Chat Control 2.0: The EU wants to read your messages before you send them

The CSAR regulation would force messaging apps to scan your messages before encryption. Signal threatens to leave Europe. Here's what you can do.

Chat Control 2.0: The EU wants to read your messages before you send them

JULY UPDATE 2026. The timeline of this article is outdated: the trilogue on May 4th took place, and on July 9th the European Parliament allowed the renewal of Chat Control 1.0 (voluntary scanning), not by a vote for but due to the lack of the 361 votes required to block it (314 against, 276 for), while the majority voted against. This renewal extends the ePrivacy derogation until April 3rd, 2028, not August 3rd, 2027 as still stated below. End-to-end encryption is explicitly excluded from this text. The real fight, CSAR (2.0) described below, will restart in trilogue in September. Details in the radar.

You send a message to a friend on Signal. End-to-end encrypted, no one can read it between you two. That’s the principle, that’s the promise, that’s what makes hundreds of millions of people use encrypted messaging.

The European Union finds this problematic.

Under the guise of fighting child pornography, the European Commission is pushing a regulation that would force every messaging app to scan the content of your messages before they are encrypted. Signal threatens to leave Europe. Proton says it would rather be blocked. Apple hasn’t said anything. And that might be the most worrying part.

Read: Radar Chat Control 2.0: EU wants to scan all your messages


The Problem: A Snitch on Your Own Device

Imagine a postman who reads every letter you send, compares it to a blacklist, then puts it in a sealed envelope. The envelope is well-sealed, no one can open it in transit. But the postman has already read it.

That’s exactly what the CSAR (Child Sexual Abuse Regulation) would impose on encrypted messaging apps. The technical term is “client-side scanning”. In human terms: your device scans the content of your messages, photos, and files before they are encrypted and sent. The scan result is compared to a database of illegal content. If a match is detected, automatic reporting to authorities.

End-to-end encryption remains “technically” intact. The message is encrypted during transport. Except it’s read beforehand.

Encryption that’s bypassed before it applies is just window dressing.


The Mechanism: How It Works in Practice

Client-side scanning relies on three steps, all performed on your device.

  • Pre-encryption interception: When you type a message or attach a photo, the content is captured in plaintext before the end-to-end encryption protocol applies. That’s the key to the mechanism: encryption is never “broken”, it’s bypassed.
  • Perceptual hash comparison: The content is converted into a numerical fingerprint and compared to a database of known content fingerprints. The problem of false positives is well-documented: family photos, medical images, memes have already triggered false reports in existing systems from Google and Meta.
  • Automatic reporting: If there’s a match, the authorities are notified without human intervention and without notification to the user. You don’t know you’ve been reported. You can’t contest before the process starts.

All this happens silently, in the background, on every message sent by every user. And without any judicial warrant. The door is open to all kinds of administrative abuses.

It’s mass surveillance by design, under the guise of clean democracy.

And that’s where the postman analogy falls short. The postman, you can see. If he gets caught, it’s aggravated offense direct. Likely prison time.

The scanner integrated into your own device, though, it’s just chilling. If you don’t read my articles, you don’t even know it’s just there, working under your nose.


What It Changes in Practice

Two Texts, Two Fates

It’s important to untangle two things that often get confused.

Chat Control 1.0, in its most aggressive form, wasn’t renewed, that’s true. But the reality is more nuanced. On March 11th, 2026, the European Parliament voted 458 to 1 to extend the ePrivacy derogation until August 3rd, 2027. The old derogation expired on April 3rd, 2026. The resolution explicitly protects end-to-end encryption: measures cannot apply to E2EE communications. It’s not “Chat Control 1.0 is dead”. It’s a partial victory: mandatory E2EE scanning is off the table, a limited extension was voted for, and time was given for the permanent CSAR text to be negotiated. Upcoming CSAR trilogues: May 4th and June 29th, 2026.

Chat Control 2.0, officially dubbed CSAR, that’s another story. And it’s that one that’s at stake.

The Council of the EU adopted its position on November 26th, 2025, with Poland and the Netherlands voting against. Since December 2025, the text has been in trilogue: the phase where the final text is crafted between Parliament, Council, and Commission. These negotiations are opaque by design. The positions of the three parties are not public, compromises are made behind closed doors.

Next trilogue: May 4th, 2026. Formal adoption targeted for July 2026.

The terms have changed since the first version. “Client-side scanning” has become “risk mitigation measures” and “voluntary detection activities”. The packaging is more presentable. The practical effect is the same, according to the EDRi, the EFF, and noyb.

Signal, Proton, Apple: Three Very Different Responses

Signal was direct. Meredith Whittaker, executive director, said in October 2025 that Signal would “unfortunately have to leave the European market” rather than compromise its encryption. Signal is a non-profit organization. No shareholders, no advertising revenue, no market obligations. When they say that, it’s credible.

Proton, jurisdiction Switzerland, same stance: “we’d rather be blocked”. Switzerland isn’t in the EU, Proton benefits from real legal distance from European law. The CSAR would only apply to Proton if Proton operates in the EU via its European users, but the legal room for maneuver is wider than just “we comply or we close”.

Apple hasn’t said anything publicly about the CSAR.

This silence is significant. In December 2022, Apple abandoned its own client-side scanning project for iCloud photos after a massive backlash from the security research community. The message seemed clear: no client-side scanning.

Unless Apple isn’t Signal. Apple is a publicly traded company, with physical Apple Stores across Europe, local subsidiaries, European revenue in the tens of billions. Signal can say “we close”. Apple, not so easily.

For a Mac user who uses iMessage daily and trusts its end-to-end encryption, Apple’s silence on the most direct threat to that encryption is the most uncomfortable angle.


The Global Pattern: Same Excuse, Same Infrastructure

Europe isn’t acting in a vacuum.

In the US, the EARN IT Act follows exactly the same logic: same excuse (protecting children from CSAM), same effect (destroying end-to-end encryption), same rhetorical strategy. Who could be against protecting children? No one. That’s precisely why it’s the chosen lever.

It’s not a coincidence. It’s a pattern. On both sides of the Atlantic, legislators are using the most morally unassailable cause to create the infrastructure for generalized surveillance. Once built, that infrastructure doesn’t disappear.

When One Judge Suffices

In March 2026, a New Mexico court ordered Meta to pay $375 million for unfair practices towards minors. In this case, the attorney general presented Meta’s decision to make Messenger end-to-end encrypted by default as a “design choice” that made it harder to transmit reports to law enforcement. The judge followed suit, creating a precedent.

The “design choice” argument is formidable: if this legal angle catches on, every decision to improve user security could become evidence in a future lawsuit. Why add encryption? An attorney could make it “a deliberate tool for protecting criminals”. This logic is legally credible, and it’s just been tested successfully.

This ruling only concerns Meta, in the US. But Apple is also legally exposed on US soil. If this precedent makes waves, the pressure on iMessage will be of a different nature than on Signal. Signal can say “we close” for a geographical area. Apple, not so easily.


When the Commission Admits It’s Useless

The implementation report COM(2025)740, published by the European Commission itself, contains a remarkable admission: it’s currently not possible to establish a clear link between the reports submitted by providers and the convictions handed down, nor to provide a reliable overview of the number of children rescued.

This isn’t a libertarian argument. It’s the Commission, in its own document, acknowledging that the tool it wants to impose on 450 million Europeans has no demonstrable results.

We’re creating an infrastructure for generalized scanning of private communications without being able to prove it protects anyone.

The only guaranteed result is surveillance itself.

The categories are elastic by nature. The infrastructure chosen creates the framework for expansion.


The Limits: Myths and False Evidences

”It’s to Protect Children, So It’s Legitimate”

The goal is legitimate. The means aren’t. Everyone agrees we should fight pedocriminality. But creating a system that scans every message from every citizen to catch a tiny minority of criminals is mass surveillance.

It’s straight out of totalitarian states. The ones that Europe and France love to criticize for their lack of human rights and public freedoms.

And specialists in child protection, including within European civil society, point to targeted alternatives: strengthening law enforcement resources, international cooperation, behavioral detection on non-encrypted platforms. Mass scanning isn’t the only tool. It’s the most intrusive one.

”Encryption Is Protected in the Text”

The CSAR text does contain a clause protecting encryption. But this clause coexists with the obligation to scan content before encryption. It’s like guaranteeing the inviolability of mail while requiring the postman to read it before sealing it.

”It Only Concerns Criminals”

No. Scanning is systematic, applied to all communications, not just suspected ones. There’s no judicial warrant. There’s no targeting. If you use an encrypted messaging app in Europe, your messages would be scanned. All of them.

False positives exist. Similar systems deployed by Google and Meta have reported parents sending photos of their children to their pediatrician. Innocent, scanned, reported.

”Once Voted, the Law Is Irreversible”

Not necessarily. The aggressive version of Chat Control 1.0 (mandatory E2EE scanning) was set aside thanks to citizen mobilization and the European Parliament’s vote. Public pressure changes votes. The trilogue on May 4th, 2026, is the next tipping point, and the text isn’t set in stone yet.


The Political Precedent

The real danger of CSAR goes beyond the technical issue of scanning.

If the European Union, the jurisdiction that invented the GDPR and presents itself as the global champion of personal data protection, normalizes mandatory scanning of encrypted private communications, the signal sent to the rest of the world is devastating.

Every government that dreams of surveilling its citizens’ communications will have a ready-made model, validated by the EU, at its disposal.

I’ve spent the last two years building a sovereign, encrypted, largely self-hosted digital infrastructure. Signal for everyday use. Matrix for internal messages, Proton for emails, encrypted DNS, hardened browsers. By principle, yes, but also for business.

What’s shocking about this text is that it’s pushed by the same institution that created the GDPR. The one that prides itself on all the virtues attached to human rights and freedoms.

Mass surveillance infrastructure never comes with an expiration date. Once in place, it only expands.

The databases for comparison, currently limited to CSAM, could tomorrow include terrorist content, extremist content, disinformation content. Except to be characterized as such today, content must meet precise, legal criteria that a judge must confirm.

Without judicial control, with a little push, we could easily slide into subjects like divergent political views, investigative journalism that ruffles feathers (Rhaaa! Mediapart and Le Canard Enchaîné, thorny issues for elected officials…), the labor sector, NGOs that make too much noise where it hurts, medical confidentiality, etc. All by simple administrative means, without a warrant, and without a judge. Franco must be kicking himself for missing this.

The categories are elastic by nature. The infrastructure chosen creates the framework for expansion.


What You Can Do

You can’t prevent a trilogue from happening. But you can make surveillance more difficult on your own devices, and you can influence the political outcome.

Protect Your Communications

Signal for your conversations. It’s the only messaging app, with end-to-end encryption, whose operator has publicly stated they’d prefer to close the service in Europe rather than compromise its encryption.

Open-source, no advertising, no data collection. Funded by donations, including $50 million from Brian Acton, co-founder of WhatsApp, when the Signal Foundation was created in 2018. No shareholders, no advertising revenue: no financial incentive to monetize your messages.

I use Matrix/Elements because I self-host in maximum privacy mode, but Signal for everyday, easy encrypted messaging is the reference choice. If you had to use only one tool from this list, that’s my recommendation.

Proton Mail for your emails. End-to-end encryption, Swiss jurisdiction, same stance as Signal on the CSAR. Your professional, banking, administrative emails have no business on Gmail, and no one should be able to read them.

Read: Apple Mail vs Gmail vs Proton Mail: The Honest Comparison

Read: Migrating from Gmail to Proton Mail

Reduce Your Exposure Surface

VPN as an additional layer. If Signal or Proton were to be geo-blocked in Europe, a VPN with an IP outside the EU would give you access to the service. Mullvad is the one I’d recommend: no account, no email, cash or crypto payment, Swedish jurisdiction. The VPN doesn’t replace messaging encryption, it complements it by masking your access.

Sovereign DNS. Change the DNS resolvers on all your devices. If European ISPs are forced to block domains, a resolver outside the EU’s jurisdiction circumvents that block. Quad9 (9.9.9.9), run by a Swiss non-profit association, doesn’t log your queries.

To natively encrypt DNS queries on Mac and iPhone, install the DoH profile configuration from Quad9’s documentation page (docs.quad9.net, under Apple). Ten minutes well-spent.

If Signal or Proton Leave Europe?

That’s the practical question. If the law passes and Signal or Proton make good on their threat, how do you keep using them?

Signal distributes its Android APK directly on signal.org. On iOS, the Digital Markets Act, in effect since March 2024, opens the door to sideloading. Signal could distribute its app via an alternative channel, outside the App Store. It’s technically feasible.

Proton is end-to-end encrypted by design: your emails and files are encrypted by default, Proton has no access. Maximum confidentiality by default. If a geographical block were to occur, a VPN with an IP outside the EU would suffice to bypass it. The VPN is also end-to-end encrypted: two independent layers.

Important note: “leaving the market” would first be a negotiation threat, a political signal. Legal recourse would come first. Signal and Proton know this. So do the legislators. It’s a game of pressure, not an immediate ultimatum.

Read: Why You Need a VPN

Weigh In on the Outcome

The trilogue on May 4th, 2026, is the next tipping point. Public pressure works: the vote on Chat Control 1.0 proves it. The aggressive version was set aside thanks to citizen mobilization.

The EDRi (European Digital Rights) and Patrick Breyer, former Pirate MEP and one of the most consistent voices against this text, maintain tools for direct contact with MEPs. Use them. Write to your representatives. It’s not just activism, it’s applied democracy.

The CSAR isn’t voted yet. It’s not dead yet either.


In Summary

The European Union is preparing a regulation that would turn every smartphone into a silent snitch, scanning every message before it’s encrypted. The stated goal is protecting children. The real effect is mass surveillance infrastructure whose effectiveness the Commission itself can’t prove.

Signal and Proton have drawn a line: rather than compromise encryption, they’d leave Europe. Apple hasn’t said anything. For a Mac user who trusts iMessage daily, this silence should raise questions.

Install Signal. Use Proton Mail. Change your DNS. Contact your MEPs before the May 4th trilogue. These are concrete actions you can take today that reduce your exposure whatever happens.