Chat Control 2.0: The September 29 Trilogue and the Future of Digital Privacy in Europe

The CyberSec Guru

Chat Control 2.0

If you like this post, then please share it:

Buy me A Coffee!

Support The CyberSec Guru’s Mission

🔐 Fuel the cybersecurity crusade by buying me a coffee! Why your support matters: Zero paywalls: Keep the main content 100% free for learners worldwide.

“Your coffee keeps the servers running and the knowledge flowing in our fight against cybercrime.”☕ Support My Work

Buy Me a Coffee Button

What happens when three EU institutions clash over encrypted messages

On September 29, 2026, three delegations will meet at the Council premises in Brussels to try to settle what has become the most contested piece of digital legislation in European Union history. The sixth political trilogue on the Child Sexual Abuse Regulation, known colloquially as Chat Control 2.0, follows four years of drafting, lobbying, legal challenges and public backlash, and five earlier negotiation rounds that all failed to produce consensus. The question before the negotiators is easy to state: may a government order the scanning of every citizen’s private communications, or must detection stay targeted, judicial and specific?

The answer is not a theoretical matter. The outcome of this single meeting will help determine whether 450 million EU citizens keep the right to private digital communication, whether end-to-end encryption survives as a meaningful technical guarantee in Europe, and whether the continent sets a precedent for suspicionless mass surveillance that would make the EU the first democratic bloc to write such a practice into permanent law. The stakes go beyond child protection, a goal almost nobody disputes. They reach the basic design of digital rights, the viability of secure communication infrastructure, and the balance of power between state authority and individual liberty.

This analysis sets out what the September 29 trilogue can decide, what it cannot decide without new mandates, the political arithmetic that determines whether mandatory scanning survives, and what happens to your data whichever way the talks go.

What a trilogue is and why its format limits the outcome

Before the politics, the procedure matters, because the format itself constrains what can come out of the room.

A trilogue is not a vote or a hearing. It is an informal negotiation between three delegations, each carrying a mandate that was agreed elsewhere, at a different time, by a different majority and under different political pressure. The Council’s delegation represents the 27 member state governments and carries the mandate ministers adopted on November 26, 2025. The Parliament’s delegation represents the directly elected MEPs and carries the mandate adopted in the Civil Liberties (LIBE) committee on November 14, 2023 and confirmed by plenary on November 22, 2023. The Commission, which proposed mandatory detection orders on May 11, 2022, has no vote in the room but drafts the compromise language that bridges the two texts.

Because of this, no negotiator can simply change position on the day. Javier Zarzalejos, the LIBE committee chair and Parliament’s rapporteur, cannot sign off on mandatory scanning of all private messages, because his mandate does not allow it. The Council’s negotiators cannot accept the Parliament’s strict “last resort” judicial order framework without checking back with the Permanent Representatives Committee (COREPER), because their November 2025 mandate removed detection orders entirely. The Commission can propose language, but it cannot impose it.

The Irish presidency, which took over on July 1, 2026, confirmed the sixth trilogue for September 29 in Council document 11501/26, dated July 7, 2026. Technical preparatory meetings are scheduled for September 10 and 18. Justice Minister Jim O’Callaghan, who chairs the Council side, has gone on record in support of the mandatory detection text, which puts him at odds with the Parliament’s delegation before the talks begin.

The two mandates: a technical comparison

The distance between the Council and Parliament positions is a difference of kind, not of degree.

Chat Control 2.0: Who Wants What?

Compare the positions of the Council, European Parliament and Commission across the key issues in the negotiations.

Issue
🇪🇺 Council
🏛️ Parliament
🇪🇺 Commission
Mandatory scanning
Position
The Council’s 2025 position does not include mandatory detection orders and instead supports voluntary detection.
Restricted
Parliament’s position supports targeted detection under strict conditions rather than general scanning.
Proposal
The Commission originally proposed detection orders as part of the permanent framework.
End-to-end encryption
No general mandate
The Council position does not establish a general obligation to scan encrypted communications.
Protected
Parliament’s position protects end-to-end encrypted communications from detection orders.
Under negotiation
The Commission acts as the institutional broker during negotiations.
Age verification
Included
The Council position includes mandatory age verification for communication services.
Excluded
Parliament’s mandate does not include mandatory age verification for communication services.
Broker
The Commission can propose compromise language but does not vote in the trilogue.
Judicial authorization
Council framework
The Council position does not use Parliament’s specific last-resort judicial detection framework.
Required
Parliament’s position requires detection to be targeted and authorized by a judicial order.
Negotiator
The Commission helps bridge the institutional positions.
Voluntary scanning
Supported
The Council supports allowing providers to voluntarily detect and report child sexual abuse material.
Limited
Parliament has sought narrower and more targeted temporary measures.
Proposed
The Commission has proposed temporary and permanent frameworks at different stages of the legislative process.
Next step
Trilogue
Negotiate with Parliament toward a common text.
Trilogue
Negotiate with the Council toward a common text.
Broker
Draft and facilitate compromise language between the co-legislators.
🇪🇺 Council Member-state negotiating position
Mandatory scanning
Position
The Council’s 2025 position does not include mandatory detection orders and supports voluntary detection.
End-to-end encryption
No general mandate
No general obligation to scan encrypted communications is established by the Council position.
Age verification
Included
Mandatory age verification for communication services is included in the Council position.
Judicial authorization
The Council position does not adopt Parliament’s specific last-resort judicial detection framework.
Voluntary scanning
Supported
Providers can voluntarily detect and report child sexual abuse material.
Next step
Continue negotiations with Parliament.
🏛️ European Parliament Parliament negotiating position
Mandatory scanning
Restricted
Detection is intended to be targeted and subject to strict conditions rather than general scanning.
End-to-end encryption
Protected
Parliament’s position protects end-to-end encrypted communications from detection orders.
Age verification
Excluded
Mandatory age verification for communication services is not included in Parliament’s mandate.
Judicial authorization
Required
Detection is intended to be targeted and authorized by a judicial order.
Voluntary scanning
Limited
Parliament has supported narrower and more targeted temporary measures.
Next step
Continue negotiations with the Council.
🇪🇺 European Commission Proposal and mediation role
Mandatory scanning
Proposal
The Commission originally proposed detection orders within the permanent framework.
End-to-end encryption
Negotiation
The Commission participates in finding compromise language between the co-legislators.
Age verification
Broker
The Commission can help formulate compromise language but does not vote in the trilogue.
Judicial authorization
Broker
The Commission helps bridge the positions of the Council and Parliament.
Voluntary scanning
Proposed
The Commission has proposed temporary and permanent frameworks during the legislative process.
Next step
Facilitate compromise language during negotiations.
How to read this: The three institutions do not have identical roles. The Council and Parliament are the co-legislators negotiating the text, while the Commission participates in the trilogue and helps formulate compromise language.

The Council’s mandate, adopted on November 26, 2025, removes detection orders (Articles 7 through 11 of the Commission’s original draft) entirely. It does not compel any provider to scan anything. It allows voluntary scanning, so companies such as Meta, Google and Apple may choose to inspect content on their platforms, but no authority can force them to. It also introduces mandatory age verification for communication services, a provision that has drawn substantial criticism from privacy advocates and civil liberties organizations.

📬 Stay Ahead of Cyber Threats

Get the latest cybersecurity news, critical vulnerabilities, threat intelligence, tutorials, and exclusive giveaways delivered straight to your inbox. No spam. Unsubscribe anytime.

Subscribe to the Newsletter →

The Parliament’s mandate, from November 2023, permits detection only under strict conditions. Detection must be a last resort, aimed at specific named suspects and authorized by a judicial order, and it must not touch end-to-end encrypted communications. The text has no provision for general, suspicionless scanning and none for mandatory age verification on communication services. Parliament reinforced this position twice in 2026, on March 26 and July 9, by refusing to extend the temporary voluntary scanning regime.

The Commission sits between the two texts as a broker without a vote. In June 2026, the presidency floated a compromise: voluntary detection for some content categories and mandatory detection for others, split by whether the material is public or non-public. That hybrid failed to close the fifth trilogue on June 29-30, 2026, which ended without agreement.

What the negotiators can agree on September 29

What Can Actually Happen on September 29?

Tap an outcome to see where the Chat Control 2.0 negotiations could go next.

🇪🇺 September 29, 2026 Sixth political trilogue between the Council, European Parliament and European Commission in Brussels.
Council mandate
November 2025 position
  • No mandatory detection orders in the adopted text
  • Voluntary scanning remains possible
  • Mandatory age verification included
Parliament mandate
November 2023 position
  • Detection only as a last resort
  • Named suspects + judicial authorization
  • End-to-end encryption protected
🤝 Negotiators look for overlap Risk assessments, the EU Centre, reporting duties, transparency and technical infrastructure can potentially be settled without changing either mandate.
Provisional agreement The negotiated text would still need formal steps afterward. The article identifies COREPER, the LIBE committee and ultimately the full Parliament as relevant approval stages.
No agreement Nothing immediately collapses. Chat Control 1.0 remains in force until April 3, 2028, voluntary scanning continues, and the file passes to the next Council presidency.
New mandate required Mandatory scanning of private messages, a major change to the encryption framework, or mandatory communication-service age verification would raise issues that the current mandates do not simply authorize negotiators to settle in the room.
Agreement path Status quo path Mandate constraint

The overlap between the two mandates is real but narrower than media coverage suggests. Both texts support an EU Centre on child sexual abuse, which would coordinate reporting, maintain databases of known illegal material and act as a clearinghouse between providers and national law enforcement. Both impose risk assessment and mitigation duties on service providers, who must evaluate their platforms for vulnerability to exploitation and put reasonable safeguards in place. Both set reporting obligations to national authorities when illegal content is identified, and both require providers to publish regular reports on their moderation activity.

The negotiators can also settle the institutional machinery: governance structures for the EU Centre, data flow protocols between providers and authorities, publication timelines for transparency reports, and technical standards for hash-matching databases of known child sexual abuse material (CSAM). These provisions are not trivial. They will form the operational backbone of whatever law eventually passes. But they do not touch the core constitutional question of whether the state may order the scanning of private communications without individual suspicion.

A deal is achievable on September 29 only where the text can honestly be read as consistent with both mandates: detection that is targeted, authorized by a court, directed at named suspects and kept away from end-to-end encrypted channels. The negotiators could agree on that framework without going back to their principals.

What the negotiators cannot agree without new mandates

Three categories of decisions lie beyond the authority of the people in the room on September 29.

Mandatory scanning of private messages

The Parliament’s delegation is bound by a text that permits detection only against named suspects on a judicial order. A general obligation to scan every user’s messages, regardless of suspicion, falls outside that mandate. Zarzalejos cannot sign it. He would have to return to the LIBE committee, win a new mandate and bring it to the full Parliament for approval. Appetite for that is minimal. On July 9, 2026, Parliament cast 314 votes to reject even the temporary voluntary scanning regime. That motion failed only because it needed an absolute majority of all members (360 that day), not because support was lacking. A mandatory regime would ask the same chamber for far more, and the arithmetic does not favor it.

The Council faces the inverse constraint. Its delegation cannot accept the Parliament’s “last resort” judicial order framework without returning to COREPER, where any provisional agreement needs a qualified majority. To block one, at least four member states representing more than 35 percent of the EU population must oppose it. As of September 2026, nine governments representing 32.9 percent of the population are on record against mandatory scanning of private messages, which is 2.1 percentage points short of a blocking minority. Three governments could close that gap: Germany (18.47 percent), Belgium (2.63 percent) and Portugal (2.38 percent). None has formally declared against mandatory detection. Germany’s public position rejects suspicionless scanning, but the instructions its negotiators have carried since June 2026 do not oppose mandatory detection where it supplements voluntary scanning. Italy, Poland and the Netherlands carry 25.5 percent between them, so the opposing bloc cannot afford to lose any one of the three swing states.

Client-side scanning of encrypted services

This provision drew the fiercest opposition during the Danish presidency in 2025. Client-side scanning does not technically break end-to-end encryption. It bypasses it by inspecting content on the user’s device before encryption happens. The messaging app reads the message, runs it through a detection algorithm and reports matches to authorities, all before the content is encrypted and sent. For the user, the effect is the same as having no encryption at all.

Parliament’s mandate explicitly protects end-to-end encryption. In February 2024, in Podchasov v. Russia, the European Court of Human Rights ruled that requiring providers to weaken encryption cannot be regarded as necessary in a democratic society. The Council’s own Legal Service told ministers on April 26, 2023, in opinion 8787/23, that ordering a service to scan all users’ communications amounts to “general and indiscriminate screening.” It repeated the objection in May and June 2026. Negotiators may not rewrite the Charter of Fundamental Rights, and they know it.

The scope of age verification

Mandatory age verification for communication services is less technically dramatic than scanning, but it is a significant privacy intervention. Users would have to prove their age before using messaging platforms, which effectively ends anonymous communication and creates centralized databases of identity-linked usage records. Parliament’s mandate excludes mandatory age verification for communication services. The Council’s text includes it. Settling that requires a conversation about mandates that cannot happen in a single afternoon of negotiation.

How detection orders would work in practice

For readers unfamiliar with how modern communication systems are built, it helps to spell out what a detection order compels and what it cannot.

A detection order can reach only what a provider can read. For services that store messages in plaintext or with server-side encryption keys, such as traditional email providers, some social media messaging features and cloud storage, a detection order is straightforward. The provider’s servers hold readable content, and automated systems can scan it against databases of known illegal hashes or run machine learning classifiers to flag previously unknown material.

End-to-end encrypted services such as Signal, WhatsApp, iMessage and Threema work differently. Content is encrypted on the sender’s device and decrypted only on the recipient’s. The server stores only ciphertext and holds no key that could decrypt it, so a detection order served on the server achieves nothing. Client-side scanning was proposed as the workaround: rather than scanning at the server, software on the user’s phone or computer inspects messages before they are encrypted for transmission.

The Council’s Legal Service saw this as a distinction without a practical difference. If every message is inspected before sending, encryption offers no meaningful privacy guarantee, wherever the inspection technically occurs. The Danish presidency’s 2025 proposal, championed by Justice Minister Peter Hummelgaard, pushed for exactly this client-side approach. Hummelgaard said publicly that “we must break with the totally erroneous perception that it is everyone’s civil liberty to communicate on encrypted messaging services.” The proposal was ultimately withdrawn under heavy public pressure.

Detecting “unknown” CSAM, meaning material not already catalogued in hash databases, adds a further problem. It requires machine learning classifiers trained on imagery, and such systems carry significant false positive rates. Under the temporary regulation (Chat Control 1.0), providers must publish their first public reports on error rates and false positives by February 1, 2027, which will give the first hard data on how these systems perform at scale.

Why Chat Control faces serious constitutional challenges

European Digital Rights (EDRi) has described the Child Sexual Abuse Regulation as the “most criticized law of all time.” The legal objections go beyond political posturing. They concern the design of the regulation itself.

The EU Charter of Fundamental Rights guarantees the right to private life (Article 7) and the right to protection of personal data (Article 8) to all persons within the Union. The European Parliament’s own Scientific Service concluded in 2024 that the CSAR proposal “would violate Articles 7 and 8 of the Charter of Fundamental Rights with regard to users” when weighed against the fundamental rights affected by its measures. The Council’s Legal Service has issued multiple opinions, in April 2023, May 2026 and June 2026, stating that general, indiscriminate scanning of all communications is incompatible with EU law.

The Court of Justice of the European Union has held, in a line of cases including Digital Rights Ireland (2014), Tele2 Sverige (2016) and La Quadrature du Net (2020), that general and indiscriminate retention of or access to communications data is disproportionate and violates the Charter. A mandatory scanning regime that inspects all private communications without individualized suspicion falls squarely within the category of measures the Court has struck down. The German Federal Constitutional Court has likewise declared data retention legislation unconstitutional several times, most recently reinforcing that mass surveillance of communications is disproportionate.

The European Court of Human Rights added to this in February 2024 with Podchasov v. Russia, which established that compelling providers to weaken or bypass encryption cannot be regarded as necessary in a democratic society. The ruling binds all 46 Council of Europe member states, including all 27 EU members.

If the CSAR passes in a form that includes mandatory detection orders, challenges before the CJEU are virtually certain, and the existing case law strongly suggests the provisions would be annulled.

The lobbying question: who benefits from mandatory scanning?

The lobbying controversy has followed the legislation since 2022 and belongs in any analysis of it. Research published in September 2023 revealed extensive lobbying by AI companies and organizations that stood to gain financially from mass scanning infrastructure.

The investigation identified Thorn, the organization founded by actor Ashton Kutcher, alongside the WeProtect Global Alliance, a government-affiliated institution closely linked to ex-diplomat Douglas Griffiths and his Oak Foundation. The Oak Foundation has invested more than $24 million in lobbying for Chat Control since 2019 through networks including Ecpat, Brave and the PR agency Purpose. Multiple AI companies with content moderation products stood to win large contracts if scanning became mandatory across EU communication platforms.

EDRi’s head of policy, Diego Naranjo, said the research “confirms our worst fears” and called the regulation “the product of lobbying by private companies and law enforcement.” Civil society organizations have also criticized former EU Commissioner Ylva Johansson, who proposed the original regulation, accusing her of ignoring scientific evidence and expert testimony in favor of industry-aligned solutions.

None of this makes child protection concerns illegitimate. It does mean that actors with a financial interest in the outcome have shaped the policy debate, and that the technical solutions on offer are not necessarily the most effective way to protect children. Targeted investigations, better international cooperation, better-resourced law enforcement and work on the root causes of exploitation would all serve children more effectively than scanning every citizen’s messages, but none of those approaches generates revenue for AI companies.

The exemption for government communications

One provision in the draft regulation has drawn particular criticism. Non-public communication services, including military and government accounts, are exempt from scanning requirements. The stated rationale is the protection of “confidential information, including classified information.”

The same EU institutions that would compel Signal to scan every message sent by a nurse in Lisbon or a teacher in Kraków would not subject their own communications to the same treatment. Government ministers, military personnel and diplomats would keep full encryption and privacy protections. Citizens and businesses would not. Privacy advocates across the political spectrum have pointed to this asymmetry as evidence that the legislation’s true function is surveillance infrastructure rather than child protection, arguing that its designers plainly consider encryption essential for their own security while treating it as an obstacle when the public uses it.

Chat Control 1.0: the law already in force

Chat Control 1.0 vs 2.0

The temporary regime already allows voluntary scanning. The proposed permanent framework is where the bigger legal and technical questions arise.

Key issue
Chat Control 1.0
Chat Control 2.0
Legal status
Temporary
Regulation (EU) 2026/1881 is described in the article as the temporary regime and remains in force until April 3, 2028.
Permanent framework
The Child Sexual Abuse Regulation is the proposed long-term framework being negotiated by the institutions.
Detection / scanning
Voluntary
Providers may voluntarily scan content that they can technically access.
Main dispute
The major dispute concerns whether detection orders should exist and under what conditions.
End-to-end encryption
Excluded
The article states that the temporary regulation excludes end-to-end encrypted communications following a Parliament amendment.
Major battleground
Parliament’s mandate protects E2EE, while client-side scanning has been proposed as a possible workaround.
Judicial authorization
Not the core model
The temporary regime is based on voluntary provider scanning rather than individualized detection orders.
Proposed safeguard
Parliament’s position would allow detection only as a last resort against named suspects under a judicial order.
Age verification
Not the focus
The article’s discussion of the temporary regime does not identify mandatory communication-service age verification as its central mechanism.
Disputed
The Council’s 2025 text includes mandatory age verification for communication services, while Parliament’s mandate excludes it.
Client-side scanning
No
The article describes the temporary regime as excluding end-to-end encrypted communications.
Proposed concept
Client-side scanning has been discussed as a way to inspect content before encryption occurs.
Transparency
Reporting
Providers must publish information about their scanning activity, including upcoming error-rate and false-positive reporting.
Permanent rules
The proposed framework would establish longer-term reporting, oversight and institutional structures.
What happens next?
Expires 2028
The temporary regulation remains in force until April 3, 2028.
Negotiations
The permanent regulation remains under negotiation through the Council, Parliament and Commission.
Chat Control 1.0 Temporary regime
Legal status
Temporary
Regulation (EU) 2026/1881 remains in force until April 3, 2028.
Detection / scanning
Voluntary
Providers may voluntarily scan content they can technically access.
End-to-end encryption
Excluded
The article states that E2EE communications are excluded following a Parliament amendment.
Judicial authorization
The temporary regime is based on voluntary provider scanning rather than individualized detection orders.
Client-side scanning
No
The article describes E2EE communications as excluded from the temporary regime.
What happens next?
2028 expiry
The temporary regulation remains in force until April 3, 2028.
Chat Control 2.0 Proposed permanent framework
Legal status
Under negotiation
The permanent Child Sexual Abuse Regulation remains under negotiation.
Detection / scanning
Main dispute
The central dispute concerns detection orders and the conditions under which detection could become mandatory.
End-to-end encryption
Major battleground
Parliament’s mandate protects E2EE. Client-side scanning has been discussed as a possible technical workaround.
Judicial authorization
Parliament position
Parliament’s mandate requires targeted detection, named suspects and judicial authorization.
Age verification
Disputed
The Council includes mandatory age verification for communication services, while Parliament’s mandate excludes it.
What happens next?
Trilogue
The Council, Parliament and Commission continue negotiating the permanent framework.
The key difference: Chat Control 1.0 is the temporary framework already allowing voluntary scanning, while Chat Control 2.0 is the permanent legislation being negotiated. The biggest unresolved questions are whether detection orders should exist, how targeted they should be, what happens to end-to-end encryption, and whether communication services should require age verification.

Scanning is already happening, whatever the trilogue produces. Regulation (EU) 2026/1881, known as Chat Control 1.0, has been in force since 2024 and remains valid until April 3, 2028. It allows providers to scan voluntarily the content they can access, and it excludes end-to-end encrypted communications following a Parliament amendment. Whatever happens on September 29, Meta, Google, Microsoft and other major platforms keep the legal authority to inspect messages, photos and files on their services.

The temporary regulation sets three upcoming deadlines that will produce significant data on the real-world impact of scanning:

  • October 1, 2026: The Commission must publish the list of organizations that receive reports about European citizens’ communications.
  • February 1, 2027: Providers owe their first public reports on error rates and false positives in their scanning systems.
  • April 1, 2027: The grace period ends for providers that were already scanning before July 31, 2026, without completing a data protection impact assessment.

These dates will show more about what scanning actually does than any trilogue negotiation will: how many false positives it generates, which organizations receive flagged content, and whether data protection safeguards are being honored.

What happens if September 29 produces no deal

Little changes in the short term, and that is the point.

If the trilogue ends without agreement, as the fifth round did on June 29-30, the file passes to the next presidency. Ireland holds the Council presidency until December 31, 2026. Lithuania takes over on January 1, 2027, followed by Greece on July 1, 2027. Every presidency since the file was opened has inherited it, and none has closed it. The Danish presidency spent months crafting a proposal that ultimately collapsed. The Hungarian and Swedish presidencies before it made no meaningful progress. No procedural deadline forces a resolution.

Chat Control 1.0 stays in force until 2028 regardless. Voluntary scanning continues, as do the EU Centre’s work and provider obligations under the temporary regime. The lack of a permanent regulation does not create a legal vacuum. It preserves a status quo that already allows significant scanning activity.

The Irish presidency’s planning documents point to a push for formal adoption in October 2026, with Justice and Home Affairs ministers meeting in Luxembourg on October 1-2. The file is not on the draft agenda the Council published in June, however, so anything the negotiators produce would reach ministers under “any other business.” Formal endorsement of a provisional agreement belongs to COREPER, not the ministerial council.

What to watch on September 29

The wording of the post-trilogue press release will show within minutes what happened. “Provisional agreement” means a text exists and is heading to COREPER and the LIBE committee for formal approval. “Progress” or “constructive exchange” means it does not.

If a text does exist, three questions determine its significance. Does it contain detection orders at all? If so, who issues them (a judge, an administrative authority or a government minister), and against whom are they directed, named suspects or the general population? Does it say anything about encrypted services beyond leaving them alone?

The answers will indicate whether the regulation works as a child protection framework or as a mass surveillance architecture dressed in protective language.

The German question: how one country’s ambiguity could decide the vote

Germany holds a pivotal position in the negotiation. At 18.47 percent of the EU population, it is the largest member state, and its stance on mandatory scanning largely determines whether a blocking minority can be assembled.

Germany has historically been Europe’s strongest opponent of mass surveillance, a position rooted in the experience of the Stasi in East Germany and in the constitutional tradition of information self-determination. The German Federal Constitutional Court has struck down data retention legislation several times. German civil society organizations, including Digitalcourage, have been among the most vocal opponents of Chat Control.

The government that took office in May 2025 has taken a more ambiguous line. Its public statements reject suspicionless scanning, but the instructions its negotiators have carried since June 2026 do not oppose mandatory detection where it supplements voluntary scanning. That equivocation is the most consequential variable in the September 29 arithmetic. If Germany moves firmly against mandatory scanning, the blocking minority threshold is met. If it keeps its current ambiguity, the mandatory text survives.

Germany’s data retention history offers a parallel. Politicians pushed retention requirements for years, faced repeated constitutional annulments and eventually settled on a compromise that explicitly excluded emails as a form of personal communication deserving privacy. Whether Chat Control follows the same path, with years of legal challenges, eventual narrowing and ultimate gutting, depends on whether the current government holds firm.

Age verification: the new battleground

With mandatory scanning of encrypted messages increasingly untenable politically and legally, the draft regulation’s age verification requirements have become the new focus of the fight. The Council’s November 2025 text includes mandatory age verification for communication services. The Parliament’s mandate explicitly excludes it.

Age verification for messaging platforms would require every user to prove their age before using a communication tool, typically through government ID, credit card verification or third-party age assurance services. The privacy implications are serious. It eliminates anonymous communication, creates centralized databases linking real identities to platform usage and builds infrastructure that could be repurposed for broader surveillance. It also falls hardest on vulnerable people who rely on anonymous communication for safety: domestic abuse survivors, political dissidents, journalists’ sources and LGBTQ+ individuals in hostile environments.

The trend is already visible in platform behavior. YouTube has begun requesting age verification in certain contexts, and Discord has announced plans for universal age verification. The framework the EU adopts will either constrain or accelerate this industry-wide shift toward identified, surveilled communication.

AI, privacy and the pressure to scan

Chat Control arrives amid a wider debate over the role of artificial intelligence in surveillance and content moderation. Users are increasingly aware of how AI systems process their data. The backlash against Google’s Gemini integration, Meta’s AI features in WhatsApp and LinkedIn’s silent enrollment of users into AI training programs reflects growing public resistance to feeding personal data into opaque algorithmic systems.

Deploying AI classifiers to scan private communications would mean making probabilistic judgments about whether an image or message is illegal content, with the false positive risk that entails. It would be the most invasive application of AI surveillance yet proposed in a democratic jurisdiction. The false positive problem is not hypothetical: at the scale of billions of daily messages, even a 1 percent error rate produces tens of millions of incorrect flags annually, each potentially exposing intimate personal content to human reviewers or automated reporting systems.

The EU’s own AI Act, which sorts AI deployment into risk-based categories, would classify mass communication scanning as a high-risk application requiring conformity assessments, transparency obligations and human oversight. Whether the CSAR’s scanning provisions comply with the AI Act is an open question that adds another layer of legal uncertainty to the regulation.

What the outcome means for users

For the 450 million people living in the EU, the negotiation bears on several concrete realities.

If mandatory scanning passes, every message, photo and file sent through a covered platform could be inspected by an algorithm before it reaches its recipient. End-to-end encryption would become meaningless if client-side scanning were mandated, because the inspection happens on the user’s device before encryption is applied. The communication provider would become an agent of state surveillance, acting under compulsion rather than by choice.

If targeted judicial orders pass, detection remains possible but requires a judge to name a specific suspect and authorize the intrusion. Communications are not scanned unless a person is personally suspected of a crime and a court has reviewed the evidence. Encryption stays intact as a technical guarantee.

If no deal is reached, the status quo continues. Voluntary scanning persists under Chat Control 1.0 until 2028, and providers scan what they can access. Encrypted messages remain protected from server-side scanning. No new mandatory obligations are imposed, but no new protections are created either.

Whatever the outcome, age verification pressure will continue from both regulation and industry trends. The EU Centre begins operations, transparency reports start to appear, and the oversight infrastructure, imperfect as it is, begins generating data on what scanning catches, what it misses and what it incorrectly flags.

What civil society wants instead

The coalition opposing Chat Control in its current form includes EDRi, Digitalcourage, the Chaos Computer Club, Access Now, the Electronic Frontier Foundation, the Signal Foundation and hundreds of academics, technologists and legal scholars. Its members say they are not opposing child protection. They oppose suspicionless mass scanning as the means of achieving it.

Their alternative framework calls for properly resourced law enforcement to run targeted investigations, better international cooperation to pursue offenders across borders, prevention programs that address the root causes of exploitation, robust and rights-respecting content moderation by platforms, and judicial authorization, proportionality testing and meaningful oversight for any detection technology that is deployed.

The 69 opposing voices compiled by EDRi, among them EU politicians, member state governments, technology companies and child protection experts, reflect an unusually broad consensus that the proposed mechanism is wrong even if the goal is right. One child protection researcher quoted in the EDRi collection noted that mass scanning diverts resources from effective interventions while creating a surveillance infrastructure that will inevitably be repurposed for other objectives.

what the September 29 trilogue can and cannot settle

On September 29, approximately thirty people will sit in a room in Brussels and decide, or fail to decide, the future of private communication in Europe. They carry mandates they did not write, from institutions they do not control, and they work within legal opinions they did not commission and political arithmetic they cannot change. The space for agreement is narrow. On any honest reading of the mandates and the law, the space for mandatory mass scanning is nonexistent.

Politics does not always follow honest readings, though. The Irish presidency wants a deal. The Commission wants a legacy. Some member states want the file closed before their own electoral cycles intervene. The pull to paper over contradictions with ambiguous language, calling mandatory scanning “risk-based detection” or dressing age verification in child-safety terminology, will be strong.

What happens afterward matters more than what happens in the room. A provisional agreement would face COREPER, the LIBE committee and ultimately the full Parliament. If it contains mandatory scanning, legal challenges begin the day it is published. If it mandates age verification, implementation fights will occupy years. If the talks fail, the file passes to Lithuania, then Greece, then whoever follows, and the question stays open.

September 29 will not settle Chat Control in any of these scenarios. The file moves on to COREPER, to Parliament or to the next presidency, and the legal and political fight over it continues.

This article will be updated following the September 29 trilogue. For ongoing coverage of EU digital rights legislation, bookmark this page and follow our regulatory analysis series.

Key dates to watch

DateEvent
September 10, 2026Technical preparatory meeting (Council)
September 18, 2026Second technical preparatory meeting
September 29, 2026Sixth political trilogue
October 1, 2026Commission publishes list of reporting organizations
October 1-2, 2026Justice and Home Affairs Council, Luxembourg
December 31, 2026Irish presidency ends; Lithuania takes over
February 1, 2027First provider transparency reports due
April 1, 2027Grace period ends for pre-existing scanners
April 3, 2028Chat Control 1.0 expires

Sources and further reading

Disclosure: This analysis draws on publicly available Council documents, Parliament voting records, court decisions, and reporting from civil society organizations. Position statements attributed to member states are based on recorded Council interventions and published government positions as of September 8, 2026.

Buy me A Coffee!

Support The CyberSec Guru’s Mission

🔐 Fuel the cybersecurity crusade by buying me a coffee! Your contribution powers free tutorials, hands-on labs, and security resources.

Why your support matters:
  • Writeup Access: Get complete writeup access within 12 hours
  • Zero paywalls: Keep the main content 100% free for learners worldwide

Perks for one-time supporters:
☕️ $5: Shoutout in Buy Me a Coffee
🛡️ $8: Fast-track Access to Live Webinars
💻 $10: Vote on future tutorial topics + exclusive AMA access

“Your coffee keeps the servers running and the knowledge flowing in our fight against cybercrime.”☕ Support My Work

Buy Me a Coffee Button

If you like this post, then please share it:

News

Discover more from The CyberSec Guru

Subscribe to get the latest posts sent to your email!

Leave a Reply

This site uses Akismet to reduce spam. Learn how your comment data is processed.

Discover more from The CyberSec Guru

Subscribe now to keep reading and get access to the full archive.

Continue reading