Policy & Regulation
The EU Moves to Revive Private-Message Scanning, and the 'We Can't Read Your Messages' Promise Is on Trial
Published: 2026-07-09
What Happened
On July 7, 2026 the European Parliament voted 331 to 304 to adopt an urgency procedure. That route skips the committee stage and sends the file straight to a plenary vote, which is now scheduled for Thursday, July 9. To reject the proposal, opponents need not just more votes but an absolute majority of all members, 361 votes. That threshold favors the side pushing the rules through.
What is being revived is a temporary regulation that let platforms scan user communications to detect child sexual abuse material (CSAM). Parliament refused to extend it in March (311 against, 228 for, 92 abstentions), so it lapsed in early April 2026. The moment it lapsed, the ePrivacy exemption that services like Gmail, Messenger, Instagram, WhatsApp, iCloud Mail, and Snapchat had relied on for voluntary scanning disappeared. This week’s vote would switch that exemption back on, running to 2028. In parallel, the permanent regulation, the CSAR (nicknamed “Chat Control 2.0”), has been stuck through five rounds of trilogue since 2022. In early July the Council approved its own negotiating position, favoring broad scanning untethered from any specific suspicion, meaning content checked on the device itself. Parliament wants to narrow this to detection orders against named suspects with judicial authorization. The EU Legal Service warned in June that even “voluntary” generalized scanning may breach Article 7 of the EU Charter without reasonable suspicion and prior judicial sign-off.
What It Means for Founders
For anyone selling messaging or privacy, end-to-end encryption has long been the differentiator. “We can’t read your messages” was both a marketing line and the basis of trust. Device-side scanning attacks the root of that line. It plants a scanner on the user’s device and inspects content before the message is encrypted. The encryption stays intact, but the inspection finishes ahead of it, so “we can’t read it” becomes conditional on a legal carve-out. The threat model shifts too. What you now have to keep out is not only external attackers, but a scanner the regulation asks you to embed inside your own stack.
The immediate vote revives voluntary, not mandatory, scanning. But EFF and other watchers already flag how “voluntary” hardens into a de facto expectation: once a service that declines looks like the suspect one, voluntary is a label with nothing behind it. If you serve EU users, assume detection orders, age verification, and mandated hash-matching could land on top of your product at any point. The bigger risk is the uncertainty itself. The rule lapsed, then came back; an urgency procedure skips scrutiny; the legal basis flips within months. If your product touches private communication in the EU, that churn alone is a variable that shakes your roadmap. What stings most is that on-device-only design, no server-side keys, and metadata minimization still do not escape a client-side scanning mandate.
What You Can Do Now
If you build EU-facing messaging or privacy tools, map now where your product sits under both tracks: the interim voluntary regime and CSAR detection orders. Settle inside the team whether end-to-end encryption is a hard commitment or a feature you would negotiate away under pressure. Document your data flows so that if a detection order or age-verification requirement actually arrives, you can answer it without a ground-up rebuild. Track the July 9 result and the CSAR trilogue, but do not bet on either outcome; design a structure that survives both. There is also a path that treats regulation as more than a hazard. Some users will pay for a service that can verifiably prove it does not scan, while some jurisdictions will require scanning outright. The team that segments along that split turns a few years of regulatory churn into an opening.
Sources
- EU to extend temporary message-scanning regime to detect child sexual abuse online · Euronews
- EU now one step away from reviving private message scanning rules · CyberInsider
- Parliament forced back to the chat control question · EU Perspectives
- EU Parliament Blocks Mass-Scanning of Our Chats, What's Next? · Electronic Frontier Foundation
- Chat Control: The EU's CSAM scanner proposal · Patrick Breyer