever proposed. Critics feared it would breach encryption and turn every phone into a surveillance device, which further led to years of debates between European institutions. The European Parliament’s Civil Liberties (LIBE) committee voted in November 2023 to protect end-to-end encryption and demand scanning be “a last resort”. In 2025, Germany blocked the Council draft that kept mandatory orders alive. Based on a post on X, the Federal Justice Minister Stefanie Hubig stated: “Germany will not agree to such proposals at the EU level”. By November 2025, the phrase “mandatory scanning” was deleted from the Council’s negotiating text.
The 2025 ‘Mandatory’ Compromise
What the November 2025 text established as mandatory was based on three pillars: risk assessment, mitigation measures, and voluntary scanning. Within this framework, ‘high-risk’ services must adopt mitigation measures. Although scanning isn’t required, it is listed as one option among several a company might choose. Paragraph 17 states that “providers are free to design and implement, in accordance with Union law, measures based on their existing practices to detect online child sexual abuse in their services and indicate as part of the risk reporting their willingness and preparedness to carry out voluntary activities under Regulation (EU) 2021/1232”. Nonetheless, digital providers that choose to scan get something valuable in return, which is funding for detection technology (paragraph 27) and a more favorable risk score (Article 27). Additionally, according to Article 35, companies that fail to comply with an obligation from the Regulation, face a higher chance of being labeled high-risk, with regulatory scrutiny and potential fines that label carries if abuse material later surfaces on their platform.
The question that arises is whether this architecture is meant to be the permanent shape of EU policy in this area.
If voluntary scanning itself becomes an indefinite feature of the law, it would mean that the interim permission in which companies have been operating under for years will never expire. Alongside it, the EU Centre gets built, gathering lists of known abuse images, handing companies detection tools and funding to deploy them, and coordinating the removal of flagged material across borders.
As aforementioned, a platform technically retains the legal right to refuse. But the practical cost of refusal means worse regulatory standing, no funding, no legal shield, and public exposure the moment something goes wrong. Thus, making that refusal expensive enough that few companies will actually exercise it. Andy Yen, CEO of Proton, and Dr. Patrick Breyer, a privacy advocate and former MEP, have already given this arrangement a name: “mandatory scanning through the back door.”
What the Law Looks Like in August 2026
To be fair to the process, something did alter this year. The interim law that had allowed voluntary scanning lapsed on April 3, 2026, after Parliament rejected a Commission proposal to extend it and closed its first reading. Further, on 2 July, the Council sent the matter back to Parliament for a second reading. On July 9, MEPs voted to support a narrower extension: scanning tools should apply only to material already flagged as abusive, target users under judicial suspicion rather than the general population, and, most importantly, to exclude the end-to-end encrypted communications entirely. On July 24, the European Parliament and the Council passed a renewed interim framework (Regulation (EU) 2026/1881), permitting providers to voluntary scan until April 2028.
This regulation blurred the line between protection and control, turning private devices into potential informant points.
However, the permanent regulation, the successor to the original 2022 proposal, is still being negotiated in trilogue, and the underlying tension that the interim law avoided has not been resolved, only postponed. Most of the substantive terms persist, remaining deadlocked in institutional negotiations. For now, the risk-based incentive architecture remains the leading model on the table for that permanent text. Whether it survives negotiation with the same encryption exemption Parliament fought for in July is genuinely unknown.
Unresolved Fundamental Rights Tensions
None of this is an argument that Europe should abandon the fight against online child abuse. The scale of the problem, documented by the Commission, much of the content now being AI-generated, is something very serious that needs to be mitigated.
The problem is: European lawmakers have spent three years fighting the wrong battle. They fought hard over whether scanning could be mandatory, and won a victory in getting that word struck from the text. They have fought far less over whether a system can be built to produce mandatory-style compliance without ever using the word. And if the answer is yes, then the victory over “Chat Control” was mostly a facade.
Assedel, a non-profit organisation, studying the files have flagged this ambiguity directly, noting that voluntary detection now overlaps so heavily with risk-mitigation duties that in practice it may function much like the mandatory system it replaced.
And that system clashes with several other fundamental rights. For instance, Encryption Policy Lead Namrata Maheshwari, civil society group EDRi, and privacy advocate Patrick Breyer explained the dangers of such regulation.
The risk-mitigation duties written into Article 4 of the Council draft requires providers to regularly assess and address their exposure to abuse material: “they shall take all reasonable mitigation measures, […] to effectively minimise that risk.”
Based on the description above, it creates exactly the kind of indirect pressure to scan. There are different legal issues arising from this description of ‘risk mitigation’, as its lack of clear boundaries makes compliance difficult to assess. In addition, it may be in conflict with Articles 7 and 8 of the EU Charter about privacy and data protection, which are important legal issues.
Furthermore, Article 5.2 introduces the classification of digital communication services based on risk category (High, Medium, and Low). Consequently, it strongly incentivizes companies to employ such ‘voluntary’ scanning. The scope of permitted scanning extends the practice of provider’s discretion across text and metadata, including keyword-based textual analysis intended to detect grooming behavior. Layered on top of that is the technical reality of automated detection at scale. Patrick Breyer pointed out that these systems are prone to false positives, and researchers have warned that already disadvantaged communities, whose data may carry markers that automated tools can mistake for risk indicators, may end up being flagged disproportionately. For instance, natural-language classification of this kind struggles to reliably distinguish between criminal intent, humor, sarcasm, and ordinary conversational speech, which produces a structural risk of large-scale false reporting and a corresponding chilling effect on protected expression. As Patrick Breyer states “These technologies are notoriously unreliable and can recognize neither age nor consent”. It may become a pattern of uncomfortable echoes of predictive policing’s track record of targeting minority populations.
Moreover, by adding mandatory age and identity verification, the law collides with the GDPR’s own data-minimization principle. The enforcement of age-based restrictions would require most users to authenticate their identity, via government identification or biometric facial verification. Besides the fact that it collects more personal data than the stated purpose requires, such a requirement disproportionately burdens categories of users for whom anonymity is necessary to safety. Vulnerable people may be: whistleblowers, investigative journalists, and individuals seeking help for sensitive personal circumstances such as abuse, addiction, or persecution.
And the paradox: any deliberate weakening of encryption for detection purposes doesn’t just open a door for regulators, it opens the same door for hackers and hostile states, potentially undermining the security of the exact communications systems the law is meant to protect.
Conclusion
Does the end justify the means? It is not rhetorical to say so. Regardless, the debate of whether scanning of private messages should be mandatory is still being fought over.
The ‘new’ interim regulation (Regulation 2026/1881), identical in content with the expired derogation (Regulation 2021/1232), was adopted and will continue until 2028. While the temporary law passed, the permanent one remains deadlocked after several trilogue rounds. The negotiators cannot agree on making permanent scanning, leaving the talks to continue in September 2026, under the Irish presidency.
The question we should address is unresolved: how much coercive weight a formally voluntary system can carry before it becomes mandatory in substance rather than name?
There are many alternatives to this serious issue, and mass surveillance is the wrong approach to fighting CSAM and sexual exploitation. Below, I have added three recommendations.
1. Minimize unnecessary personal data collection. Age verification and identity checks should be scoped as narrowly as the underlying risk demands, not applied as a blanket requirement across every user of every platform. Any verification system adopted should be evaluated against the GDPR.
2. Define “voluntary” in law. Negotiators should write explicit statutory limits on how much a company’s risk score, funding, or legal protection can depend on whether it scans or not. The current phrasing is deemed coercive.
3. Treat false positives as a design issue. Every scanning system deployed under the regulation should route flagged content through human review before referral to law enforcement, and detection tools should undergo regular, independently audited bias testing. This is especially important for protecting marginalized communities from being disproportionately flagged, as researchers have already warned.
Header Source: Camilo Jimenez on Unsplash https://unsplash.com/photos/people-using-phone-while-standing-qZenO_gQ7QA
