
What Is 'Chat Control'? The EU Plan to Scan Your Messages, Explained
- WeThePurple
- Rights
- 8 min read
Chat Control is the nickname for an EU proposal to detect illegal content by scanning private messages - potentially even encrypted ones. What it actually proposes, why client-side scanning is so contested, what it would mean for your privacy, and where it stands.
"Chat Control" - written as one word, "Chatcontrol", about as often as two - is the nickname privacy advocates gave to a proposed European Union regulation whose official aim is to fight the spread of child sexual abuse material (CSAM) online. The nickname stuck because of how the proposal would work in practice: by having messaging services scan the content people send - including in private chats. It has been debated, redrafted and fought over for years, and as of 2026 it is still not settled.
The reason it matters to anyone who messages, emails or shares files is simple. The most controversial version of the plan would push detection down onto your own device, checking what you send before it is protected by encryption. That is a fundamentally different thing from a company moderating public posts, and it is why the debate has been so heated.
What does Chat Control actually propose?

At its core, the proposal would require certain online services to detect and report illegal material. Where it gets contentious is the method: so-called "client-side scanning," where software on your phone or computer inspects your messages, photos and files against a list of known illegal content before they are sent.
Supporters argue this is a proportionate way to catch serious crime that increasingly hides inside private, encrypted channels. Critics argue that scanning everyone's private messages to find a few is mass surveillance by default, and that once the scanning machinery exists on every device, it can be widened later to other targets.
Why is client-side scanning so controversial?
End-to-end encryption is designed so that only you and the person you are talking to can read a message - not the provider, not the network, not anyone who orders them to hand it over. Client-side scanning sits awkwardly with that promise: if your message is inspected on the device before it is encrypted, the guarantee that "only the participants can read it" no longer fully holds, even if the law never literally bans encryption.
- Chat Control = nickname for an EU proposal to detect illegal content (CSAM) by scanning messages.
- The contested mechanism is 'client-side scanning' - checking content on your device before it is encrypted.
- Critics say it undermines end-to-end encryption and amounts to mass surveillance by default.
- Supporters frame it as a proportionate tool against serious crime in private channels.
- On 9 July 2026, 314 MEPs voted to reject it and 276 to keep it - and it survived, because rejecting a Council position at second reading needs 360 votes, not a plurality.
- Status changes often - verify the current state of the proposal against an up-to-date source.
- Your move regardless: use end-to-end-encrypted apps, update software, and stay informed.
There is also the question of accuracy. Automated detection systems produce false positives, and at the scale of every message in Europe, even a tiny error rate means large numbers of innocent people could have private content flagged and reviewed. Critics worry about who reviews it, where it is stored, and how mistakes are corrected.
What would Chat Control mean for you?
For an ordinary person, the practical concern is not that you have something to hide - it is that private communication is a normal, healthy part of life: medical questions, legal problems, family matters, journalism, activism, ordinary intimacy. A right that only protects you when no one is looking is not much of a right.
Where does Chat Control stand now?
It is worth being precise about status, because the proposal keeps changing. The older voluntary-scanning rules known as 'Chat Control 1.0' were rejected by the European Parliament on 26 March 2026 and lapsed on 3 April 2026. On 2 July 2026 the Council moved to reinstate that lapsed interim measure and apply it until 3 April 2028 - longer than the 3 August 2027 end date Parliament had backed on 11 March 2026, in a vote of 458 in favour, 103 against and 63 abstentions. Parliament's position also held that the rules should not apply to end-to-end encrypted communications, and that detection should cover only material already identified or flagged as suspected abuse.
The second reading came on 9 July 2026, and the arithmetic of that day explains why the file is still alive. 314 MEPs voted to reject the Council's position and 276 voted to keep it - but rejecting a Council position at second reading requires an absolute majority of 360, not simply more votes than the other side. The rejection fell 46 votes short, so the measure survived a vote in which more MEPs opposed it than supported it. In a separate vote that did succeed, Parliament adopted amendments excluding from the scope of the derogation any communication to which end-to-end encryption is, has been, or will be applied.
So the file is not closed, and it was not settled by that vote. The amended text goes back to the Council, which has three months to approve or reject the amendments; if it does not accept all of them, the two institutions move to a conciliation committee. Separately, the permanent regulation often called 'Chat Control 2.0' remained in trilogue negotiations between Parliament, Council and Commission through mid-2026, with the Council favouring broad detection powers and Parliament pushing to limit any scanning to users already suspected of an offence and authorised by a court. Because the text shifts from one negotiation to the next, treat any claim that it has finally passed, failed or been abandoned as something to check against a current source. The encryption carve-out, rather than the end date, is the part that decides what any of this means for ordinary messaging.
What can you do about it?
Whatever happens with the law, the personal response is the same and entirely legal: understand how your tools work and choose ones that minimise what is exposed. Use end-to-end-encrypted apps, keep your software updated, and pay attention to which services hold your data and where.
You can also make your voice part of the democratic process. Proposals like this are shaped by public attention, consultations and elected representatives - privacy organisations across Europe track the file and explain how to follow or contact decision-makers. Staying informed is the single most useful thing most people can do.
The bottom line: "Chat Control" is a real, recurring debate about a genuine problem and a contested solution. The aim - protecting children - is not in question; the method - scanning private messages on personal devices - is. Knowing what the proposal actually says lets you follow the story without the hype, and protect your own privacy in the meantime.



So the file is not closed, and it was not settled by that vote. The amended text goes back to the Council, which has three months to approve or reject the amendments; if it does not accept all of them, the two institutions move to a conciliation committee. Separately, the permanent regulation often called 'Chat Control 2.0' remained in trilogue negotiations between Parliament, Council and Commission through mid-2026, with the Council favouring broad detection powers and Parliament pushing to limit any scanning to users already suspected of an offence and authorised by a court. Because the text shifts from one negotiation to the next, treat any claim that it has finally passed, failed or been abandoned as something to check against a current source. The encryption carve-out, rather than the end date, is the part that decides what any of this means for ordinary messaging.