Skip to main content
End-to-end encryption

Chat Control in 2026: What Happens to Encrypted Messages

What is Chat Control and how it effects encryption? Chat Control 1.0 and 2.0 explained for encrypted messaging, and what they mean for government, defense and energy teams.

Few pieces of EU legislation have been declared dead as often as Chat Control, and few have returned as reliably. In July 2026 a scanning law that more MEPs voted against than for came back into force. On 29 September 2026 negotiators meet again to decide the shape of the permanent regulation. The outcome affects ministries, armed forces, defence suppliers and energy operators, because it determines how much control they keep over who can read their communications.

This guide answers the questions people ask most about Chat Control. If you want to keep your sensitive conversations under control, talk to our Teem

What is chat control?

Chat Control is the popular name for the EU's plan to detect child sexual abuse material (CSAM) and grooming in online communication. The formal proposal, the Regulation to Prevent and Combat Child Sexual Abuse (CSAR), was presented by then Home Affairs Commissioner Ylva Johansson in May 2022.

Protecting children online is a goal everyone shares, and the problem is growing fast. The European Commission says reports of new abuse material are now more than 200 times higher than three years ago, mostly because of AI. Reports of grooming are 12 times higher. The open question is how to tackle this. Lawmakers are deciding whether it requires scanning private messages, and what that scanning would mean for the security of the tools governments, businesses and families use every day.

Chat control 1.0 and 2.0: two laws with one nickname

Most confusion about EU Chat Control comes from two separate legal instruments sharing one name.

 

Chat Control 1.0

Chat Control 2.0

Legal form

Temporary derogation from the ePrivacy Directive

Permanent Child Sexual Abuse Regulation (CSAR)

Scanning

Voluntary, by providers that choose to

Legal duties, including possible detection orders

End-to-end encryption

Explicitly excluded

Still under negotiation

Status

In force until 3 April 2028

In trilogue, next round 29 September 2026

Chat Control 1.0 dates from 2021. It lapsed on 3 April 2026 after Parliament rejected the Commission's proposed extension in March. The Council then sent the file back to Parliament for a second reading. On 9 July, 314 MEPs voted to reject the revival and 276 voted to keep it. Rejection at second reading requires an absolute majority of 361, so the Council's text stood. The Council gave final approval on 23 July and accepted Parliament's amendments excluding end-to-end encrypted communications.

Chat Control 2.0 is the permanent CSAR. It would set up a new EU Centre, place risk-mitigation duties on providers and create a legal basis for detection orders. This is the text negotiators are still fighting over.

How does chat control work?

Detection relies on two techniques. Hash matching compares a digital fingerprint of an image or video against a database of known abuse material. Machine-learning classifiers try to recognize previously unseen material or grooming patterns in text, and they are far more prone to false positives.

Where a service can read message content on its servers, scanning happens there. End-to-end encryption (E2EE) changes that picture. With E2EE, only the sender's and recipients' devices hold the keys needed to read a message, and the server only ever sees ciphertext. Any scanning of E2EE content would have to run on the device itself, before encryption or after decryption. That approach is called client-side scanning, and it is the technical heart of the dispute. The European Data Protection Board has formally opposed elements of the CSAR in several opinions since 2023, and cryptographers have warned for years that a scanner reading plaintext on every device creates a new point of failure.

Who is actually scanning?

Under Chat Control 1.0, scanning is done by providers that opt in, on services without E2EE. One tracker reports that this mainly covers direct messages and email on a handful of large, mostly American platforms, and that end-to-end encrypted chats remain outside its reach. Telegram's default cloud chats are not end-to-end encrypted, which places them in the category that can be scanned voluntarily; only Secret Chats use E2EE (we covered this in Is Telegram a Security or Surveillance Tool). Neither version of Chat Control currently requires operating systems to scan. Apple shelved its own on-device CSAM scanning plan in 2022 after widespread criticism, which shows how contested the technique remains.

Did Chat Control get passed?

Chat Control 1.0 yes. The EU adopted Regulation (EU) 2026/1881 in July 2026, a temporary exception to the ePrivacy Directive that lets webmail and messaging providers keep using technology to detect and report child sexual abuse material, and it applies until 3 April 2028. Its scope excludes interpersonal communications protected by end-to-end encryption.

Chat Control 2.0, the permanent regulation, has not passed. A sixth political trilogue is set for 29 September 2026 in Brussels under the Irish Council presidency, following five earlier rounds that ended without consensus.

What Chat Control 1.0 means for Wire

Wire applies end-to-end encryption to every message, call and file by default, with no opt-in and no unencrypted mode. Encryption keys live on users' devices, and Wire's servers route ciphertext they cannot read. Every Wire conversation therefore sits in the category the 2026 derogation excludes. Wire has no access to message content and no mechanism to scan it.

That protection is built on Messaging Layer Security (MLS), the open IETF standard for end-to-end encrypted group communication. MLS provides forward secrecy, which protects past messages if a key is compromised, and post-compromise security, which heals a conversation after a device is compromised. Our MLS explainer goes deeper. Wire's clients and server are open source, so security teams and auditors can verify that no hidden scanning or key escrow component exists. Organizations that need full control can run Wire self-hosted or on-premises and keep keys, infrastructure and jurisdiction in their own hands.

One crucial warning is important here: the Council agreed to protect encrypted messages in Chat Control 1.0, and it has said this is no promise for Chat Control 2.0. The exception in 1.0 is a good sign. Whether encrypted messages stay protected in the permanent law is still undecided.

What Chat Control 2.0 would mean if it passes

The last round of talks in June ended without a deal. The main sticking point was the Council's wish to allow scanning of private messages without any suspicion, on a permanent basis. Negotiators did make progress on dropping mandatory age checks.

An internal note from 18 September shows where things stand now. Ireland, which currently chairs the Council, has proposed the following:

  • Public content, such as posts anyone can see: platforms could be ordered to search for abuse material that is already known and on record.
  • Private messages: providers could keep scanning voluntarily, both for known material and for new material and grooming.

The European Parliament wants to go less far. It would allow automatic scanning only for known material, with oversight from courts or independent authorities.

Ireland has also suggested aiming scanning orders at specific parts of a service or at individual users. If no deal is reached, it has asked member states whether private messages should be left out of the law entirely.

For encrypted messaging, one question matters most: does the final law reach end-to-end encrypted services? If it does, messages would have to be scanned on the device before they are encrypted. The promise that only the people in a conversation can read it would then come with a legal exception, built into the app on every phone.

That exception brings a new attack surface with it. A scanning component that reads plaintext and a pipeline that forwards flagged content to authorities are high-value targets for state-backed attackers. The Salt Typhoon campaign showed what happens when access built for lawful interception is compromised. Our earlier analysis of Chat Control walks through these technical weaknesses in detail.

Error rates matter too. Classifiers aimed at new material and grooming misfire, and every false positive sends someone's private photos or conversations to a human reviewer. A permanent voluntary regime for unencrypted services would also normalize scanning as the default state of private messaging in Europe.

A narrow outcome would look very different. If the final text limits detection orders to known material on public content and leaves private, encrypted communication out of scope, the direct effect on E2EE services would be small. The 29 September trilogue and the rounds that follow will decide which of these paths Europe takes.

Chat control in Germany

Germany's position within Chat Control carries a lot of weight in the Council. In October 2025 the federal government said it would not support scanning messages without suspicion or weakening encrypted communication.

Chat Control in Germany

For authorities and the defense sector, the original draft already left out internal communication tools that only one organization or authority uses. The reason given was the need to protect classified information.

The bigger risk is everyday work across organizations. Agencies, the Bundeswehr, defence suppliers and NATO partners often coordinate over consumer apps. In our State of Secure Collaboration 2026 survey, 42% of CISOs said their organizations use WhatsApp, Signal or similar apps for work. These are public services, so any future scanning rules would apply to them.

Wire Bund is the only messenger approved by Germany's Federal Office for Information Security (BSI) for communication classified as VS-NfD, and tens of thousands of German government employees already use it. What VS-NfD and BSI Zulassung Mean for Secure Communication explains what that approval covers.

Which apps actually protect you?

Look for end-to-end encryption that is on by default for every message, call, file and group conversation, with no settings to forget. Check whether the protocol is an open, peer-reviewed standard such as MLS, and whether the code is open source and independently audited. Confirm that the provider cannot access your keys and that the service can run self-hosted when your threat model requires it. Independent approvals such as BSI's VS-NfD Zulassung add assurance that goes beyond a vendor's own claims. Governance matters as well, which is why 42% of organizations using WhatsApp for work is a risk on its own.

How to prepare your organization

Start by mapping where sensitive conversations actually happen, including the consumer apps staff use with external partners. Move that work onto a governed platform with default end-to-end encryption and a self-hosted option, and document the choice as part of your NIS2 cryptography and communication measures. Track the trilogue outcome, since a final text will come with transition periods and scope definitions that affect procurement. If you want to make your voice heard, Fight Chat Control offers a tool to contact your MEPs and a clear overview of Chat Control 1.0 and 2.0. Our earlier call to act against Chat Control and our piece on ChatControl as an invasion of our digital living spaces set out why Wire has opposed the proposal from the start.

Frequently Asked Questions

Does Chat Control affect Signal and WhatsApp

Chat Control 1.0 excludes end-to-end encrypted chats, so it does not require those services to scan encrypted conversations. Chat Control 2.0 could still affect them, depending on the final text.

Will governments be able to read my message history?

 Neither version gives authorities general access to message archives. Chat Control 2.0 could lead to flagged content being reported to an EU Centre and national authorities, which is why the scope of detection matters so much. 

Does my phone's operating system scan my messages?

 No current EU rule requires operating system scanning. Client-side scanning under a future detection order would most likely run inside the messaging app. 

Does Chat Control apply outside the EU?

It applies to services offered to users in the EU, regardless of where the provider is based. 

Is Wire affected by Chat Control 1.0?

No, Wire encrypts all communication end to end by default and cannot access content, so it falls in the category the 2026 derogation excludes. 

Wire

As a leader in secure communication, we empower businesses and government agencies with expert-driven content that helps protect what matters. Stay ahead with industry trends, compliance updates, and best practices for secure digital exchanges.

Similar posts

See Wire in action 

product_shot_mobile_and_desktop_calling_1200px-min

Discover in a quick call how Wire enables secure, compliant, and seamless collaboration for your organization, without compromising on usability or control.

  • Messaging, calling, conferencing, and file sharing — all in one app.
  • The only full implementation of Messaging Layer Security (MLS).
  • Invisible security that’s easy to use and built for enterprise scale.
  • Government-approved for VS-NfD, GDPR, and NIS2, trusted by 1,800+ customers.