One regulation has been in force since July and explicitly protects encryption. The other is where the real battle resumes on 29 September.
This is the second piece in our Who Decides? series.
If you have heard of Chat Control, you have probably heard of it as one thing: the EU law that scans your private messages. That sentence contains the first mistake. There is no single law called Chat Control. There are two separate pieces of legislation. They sit at different stages of the process and they do different things.
I will admit something up front. I have followed this debate for years, and until I sat down with the actual texts, I had not realised how completely the two get blended into one story. It bothers me, because the blend is doing real work: it makes a complicated situation look like a simple scandal.
Here is where things actually stand, as of 12 August 2026.
Chat Control 1.0 is Regulation (EU) 2026/1881, published in the Official Journal on 28 July 2026 and in force since 31 July. It is temporary, it expires on 3 April 2028, and it follows an earlier derogation from 2021 whose extended period of application ran out on 3 April 2026. For nearly four months providers had no legal basis to scan; this regulation restores it.
Chat Control 2.0 is the proposed Child Sexual Abuse Regulation, on the table since May 2022 and still in first reading. This is the permanent framework, and the one where the real fight is happening. The next negotiating round is scheduled for 29 September.
Same nickname, different laws. Keep them apart and the whole subject becomes easier to think about.
The claim
Both laws answer to the same underlying claim: child sexual abuse material circulates through private communication channels, and the law must make detection possible.
But each makes a different claim on top of that. The temporary regulation says: providers who already scan their services voluntarily need a legal basis to do it, otherwise EU privacy rules force them to stop. The proposed permanent regulation says something stronger: voluntary scanning is not enough, and authorities should be able to order providers to detect.
That word, order, is where the temperature rises. Before judging either claim, it is worth knowing precisely which one you are reading about. Most viral posts do not say.
Who decides?
Under the law in force today, the decision to scan sits with the provider. The regulation permits scanning; it does not command it. A company can scan its unencrypted channels for abuse material, or it can choose not to.
Under the proposed regulation, the central dispute is exactly this: who gets to decide. If detection can be ordered by an authority, the decision moves from the company to the state.
In my head the line is simple. May and must are two different worlds. The moment a state can order the monitoring of private communication, the matter stops being a technology company’s policy. It becomes a question of what power we are willing to hand the state, and what doors that opens later.
The negotiators know it. According to EDRi’s reporting from early August, the teams have already agreed on protecting encryption and on dropping age verification from the text. What remains open is whether detection will be mandatory or voluntary, and whether it can be blanket or must be targeted. The dispute has narrowed to the single question that matters most.
By what rule?
The temporary regulation is unusually explicit about its own limits, and this is the part the nickname hides.
Article 1(2) excludes the scanning of audio communications altogether. Article 1(3) excludes interpersonal communications to which end-to-end encryption is, has been or will be applied. And the recitals state that nothing in the regulation may be interpreted as prohibiting or weakening end-to-end encryption.
Read that again, because it runs against everything the name suggests: the law currently in force explicitly protects encrypted messaging. Signal and WhatsApp conversations are outside its scope by the letter of the law. When the Council position came to a second reading vote on 9 July 2026, a joint proposal to reject it outright drew 314 votes in favour, 276 against and 17 abstentions, short of the 360 that a majority of Parliament’s component members requires. The text went through, and the size of the opposition was itself a message.
The proposed permanent regulation has no final rules yet. That is the point: the rules are being written now, in trilogue meetings, the next on 29 September under the Irish presidency. And there are fixed dates already running. By 1 September 2026 the Commission must request guidance from the European Data Protection Board, and providers must report which organisations they forward material to. By 1 October the Commission publishes that list. By 1 August 2027 member states begin publishing statistics.
Who pays the price?
Take the claim seriously first. Child sexual abuse is real, and so is the material. The people demanding detection tools are not inventing a problem, and I refuse to wave that away with one clever sentence.
But a good goal does not automatically bless every instrument, so ask what happens when the instrument errs. Detection at scale means classifiers, and classifiers make mistakes. A family beach photo, a medical image sent to a doctor, a teenager’s own picture: systems built to find abuse material have flagged all of these. The person wrongly flagged carries the cost, and it is not small: an account suspended, a report filed, and a suspicion that stays attached to a name. Scale makes it worse. A tiny error rate across billions of messages is still a very large number of innocent people.
There is a quieter cost too, harder to measure. Communication that knows it may be scanned changes. People self-censor first and ask questions later.
Today, under the law in force, that price is confined to unencrypted channels and to providers who choose to scan. If the permanent regulation ends with mandatory, blanket detection, it would be paid by everyone.
What does it mean for you?
Today, practically: nobody in the EU is reading all your messages. The regime in force is voluntary. It does not touch audio, and it explicitly does not touch end-to-end encrypted communication. If your messenger is end-to-end encrypted, this law does not reach it. What can be scanned are unencrypted channels of providers who choose to scan, a category that includes much of ordinary email and some chat services.
So there is no cause for panic. There is good cause to pay attention. Debates like this one determine how private your communication will be in a few years, and who can reach it under what conditions. The decisions are being made now, while almost nobody is watching. That is exactly why we are writing about it now, ahead of 29 September, and why we will not wait until the outcome is announced and everyone argues over a finished text. At this moment you can still see who wants which power and why, and where others are drawing the line.
Is there another way?
The honest test for any proposed instrument has five parts. Does it work? Is it proportionate? Who can it hurt? What happens on error? And does solving one terrible problem create a tool for other problems later?
Alternatives exist and are on the table. Targeted detection on the basis of suspicion, rather than blanket scanning of everyone. Proper resourcing for the investigation of known material, where the backlog is notorious. Court-ordered access in individual cases, the way other serious crime is handled. The fact that negotiators have already agreed to protect encryption suggests the less invasive path is being taken seriously, at least for now.
Protecting children is a goal we can agree on. The question begins the moment we ask what power we are willing to hand over to achieve it, to whom it goes, under what rule, and what happens to the person the system gets wrong. That question does not have an obvious answer, and it will never be answered by a nickname.
The next checkpoint is 29 September. We will be watching, and this text will be updated when the facts move.
Written by Pavel Kadlec. Sources: Regulation (EU) 2026/1881, Official Journal of the EU, 28 July 2026, full text at EUR-Lex, CELEX 32026R1881; European Parliament, second reading of 9 July 2026, minutes and results of votes; proposal 2022/0155(COD), Child Sexual Abuse Regulation; EDRi reporting, 4 August 2026. Facts as of 12 August 2026.
Live status: we now track Chat Control continuously. See what is in force, what is being negotiated, and what it means for your apps on our EU Chat Control Tracker.


