Chat Control: The EU's playing with your encryption's fate.
What Happened on June 29th
Under Cypriot presidency, the EU Council held what was billed as the fifth and final trilogue on the CSAR regulation, dubbed « Chat Control 2.0 », on June 29th. The presidency’s stated goal was to secure a political agreement before the summer break.
The sticking point remains unchanged. On one side, a Council text that mandates mass surveillance of private communications via ‘detection orders’, a provision that the Council’s own legal service deems contrary to Article 7 of the Charter of Fundamental Rights. On the other, a Parliament that, on March 26, 2026, rejected mass surveillance by a single vote (307 to 306), and is holding firm to end-to-end encryption protection.
As of now, no official source has published the outcome of this trilogue: neither success nor failure confirmed. The Cypriot presidency is pushing for formal adoption in July, but the impasse over encryption could still derail everything. Keep an eye on this silence in the coming days.
Why It Matters to You
Client-side scanning requires inspecting your messages on your device, before they’re encrypted. The crypto of WhatsApp, Signal, or iMessage isn’t broken, it’s neutered: your message is read plaintext on your phone before it’s sent. And this inspection point isn’t reserved for ‘nice guys’, it’s exploitable by any attacker who gets their hands on it.
Adding to this is the mandatory age verification, which requires tying a real identity to your messaging account. It’s the end of default anonymity, sold under the guise of child protection.
What You Can Do
Nothing to install today: it’s a political signal, not a product flaw. But keep Signal as a fallback messaging option, watch your MEP’s positions, and follow EDRi / Patrick Breyer for real-time updates. Once it’s published, we’ll update our articles on the topic.