Chat Control 1.0: Adopted by Those Who Voted Against
On July 9th, the European Parliament allowed Chat Control 1.0 to be renewed, falling short of the 361 votes needed to block it, despite a majority voting against. What this means, and what's heading back to trilogue in September.
What Happened on July 9th
On July 9th, 2026, the European Parliament renewed Chat Control 1.0, i.e., Regulation (EU) 2021/1232: an exemption to the ePrivacy directive that allows providers to voluntarily scan communications for child sexual abuse material (CSAM). This text had expired on April 3rd, 2026. It’s been renewed, in effect until April 3rd, 2028.
The detail that matters: it wasn’t adopted by a yes vote. The count was 314 against, 276 for, 17 abstentions. The majority of voters said no. But to reject the Council’s position, you needed an absolute majority of 361 votes, which was missed by 47. Result: the text passes due to lack of blocking. Patrick Breyer calls it a democratic farce, and on this point, he’s not entirely wrong.
Second detail, denounced by several MEPs: the dossier was rescheduled at the very start of the parliamentary holidays, when the hemicycle is sparsely populated. A classic scheduling move, but an effective one.
Debunk Express
Three falsehoods have been circulating since July 9th. Here’s the reality check.
“The Parliament voted FOR Chat Control.” False. 314 voted against, 276 for: the majority voted no. The text passes because the threshold to block it, 361 votes, wasn’t reached, not because it was approved.
“WhatsApp, Signal, iMessage will be scanned.” False. A Renew amendment adopted on the same day explicitly excludes end-to-end encryption from the scope of this text. The 1.0 remains voluntary scanning, outside of E2E.
“This is the big mandatory Chat Control that just passed.” False. The text of July 9th is the voluntary 1.0. Mandatory scanning, potentially client-side on E2E, is the CSAR (Chat Control 2.0), still in trilogue, to be revisited in September.
Two texts, two stories. The 1.0 is voluntary and excludes E2E. The 2.0 is the real danger, and it’s not settled yet.
Why It Concerns You
On your Mac and iPhone, the 1.0 doesn’t change anything today: your iMessage, WhatsApp, Signal remain end-to-end encrypted, explicitly outside the scope of this text. Don’t let anyone sell you a product panic that doesn’t exist.
But this text isn’t limited to messaging apps. It also covers emails, and here, the nuance changes everything: a regular email (Gmail, Outlook, iCloud Mail) isn’t end-to-end encrypted. It’s fully within the scope of the voluntary scan that the 1.0 prolongs.
Google and others can scan the content of your emails for CSAM, and the E2E exclusion won’t protect you, since there’s no E2E to protect. Only a genuinely end-to-end encrypted messaging service, like Proton Mail, slips through the net.
Consider what this means. It’s like the Police reading your mail when you’ve done nothing wrong. It’s like something out of the Stasi!
The real risk has another name: client-side scanning by the CSAR 2.0. That’s the principle of inspecting your messages on your device before they’re encrypted. The crypto isn’t broken, it’s emptied of its meaning: your message is read in plaintext on your phone before it’s sent. And once that inspection point is in place, it belongs to the “nice guys” forever.
It’s not science fiction on Apple’s side. In 2021, Apple announced NeuralHash, a system for client-side CSAM scanning on iPhones, before abandoning it in December 2022 under pressure. The code exists, the logic does too.
A binding CSAR would be exactly the lever that would reopen this dossier, this time by law and not by choice. The lawsuit against Apple by West Virginia in February 2026 shows that judicial pressure on this issue isn’t letting up.
What You Can Do
Nothing to install, nothing to fix on your device: the 1.0 opens no product vulnerabilities. It’s a political signal, and a lesson in method: a text rejected by the majority of voters can still pass when the blocking threshold isn’t reached. Remember the mechanism, because it’ll come up again in September.
The appointment is the CSAR at the September 2026 restart. Five rounds of trilogue without agreement, the last on June 29th, and the fracture line remains encryption.
Keep Signal as a fallback messaging service, follow EDRi and Patrick Breyer for the real outcome, and write to your MEP before the 2.0 comes back on the table. Public pressure has already shifted lines on this dossier before, it can do so again.
To dig deeper: Chat Control 2.0, the complete mechanism · NIS2 vs CSAR, when the EU contradicts itself · The global convergence of anti-privacy texts