Law & News Tracker

EU "Chat Control" (CSA Regulation)

Advancing European Union Updated

Actively moving — committee votes, markups, or floor action.

The EU’s Child Sexual Abuse Regulation (CSAR) — dubbed “Chat Control” by its critics — is the most consequential encryption fight in Europe. Its goal, stopping the spread of child sexual abuse material, is unarguable. Its proposed method, scanning private messages, is what has security experts, privacy groups, and several member states alarmed: you cannot build a system that scans “just the bad messages” without building the capability to scan all of them, which undermines end-to-end encryption for everyone.

What it would do

The regulation would let authorities issue “detection orders” requiring messaging and hosting services to scan users’ content for known and new abuse material — and, in some versions, for grooming. Because the messages targeted are often end-to-end encrypted, complying in practice tends to mean client-side scanning: inspecting content on your own device before it’s encrypted. Critics argue that’s a backdoor by another name, and that once the scanning infrastructure exists it can be repurposed for other content.

Where it stands (mid-2026)

Two things are happening at once:

The old voluntary regime expired. “Chat Control 1.0” — a temporary rule that allowed providers to voluntarily scan — was up for extension. The European Parliament rejected the extension 311–228 on March 26, 2026, and the voluntary framework legally expired on April 3, 2026. For the moment, mass scanning lost its legal basis in the EU.

The permanent regulation is in its final stretch. The mandatory version (“Chat Control 2.0”) is in trilogue — closed negotiations between the Parliament, Council, and Commission. The fifth and expected-final trilogue was held June 29, 2026 under the Cyprus Council presidency. In the Council, a qualified majority (23 member states) backs the proposal, while Czechia, Italy, the Netherlands, and Poland formally oppose it. An earlier demand for mandatory client-side scanning was dropped in late 2025; the remaining fights are over age verification, hash-matching of known material, and how “voluntary” scanning really is.

Timeline

  • 2022 — European Commission proposes the CSA Regulation.
  • Late 2025 — Council drops the explicit mandatory client-side-scanning requirement amid pushback.
  • March 26, 2026 — Parliament rejects extending the voluntary Chat Control 1.0 (311–228).
  • April 3, 2026 — Voluntary scanning regime legally expires.
  • June 29, 2026 — Fifth trilogue on the permanent regulation; Council holds a qualified majority in favor, four states opposed.
  • Now — Negotiators seeking final political agreement.

What it means for you

If a scanning mandate survives trilogue, the apps you use for private conversations could be required to inspect your messages, weakening the encryption that protects everyone — journalists, activists, businesses, and ordinary people alike. The practical defense doesn’t change: prefer end-to-end encrypted messengers, and support the organizations and member states resisting mandatory scanning.

Where to follow it: European Digital Rights (EDRi) tracks the negotiations closely, and the EFF covers the encryption stakes. We’ll update this entry when the trilogue concludes.