The only good thing is that end-to-end encrypted messaging services such as Signal are temporarily safe. However, this law fundamentally threatens encryption and citizen safety. There is something you can do about that:
The only good thing is that end-to-end encrypted messaging services such as Signal are temporarily safe. However, this law fundamentally threatens encryption and citizen safety. There is something you can do about that:
Chat control is specifically about scanning chats to see if there’s no CSAM. That’s mass surveillance (one that child protection services and such don’t think’ll work).
E2E-protection means nothing when the scanning is done on the client.
That’s what Chat Control 1.0 is about and the scanning is voluntary. Here is the text of Chat Control 2.0: https://data.consilium.europa.eu/doc/document/ST-15318-2025-INIT/en/pdf
Can you point me to the part about scanning chats? Because the entire text doesn’t even contain the word ‘scan’. It barely mentions CSAM or chats. It does say:
So detection is still specifically voluntary and e2e encryption protected. Which part of this document introduces mandatory chat scanning? But please, point me parts of the document, not some vague blog posts. I’m not saying it’s not there, just that I read it and didn’t find it. If you’re claiming it’s there I’m sure you will be able to show it.
You’re right, it doesn’t use the word “scan”, it uses “detect”. It doesn’t say “chat”, it says “interpersonal communication”. There are 335 mentions of “child sexual abuse”, I wouldn’t call that “barely mentions”. All of it is mentioned in the opening paragraph as background info.
Detection obligations have indeed been removed since the linked document (it wasn’t before that, as you can see in that same document, page 3), thanks to the EP, but it still provides the legal framework for companies to do so anyway, without any reasonable suspicion. That’s already bad enough.
Moreover, there are mitigation obligations:
Mitigation is very hard to do without identifying it. For that you’ll have to detect it in some way, f.e. by scanning chats, which you are allowed to do through this. Scanning might not be the only way (though I can’t think of another way), but it is the easiest way.
Authorities can adjust the risk assessment themselves.
Very ironic. The ruling class and elites are excluded.
E2EE protection is nice, but pretty irrelevant. With clientside scanning, the E2EE is not broken, because your device has already decrypted it. It simply negates E2EE
This EU explainer, puts the document in simpler language: https://www.consilium.europa.eu/en/press/press-releases/2025/11/26/child-sexual-abuse-council-reaches-position-on-law-protecting-children-from-online-abuse/
How would a chat company do such a thing without scanning chats?
But, even if all of it was fully voluntary (what chat control 1 more or less is), it’s still really bad. Why do we want to give companies the legal right to scan everything we do on their platforms?
I recommend taking a look at Patrick Breyer’s site (ex-MEP for the Pirate Party) and the EDRi.
Ok, thanks. So hopefully you will stop spreading misinformation that in introduces mandatory scanning now.
Did you read the rest of my comment?
Voluntary scanning is bad enough, but it still introduces mandatory mitigation, which may as well be the same thing as mandatory scanning in all but name.
That’s why people are still up in arms about it.
You said:
You’re right, Chat Control 2.0 will make client side scanning more difficult to avoid but it’s still just client side scanning, not breaking encryption and it’s still only specific mitigation for sharing CSAM and part of broader evaluation. Services that are not likely to be used to share CSAM will not be forced to mitigate anything. Another mitigation could simply be disabling sharing of media - text messages will not have to scanned. So we’re basically talking about checking hashes of shared media against some database in some of the services and not “permanent, mandatory scanning of everything including encrypted stuff”.
I’m not saying you have to like and support Chat Control 2.0. I’m not even saying it’s harmless legislation. Just admit it’s not about “permanent, mandatory scanning of everything including encrypted stuff”.
I did not. I responded to the comment that said that. I said that they kept bringing CC2.0 back.
I did also say that it’s specifically about scanning, but that’s indeed not entirely accurate. That’s part of it, but it’s broader than that.
Not sure what you mean by “still just”. Client side scanning just sidesteps encryption, making the encryption useless. It’s like saying “we’ll never open your posted letters in transit, but we’ll look over your shoulder while you write/read it”.
Sure, but chat apps are pretty likely, no? And authorities are allowed to adjust the risk assessments.
I mean, sure, but that doesn’t seem like a feasible solution. People’d just leave that platform. Imagine if WhatsApp blocked sending images or files.
This wouldn’t catch new CSAM though (thus not protecting children).