Original caption
Will your messages be scanned under the EU’s new rule? Not if they are end-to-end encrypted. But that is only one of two different measures commonly called “Chat Control.” On July 23, the Council gave final approval to a temporary regulation allowing online service providers to resume voluntary detection, reporting and removal of child sexual abuse material. It was published on July 28, entered into force on July 31 and applies until April 3, 2028. The rule excludes interpersonal communications protected, previously protected or intended to be protected by end-to-end encryption. “Chat Control” is not an official EU title. It is a political label often used for both this temporary measure and a separate permanent regulation that is still being negotiated. Parliament’s position rejects generalised scanning. It would permit targeted, time-limited detection orders authorised by a judicial authority, while excluding end-to-end encrypted communications and text messages. The Council’s position is different. It would make voluntary detection permanent and require providers to assess how their services could be misused, then introduce measures to reduce those risks. No final text has been agreed. The technical conflict remains. With end-to-end encryption, only the intended endpoints can read a message. The platform carries ciphertext and does not hold the keys needed to decrypt it. To inspect the content while leaving the encryption itself intact, software would have to check it before encryption or after decryption on an endpoint. That is client-side scanning: the lock remains, but the inspection point moves onto the device. This film separates what entered into force, what remains under negotiation and where content inspection would actually happen. Sources: Regulation (EU) 2026/1881; Council of the EU, July 23, 2026; European Parliament position, November 2023; Council general approach, November 2025. Current as of July 31, 2026. #ChatControl #Encryption #DigitalRights #EuropeanUnion #DataJournalism