This is a living post. I'll keep updating it as votes happen and the text changes — the newest developments sit at the top under Live Updates, and the evergreen explainer runs underneath so anyone landing here cold can get up to speed. Last updated: 10 September 2026.
Status at a glance: Chat Control 1.0 — the temporary voluntary-scanning regime — passed on 9 July 2026. A majority of voting MEPs opposed it (314 against, 276 for) but fell short of the 361-vote absolute majority needed to block it in second reading. Suspicionless scanning of private, unencrypted messages is legal again — the replacement derogation applies from 31 July 2026 until 3 April 2028. The permanent regulation ("Chat Control 2.0" / CSAR) has not passed, but the fight has narrowed sharply: a provisional trilogue text protects end-to-end encryption and pares back the age-verification mandate. Read the fine print, though — the encryption protection sits in a recital, not an operative article, and it is written around decryption and data access, which is not the same thing as ruling out client-side scanning. What is left to settle is the detection regime itself — mandatory or voluntary, targeted or mass. The next trilogue is 29 September 2026.
Live Updates
10 September 2026 — Date set: the next trilogue is 29 September. Negotiations on the permanent regulation resume in Brussels on 29 September 2026 — the sixth political trilogue, and the first under the Irish Council Presidency. Ireland has historically sat with the pro-scanning bloc, so expect a firmer Council push. But it arrives into a much narrower fight than the one that collapsed in June (see below), and Germany's position on a blocking minority is still the number to watch.
4 August 2026 — Encryption protected, age verification dropped. Detection is the last battleground. EDRi's post-mortem on the 1.0 saga confirms something that got very little coverage at the time: inside the CSAR trilogue, negotiators have provisionally agreed language protecting encryption, and have moved substantially on age verification. What remains under negotiation is the kind of detection: mandatory and/or voluntary, targeted or mass scanning. Standard trilogue caveat applies — nothing is final until the whole text is agreed, and this is exactly the point at which things get traded back. (See the 10 September entry above: I went and read the Council text, and the age-verification part of this is weaker than it first sounds.)
EDRi also reframes the July defeat as a win on points. Every rejection and amendment vote carried a simple majority; they only failed because second reading demanded an absolute one. The CSAR will not have that handicap. On the arithmetic, there is no majority in this Parliament for mass scanning. EDRi's full analysis →
10 September 2026 — Correction: I checked the Council text myself, and one of the claims below needs qualifying. Yesterday I wrote that trilogue negotiators had agreed to protect encryption and remove age verification "altogether." I have now gone to the primary document — the Council's four-column comparison of the mandates and the draft agreement (WK-6982-2026-INIT, dated 19 May 2026, showing the outcome of the 11 May trilogue) — and it is more complicated than the secondary reporting suggests.
On encryption, the good news is real but narrower than it looks. The draft-agreement column does contain protective language: nothing in the Regulation is to be understood as "prohibiting, weakening or circumventing, requiring to disable, or making end-to-end encryption impossible," and providers "should not be obliged by this Regulation to decrypt data or to provide access to end-to-end encrypted data." Two caveats matter. First, this is a recital — interpretive context, not an operative obligation. Second, look at what it actually forbids: compelling decryption and compelling access to encrypted data. Client-side scanning requires neither. It inspects the message on your device before the encryption ever engages, so nothing is decrypted and no encrypted data is handed over. A promise not to break encryption is not a promise not to look before it starts. That is precisely the Article 4 "risk mitigation" back door Patrick Breyer has been warning about.
On age verification, "removed altogether" appears to be wrong. The agreed text still carries a recital setting out how age verification and age assessment measures should be conducted — privacy-preserving, GDPR-compliant, proportionate, non-discriminatory, disclosed in providers' terms and conditions. That is not how you write about something you have deleted. The likelier reading is that a blanket mandatory age-verification obligation was dropped while age verification survives as a permitted and regulated mitigation measure. I have corrected the entries below accordingly.
Honest limit on this check: the document is 446 pages and I was only able to read the first 36 of them; the passage others have cited sits around page 127, which I have not seen. And a flattened four-column table makes column attribution imperfect. So treat this as "the primary text does not support the strong version of the claim" rather than a complete audit. If you only take one thing from this: be suspicious of any headline saying Chat Control has been defanged. The detection question — the whole ballgame — is still open, and it goes back to the table on 29 September.
31 July 2026 — The replacement derogation enters into force. Because Parliament amended the text, it was not adopted automatically: the Commission had to issue an opinion and the Council had to accept it. Both did. The new Chat Control 1.0 regime applies from 31 July 2026 and runs until 3 April 2028.
26 July 2026 — Holding pattern. No new legislative movement since the 9 July vote. Chat Control 1.0 is law until 2028; the permanent regulation (2.0 / CSAR) remains stuck after the failed June trilogue. The next real test is the sixth trilogue expected in September 2026 under the incoming Irish Council Presidency — Ireland has historically backed the pro-scanning bloc, so watch for a tougher Council push in the autumn, and watch Germany's position on a blocking minority.
9 July 2026 — Chat Control 1.0 passed. The majority voted no anyway. In a second-reading plenary vote under the fast-tracked urgent procedure, the motion to reject drew 314 votes against the regime, 276 for, 17 abstentions — a clear majority of those voting, but short of the 361-vote absolute majority (of all 720 MEPs) required to reject. A separate amendment restricting scanning to judicially identified suspects also had majority support (322 to 255) and also fell short. Two amendments protecting end-to-end encrypted communications — explicitly including protection against client-side scanning — did pass, and they mattered more than they looked on the night: because the text came out amended, it could not be adopted automatically, and the Commission had to weigh in before it became law. It green-lit the encryption protection. A further amendment banning scanning for grooming fell 15 votes short. Result: warrantless, suspicionless scanning is reinstated until 2028, or until a permanent regulation is agreed. Breyer: "moving forward against the will of the majority of voting MEPs is a farce and damages democracy." Full write-up →
7 July 2026 — The procedural trick. Parliament approved the Rule 170 urgent procedure for the 1.0 revival, 331–304 with 11 abstentions, putting it on a second-reading track where opponents needed an absolute majority to stop it. Opponents called it an unprecedented maneuver.
2 July 2026 — The Council's zombie. The Council launched a formally new interim ePrivacy derogation rather than an extension — allowing it to be fast-tracked and skip checkpoints such as an EDPS opinion.
29–30 June 2026 — No deal on 2.0. The fifth and expected-final trilogue on the permanent CSA Regulation ended without agreement. Parliament held its line against suspicionless scanning; Council would not accept targeted judicial detection orders. Talks resume September 2026.
29 June 2026 — Final trilogue. Fifth round of closed-door negotiations between the Council, Parliament and Commission on the permanent CSA Regulation. This was billed as the last scheduled session before a political deal.
Late June 2026 — The Council's end-run. EU ambassadors moved to push forward a temporary extension of the "Chat Control 1.0" voluntary-scanning derogation — the same regime Parliament had already voted to let expire. Privacy advocates called this a direct challenge to Parliament's democratic authority.
26 March 2026 — The one-vote reprieve. The European Parliament voted 307–306, with 24 abstentions, to reject extending the temporary rules that let platforms scan private messages. The civil-liberties committee (LIBE) had already rejected the draft 38–28.
(Older milestones are folded into the timeline below.)
The one-sentence version
The EU is trying to pass a law that would legally require messaging services to scan your private conversations for child sexual abuse material (CSAM). Because most serious messengers are end-to-end encrypted, the only way to do that is to inspect your messages on your own device, before they're encrypted — which is why critics call it "Chat Control." Supporters call it child protection. The disagreement is about whether you can have both, and the cryptographers are fairly clear that you can't.
Why I keep coming back to this on the show
Almost everything we talk about here — Signal, encrypted messaging, threat modeling for ordinary people — runs straight into this proposal. If it passes in a strong form, "just use an encrypted app" stops being complete advice for anyone in the EU, because the law would reach inside the app, onto the device, before the encryption ever engages. Signal has already said it would leave the EU market rather than comply. This is the clearest real-world test of whether end-to-end encryption survives as a legal reality in a major democratic bloc.
Two things are happening at once (this is the confusing part)
Nearly every headline blurs these together. Keep them separate and the whole story snaps into focus.
Chat Control 1.0 — the temporary, voluntary regime. A time-limited derogation that permits platforms like WhatsApp and Messenger to voluntarily scan for CSAM. It expires and needs renewing. Parliament voted in March to let it lapse; the Council has been trying to keep it alive.
Chat Control 2.0 — the permanent regulation (the CSA Regulation, or CSAR). The big one. This would make scanning a legal obligation enforced through "detection orders," not a voluntary choice. This is the text being fought over in trilogue.
When someone tells you "Chat Control passed" or "Chat Control is dead," your first question should always be: which one?
The encryption problem, in plain terms
Here's the crux. If a message is end-to-end encrypted, nobody in the middle — not the network, not the platform — can read it in transit. That's the entire point. So to satisfy a scanning mandate, the inspection has to move to where the message is still readable: your device. Two approaches keep surfacing:
- Client-side scanning (CSS): software on your phone analyzes the content before it's encrypted and sent, or after it's decrypted on the other end. The encryption technically stays intact, but the private moment — the instant before the lock closes — gets inspected. Critics argue this hollows out E2E encryption entirely and bolts a permanent surveillance layer onto every phone.
- "Risk mitigation" pressure: the drafts have long carried a "risk mitigation" obligation broad enough to push encrypted services toward weakening their own protocols — without ever writing the word encryption into the ban. (Update, September 2026: encryption protection has been provisionally agreed in trilogue and the age-verification mandate has been pared back — but the agreed age-verification text still describes how such measures should operate, so "gone" overstates it. The risk-mitigation framing is very much still in play.)
And the detection orders don't only target the big names. Smaller providers, unwilling to shoulder the legal and technical risk themselves, get nudged toward third-party scanning tools — which centralizes a sensitive capability in even fewer hands.
The line I'd put on a slide: more than 500 scientists and cryptographers have publicly called this approach "technically infeasible." You cannot build a scanning mechanism that only ever catches criminals. Anything that can inspect content before encryption can be repointed at other content later. It isn't a backdoor. It's a front door that's wired to stay open, and you don't control who walks through it next.
Where the member states stand
Blocking a proposal in the Council takes a blocking minority — at least four countries representing more than 35% of the EU population. That math is the whole game, and Germany is the linchpin.
Pushing for it: Denmark, Ireland, Spain and Italy have led the pro-scanning bloc, joined at various points by Bulgaria, Croatia, Cyprus, France, Hungary, Latvia, Lithuania, Malta, Portugal and Slovakia.
Resisting mandatory encryption-breaking: Germany, Poland, Austria, Estonia, Slovenia, Luxembourg, the Netherlands, Finland and the Czech Republic.
Germany alone is roughly 19% of the EU's population. When Berlin says no, a blocking minority becomes reachable; when Berlin wavers, the proposal is instantly back in play. If you only watch one thing, watch Germany's Interior Ministry.
Timeline
- Nov 2023 — Parliament adopts a negotiating position that blocks mandatory client-side scanning of encrypted messages.
- Oct 2025 — The Danish Council Presidency pushes a strong version. Germany and Luxembourg join a blocking minority of nine states (>35% of the population), and the October Council vote is effectively killed.
- 31 Oct 2025 — Denmark drops mandatory detection orders from its compromise, retreating to "voluntary" detection.
- 26 Mar 2026 — Parliament votes 307–306 to reject extending the temporary 1.0 derogation.
- 3 Apr 2026 — The temporary derogation expires. Voluntary scanning stops.
- 4 May 2026 — A trilogue round on the permanent 2.0 regulation.
- 29 Jun 2026 — Fifth and expected-final trilogue on 2.0, under the Cyprus Presidency. No deal.
- 2 Jul 2026 — The Council relaunches the interim measure as a formally "new" proposal.
- 7 Jul 2026 — Parliament fast-tracks it, 331–304.
- 9 Jul 2026 — Parliament fails to block it. Chat Control 1.0 returns until 2028.
- 31 Jul 2026 — The replacement derogation enters into force, running to 3 Apr 2028.
- 4 Aug 2026 — EDRi reports trilogue negotiators have agreed to protect encryption and to drop age verification from the CSAR.
- 10 Sep 2026 — Checked against the Council four-column text: encryption protection confirmed, but only as a recital; age verification pared back rather than removed.
- 29 Sep 2026 — Sixth trilogue on the permanent 2.0 regulation, the first under the Irish Presidency. Watch Germany.
What you can actually do about it
If you're in the EU, this isn't settled, and public pressure has already moved it once — that 307–306 vote didn't happen by accident. Contacting your MEP genuinely matters here. Beyond that, the through-line of this whole show applies: wherever you reasonably can, own the thing instead of borrowing it. Understand that client-side scanning defeats app-level encryption by design, so the answer isn't only "which app" but also which jurisdiction, which device platform, and how much of your stack you control yourself. I'll dig into concrete defensive setups in a dedicated segment as the final text firms up.
Sources & further reading
- Patrick Breyer — Chat Control tracker: https://www.patrick-breyer.de/en/posts/chat-control/
- Patrick Breyer — the historic Parliament vote: https://www.patrick-breyer.de/en/historic-chat-control-vote-in-the-eu-parliament-meps-vote-to-end-untargeted-mass-scanning-of-private-chats/
- 500+ scientists' open letter: https://www.patrick-breyer.de/en/danger-to-democracy-500-top-scientists-urge-eu-governments-to-reject-technically-infeasible-chat-control/
- EDRi — CSA Regulation document pool: https://edri.org/our-work/csa-regulation-document-pool/
- CDT Europe — response to the 1.0 rejection: https://cdt.org/insights/cdt-europes-response-to-the-european-parliament-rejection-of-the-chat-control-1-0s-extension/
- European Parliament press room: https://www.europarl.europa.eu/news/en/press-room/20260306IPR37531/child-sexual-abuse-online-support-for-extending-rules-until-august-2027
- EDRi — "The Chat Control 1.0 saga" (vote post-mortem and current CSAR state of play): https://edri.org/our-work/the-chat-control-1-0-saga-big-tech-can-scan-our-private-messages-again-but-parliament-sent-a-strong-signal-against-mass-surveillance/
I'll keep this page current as the vote resolves. If you want the fast version in your ears, it'll be a segment on an upcoming episode of Closed Network.
— Simon