Chat Control 2.0: The EU wants to scan all your private messages

Under the guise of protecting children, the EU is rushing to set up mass surveillance infrastructure for all encrypted messaging platforms.

The European Union is moving towards a law that would force encrypted messaging apps to scan all private messages. The stated goal: protecting children. The reality: unprecedented mass surveillance in a democracy. And the Commission has admitted that it doesn’t know if it works.

What’s happening

First, let’s untangle two texts that are often confused.

On the substance: everyone agrees on fighting child pornography. It’s a legitimate, urgent, universally shared goal. What this case puts up for debate are not the ends, but the means. And the means here pose a serious problem.

Chat Control 1.0 is a partial victory. On March 6, 2026, the European Parliament voted to extend the ePrivacy derogation until August 3, 2027, with 458 votes for, 103 against, and 63 abstentions. The old derogation expired on April 3, 2026, and this extension replaces it. Crucially, the resolution explicitly protects end-to-end encryption, with measures not applicable to E2EE communications. It’s not “dead”, it’s a stay with a shield.

Chat Control 2.0, also known as CSAR (Child Sexual Abuse Regulation), is another story. And it’s still ongoing.

The Council of the EU adopted its position on November 26, 2025, with only three countries against, including Poland and the Netherlands. Since December 2025, the text has been in trilogue, this opaque negotiation phase between Parliament, Council, and Commission. Next trilogue: May 4, 2026. Targeted adoption: July 2026.

The concrete mechanism: messaging services deemed “high risk” would be forced to apply “risk mitigation measures” and “voluntary detection activities”. These formulations replaced the original “client-side scanning” term, deemed too transparent in 2022.

The practical effect, though, is identical according to the EDRi (European Digital Rights), EFF, and noyb: before sending a message, your device scans it and compares its content to a database. If a match is found, the result is transmitted to authorities.

It sounds clean and targeted. In practice, it’s a spy installed on your device, reading every message before you send it, without your knowledge or consent. The database decides what’s suspicious. False positives exist. Awkward when it’s you they concern, no?

And once this infrastructure is normalized for an unassailable cause, nothing stops it from being extended to other contents, political opinions, journalism, union communications. The tool is there. It just takes changing the list.

A clause formally protects encryption, without explicitly banning this mechanism. The EFF considers this protection insufficient, and they’re right: encryption that’s read before it’s encrypted is just for show.

The worst part? The European Commission itself published an implementation report, COM(2025)740, containing this remarkable admission: there’s no proven link between scanning private messages and actual convictions or rescued children. That’s not a quote from some libertarian activist. It’s the Commission, in its own document.

Read soon: End-to-end encryption, how it really works

Why it’s important for you

What the text creates concretely: a legal obligation to install a software backdoor on every device, in every messaging app used by Europeans. Signal, iMessage, WhatsApp, Telegram, Proton Mail. All concerned if the law passes as is.

Read soon: Meta ruling: when encrypting becomes a legal fault

Signal was direct. Meredith Whittaker, executive director, declared in October 2025: Signal would “unfortunately decide to leave the European market” rather than compromise its encryption. Signal is a non-profit association, with no shareholders to satisfy. When they say that, it’s credible.

Proton, under Swiss jurisdiction, same position: “we’d rather be blocked”. Real distance from both American and European law.

Apple abandoned its own client-side scanning project in December 2022 after massive backlash from the security research community. No official statement on CSAR, but opposition is known.

The precedent is political as much as technical. If the EU normalizes mandatory scanning of encrypted communications, nothing stops states from using it to spy on their citizens about anything.

What you must do

Now, concretely:

Use Signal or Proton for your communications. Not because they’re perfect, but because they’re natively end-to-end encrypted and have publicly stated they’d leave the market rather than comply. That’s the only credible guarantee right now. And change your DNS.

Read: Why you need a VPN

If Signal or Proton leave the EU:

Signal distributes its Android APK directly on signal.org. On iOS, the EU’s DMA, in effect since March 2024, opens the door to sideloading: Signal could distribute outside the App Store via its own channel.

And “leaving the market” would first be a negotiation threat, not an immediate closure. Legal challenges would come first.

Proton, under Swiss jurisdiction, has stated it prefers being blocked rather than complying. Its servers remain in Switzerland, outside EU jurisdiction, and the webmail remains accessible without an app.

VPN: an IP outside the EU suffices to bypass a potential geographic block. Note: if Signal or Proton maintain their servers and encryption intact, the VPN doesn’t protect your data, it just gives you access to the service. It’s not the same thing.

DNS: change the DNS resolvers on all your devices. If EU ISPs are forced to block domains, an out-of-jurisdiction DNS resolver circumvents this block. Quad9 (9.9.9.9), managed by a Swiss non-profit association, doesn’t log your queries. Mullvad DNS (194.242.2.2) is another solid option, managed by the Swedish VPN provider of the same name, with no logging. Important note: putting it in Network Settings → DNS is enough to avoid your ISP’s resolver, but queries go in the clear on the network (UDP port 53).

To encrypt DNS queries (DNS-over-HTTPS), both providers offer Apple configuration profiles to install via Safari. Search “Quad9 Apple profile” or “Mullvad encrypted DNS profile”: installation takes two minutes, and your DNS queries are natively encrypted.

On the substance:

The May 4, 2026 trilogue is the next turning point. Organizations like EDRi and Patrick Breyer (former Pirate MEP, one of the most consistent voices against this text) maintain tools for direct contact with MEPs. It works. The Chat Control 1.0 vote proves: public pressure changes votes.

It’s not lost yet. But it won’t happen on its own.

Coming soon:

I’m preparing a comprehensive article on locking down your communications and data. DNS encryption, trustworthy VPN, secure browser, resistant messaging apps, hardened macOS and iOS configuration. Concrete steps, tested, that you can apply in one afternoon.

If the EU decides your private messages aren’t yours anymore, better have your machine ready first.

Sources