Few pieces of EU legislation have been declared dead as often as Chat Control, and few have returned as reliably. In July 2026 a scanning law that more MEPs voted against than for came back into force. On 29 September 2026 negotiators meet again to decide the shape of the permanent regulation. The outcome affects ministries, armed forces, defence suppliers and energy operators, because it determines how much control they keep over who can read their communications.
This guide answers the questions people ask most about Chat Control. If you want to keep your sensitive conversations under control, talk to our Teem.
What is chat control?
Chat Control is the popular name for the EU's plan to detect child sexual abuse material (CSAM) and grooming in online communication. The formal proposal, the Regulation to Prevent and Combat Child Sexual Abuse (CSAR), was presented by then Home Affairs Commissioner Ylva Johansson in May 2022.
Protecting children online is a goal everyone shares, and the problem is growing fast. The European Commission says reports of new abuse material are now more than 200 times higher than three years ago, mostly because of AI. Reports of grooming are 12 times higher. The open question is how to tackle this. Lawmakers are deciding whether it requires scanning private messages, and what that scanning would mean for the security of the tools governments, businesses and families use every day.
Chat control 1.0 and 2.0: two laws with one nickname
Most confusion about EU Chat Control comes from two separate legal instruments sharing one name.
| |
Chat Control 1.0
|
Chat Control 2.0
|
|
Legal form
|
Temporary derogation from the ePrivacy Directive
|
Permanent Child Sexual Abuse Regulation (CSAR)
|
|
Scanning
|
Voluntary, by providers that choose to
|
Legal duties, including possible detection orders
|
|
End-to-end encryption
|
Explicitly excluded
|
Still under negotiation
|
|
Status
|
In force until 3 April 2028
|
In trilogue, next round 29 September 2026
|
Chat Control 1.0 dates from 2021. It lapsed on 3 April 2026 after Parliament rejected the Commission's proposed extension in March. The Council then sent the file back to Parliament for a second reading. On 9 July, 314 MEPs voted to reject the revival and 276 voted to keep it. Rejection at second reading requires an absolute majority of 361, so the Council's text stood. The Council gave final approval on 23 July and accepted Parliament's amendments excluding end-to-end encrypted communications.
Chat Control 2.0 is the permanent CSAR. It would set up a new EU Centre, place risk-mitigation duties on providers and create a legal basis for detection orders. This is the text negotiators are still fighting over.
How does chat control work?
Detection relies on two techniques. Hash matching compares a digital fingerprint of an image or video against a database of known abuse material. Machine-learning classifiers try to recognize previously unseen material or grooming patterns in text, and they are far more prone to false positives.
Where a service can read message content on its servers, scanning happens there. End-to-end encryption (E2EE) changes that picture. With E2EE, only the sender's and recipients' devices hold the keys needed to read a message, and the server only ever sees ciphertext. Any scanning of E2EE content would have to run on the device itself, before encryption or after decryption. That approach is called client-side scanning, and it is the technical heart of the dispute. The European Data Protection Board has formally opposed elements of the CSAR in several opinions since 2023, and cryptographers have warned for years that a scanner reading plaintext on every device creates a new point of failure.
Who is actually scanning?
Under Chat Control 1.0, scanning is done by providers that opt in, on services without E2EE. One tracker reports that this mainly covers direct messages and email on a handful of large, mostly American platforms, and that end-to-end encrypted chats remain outside its reach. Telegram's default cloud chats are not end-to-end encrypted, which places them in the category that can be scanned voluntarily; only Secret Chats use E2EE (we covered this in Is Telegram a Security or Surveillance Tool). Neither version of Chat Control currently requires operating systems to scan. Apple shelved its own on-device CSAM scanning plan in 2022 after widespread criticism, which shows how contested the technique remains.
Did Chat Control get passed?
Chat Control 1.0 yes. The EU adopted Regulation (EU) 2026/1881 in July 2026, a temporary exception to the ePrivacy Directive that lets webmail and messaging providers keep using technology to detect and report child sexual abuse material, and it applies until 3 April 2028. Its scope excludes interpersonal communications protected by end-to-end encryption.
Chat Control 2.0, the permanent regulation, has not passed. A sixth political trilogue is set for 29 September 2026 in Brussels under the Irish Council presidency, following five earlier rounds that ended without consensus.
What Chat Control 1.0 means for Wire
Wire applies end-to-end encryption to every message, call and file by default, with no opt-in and no unencrypted mode. Encryption keys live on users' devices, and Wire's servers route ciphertext they cannot read. Every Wire conversation therefore sits in the category the 2026 derogation excludes. Wire has no access to message content and no mechanism to scan it.
That protection is built on Messaging Layer Security (MLS), the open IETF standard for end-to-end encrypted group communication. MLS provides forward secrecy, which protects past messages if a key is compromised, and post-compromise security, which heals a conversation after a device is compromised. Our MLS explainer goes deeper. Wire's clients and server are open source, so security teams and auditors can verify that no hidden scanning or key escrow component exists. Organizations that need full control can run Wire self-hosted or on-premises and keep keys, infrastructure and jurisdiction in their own hands.
One crucial warning is important here: the Council agreed to protect encrypted messages in Chat Control 1.0, and it has said this is no promise for Chat Control 2.0. The exception in 1.0 is a good sign. Whether encrypted messages stay protected in the permanent law is still undecided.
What Chat Control 2.0 would mean if it passes
The last round of talks in June ended without a deal. The main sticking point was the Council's wish to allow scanning of private messages without any suspicion, on a permanent basis. Negotiators did make progress on dropping mandatory age checks.
An internal note from 18 September shows where things stand now. Ireland, which currently chairs the Council, has proposed the following:
- Public content, such as posts anyone can see: platforms could be ordered to search for abuse material that is already known and on record.
- Private messages: providers could keep scanning voluntarily, both for known material and for new material and grooming.
The European Parliament wants to go less far. It would allow automatic scanning only for known material, with oversight from courts or independent authorities.
Ireland has also suggested aiming scanning orders at specific parts of a service or at individual users. If no deal is reached, it has asked member states whether private messages should be left out of the law entirely.
For encrypted messaging, one question matters most: does the final law reach end-to-end encrypted services? If it does, messages would have to be scanned on the device before they are encrypted. The promise that only the people in a conversation can read it would then come with a legal exception, built into the app on every phone.
That exception brings a new attack surface with it. A scanning component that reads plaintext and a pipeline that forwards flagged content to authorities are high-value targets for state-backed attackers. The Salt Typhoon campaign showed what happens when access built for lawful interception is compromised. Our earlier analysis of Chat Control walks through these technical weaknesses in detail.
Error rates matter too. Classifiers aimed at new material and grooming misfire, and every false positive sends someone's private photos or conversations to a human reviewer. A permanent voluntary regime for unencrypted services would also normalize scanning as the default state of private messaging in Europe.
A narrow outcome would look very different. If the final text limits detection orders to known material on public content and leaves private, encrypted communication out of scope, the direct effect on E2EE services would be small. The 29 September trilogue and the rounds that follow will decide which of these paths Europe takes.
Chat control in Germany
Germany's position within Chat Control carries a lot of weight in the Council. In October 2025 the federal government said it would not support scanning messages without suspicion or weakening encrypted communication.

For authorities and the defense sector, the original draft already left out internal communication tools that only one organization or authority uses. The reason given was the need to protect classified information.
The bigger risk is everyday work across organizations. Agencies, the Bundeswehr, defence suppliers and NATO partners often coordinate over consumer apps. In our State of Secure Collaboration 2026 survey, 42% of CISOs said their organizations use WhatsApp, Signal or similar apps for work. These are public services, so any future scanning rules would apply to them.