In this analysis
01 · Has the proposed permanent EU Chat Control regulation passed? No—and the architecture question is still real.02 · Three layers the debate keeps collapsing into one03 · The system behind the system: the Confidentiality Chain04 · What end-to-end encryption protects—and what it never promised05 · Detection is not one technical act06 · The strongest case for intervention is morally serious—and technically incomplete07 · Are WhatsApp and Signal affected? A simple yes or no is misleading.08 · The Communication Exposure Audit09 · What would change this diagnosisHas the proposed permanent EU Chat Control regulation passed? No—and the architecture question is still real.
Conflating an approved interim measure, a permanent proposal, and a technical capability produces either panic or false reassurance.
As of September 9, 2026, the EU's permanent framework for combating online child sexual abuse has not been adopted. Negotiations continue. The Commission's 2022 proposal, Parliament's position, and the Council's negotiating mandate are different texts with materially different intervention models.
A separate temporary measure has been approved and reinstated. It permits providers to use certain voluntary practices to detect, report, and remove abuse material. It is not a general duty to inspect every private message. The 2026 text expressly excludes interpersonal communications to which end-to-end encryption applies and runs through April 3, 2028.
So the claim that the EU is now scanning every WhatsApp or Signal message is wrong. The claim that the issue is over is equally complacent. A credible position holds both facts: the approved interim framework is narrower than many headlines suggest, while the permanent architecture remains unsettled.
Scenario, not a reported case: On the evening before an acquisition, a founder sends an unresolved decision to family members and two advisors. The service encrypts it between endpoints. A preview appears on a linked tablet, an old cloud backup remains readable, and a former assistant still holds group-admin privileges. No EU system had to read the message. It was still not confidential end to end. That gap between a product symbol and the real communications environment is where this analysis begins.
“Privacy does not begin only when someone reads a message. It weakens when the communications path itself becomes an inspection point.”
Three layers the debate keeps collapsing into one
Current law, a political design, and a technical capability are not interchangeable.
Layer one is current law: the temporary, voluntary ePrivacy derogation with defined scope and safeguards. Layer two is the permanent legislative process, where institutions are negotiating text that can still change. Layer three is technology: hashing, classifiers, and endpoint inspection may be built or discussed without being legally mandated.
The label Chat Control attracts attention but explains no mechanism. An architect asks who may trigger a measure, against what threshold, what a provider must do, where content is inspected, how a hit is escalated, who confirms it, and what notice and remedy follow.
Precision does not sand off the edge. It makes the edge defensible. Protecting children is a legitimate and urgent objective. That fact cannot, by itself, settle whether every proposed technical architecture is necessary and proportionate.
A forceful diagnosis becomes more credible when every claim carries its exact legal and technical status.
Effective confidentiality is constrained by its weakest critical transition.
01Legal scope
02Endpoint
03E2EE channel
04Account & identity
05Metadata
06Correction
The system behind the system: the Confidentiality Chain
No single actor controls the entire system. Practical power accumulates across handoffs.
The chain begins with a legal trigger and scope. That can create a provider permission or duty. The provider operates a detection surface. A tool classifies content or conduct. A hit is rejected, confirmed, or reported. Authority review, human judgment, action, notice, and remedy follow.
Each handoff changes the risk. An individually authorized measure is not blanket monitoring. Matching confirmed known files is not the same as predicting whether a new image or a conversation is unlawful. An automated flag is not a verified report, and a report is not proof of guilt.
The decisive architecture lies in thresholds, error budgets, and escalation. Reducing the debate to encrypted or unencrypted misses the process. Describing every institution as one command center is just as misleading.
“Modern control rarely arrives in uniform. It arrives as an update, a threshold, and a process step.”

What end-to-end encryption protects—and what it never promised
The lock protects a route. It does not govern the entire communications environment.
End-to-end encryption can prevent a service provider or network operator from reading message content in transit. That is a critical protection. But readable content still exists on the sender's device before encryption and on the recipient's device after decryption.
Backups, notification previews, linked desktops, compromised devices, screenshots, cloud accounts, administrators, metadata, and other participants remain separate trust zones. Secure transport cannot repair a compromised endpoint or an unmanaged group.
Client-side scanning is an umbrella term for inspecting content at an endpoint before encryption or after local decryption. It need not break the cipher mathematically to defeat the expected confidentiality of the system. And it is not imposed as a general E2EE scanning duty by the current EU interim measure.
“A lock icon proves encryption. It does not prove control over the endpoint, backup, metadata, identity, or lawful access.”
What is established—and what the claim does not prove
Detection is not one technical act
Known files, new images, and grooming demand different evidence standards.
Matching a file against a confirmed reference set is comparatively determinate, although implementation failures, adversarial manipulation, and reference quality still matter. Predicting whether a previously unseen image is unlawful is a different problem.
Novel-content and grooming classifiers are probabilistic and context-sensitive. Family exchanges, medical contexts, jokes, or benign images can be misunderstood. As scope expands and thresholds fall, base rates, precision, human confirmation, and the consequence of error become decisive.
The current interim text recognizes error as a governance issue. It requires error-minimization measures, human confirmation in defined cases, avenues of redress, and reporting on false positives. That establishes no universal error rate. It establishes that error cannot be dismissed as rhetoric.

The strongest case for intervention is morally serious—and technically incomplete
Child protection is not a pretext. That is precisely why the instrument must be tested against its actual effect.
Private communications services can host real abuse. Investigators, victim organizations, and platforms face a genuine operational and moral imperative to identify known material, stop ongoing harm, and find offenders. Any position that treats those facts as theater is not credible.
The hard question remains: which measures reach offenders effectively without turning a vast population's confidential communications into a generalized detection surface? Targeted orders, verified reference sets, independent authorization, narrow duration, and effective remedy are architecturally different from a standing capability for broad inspection.
The fault line is not child safety versus privacy. It is whether objective, intervention, error control, and oversight remain proportionate—and whether infrastructure built for one purpose can later be widened more easily than the political promise that created it.
Are WhatsApp and Signal affected? A simple yes or no is misleading.
A list of apps is not a threat model.
The current EU interim measure excludes end-to-end-encrypted interpersonal communications. It therefore does not impose blanket scanning of encrypted WhatsApp or Signal messages. Whether a particular feature is E2EE, how backups work, and what metadata remains available are separate product questions.
The permanent process could alter the regulatory framework. That does not establish that every service will deploy the same architecture, or that a provider can satisfy every future demand without changing its product promise. Products should be evaluated by actual function, not brand reputation.
For founders and families, the better question is where a sensitive fact exists: in which channel, on which endpoints, in which backups, among which participants, and under whose account powers. Switching apps can change a symbol while leaving the core dependency intact.
The Communication Exposure Audit
The opposite of panic is not complacency. It is a precise threat model.
First, content: what disclosure would cause irreversible harm? Second, identity: who is actually on the other end? Third, endpoint: which devices and linked sessions can see the content? Fourth, storage: which backups, exports, screenshots, or archives exist?
Fifth, role: who can add members or change settings? Sixth, metadata: what relationships, timing, location, or contact pattern is visible without message text? Seventh, recovery: who can reset an account, preserve evidence, and keep the family or company operating after compromise?
The result is not a ranking of the safest messenger. It is a classification system: routine, internally confidential, transaction-critical, legally privileged, and security-critical. The higher the class, the less one provider, device, or administrator should carry the whole burden.
“Sovereignty is not a product here either. It is architecture, discipline, and decision.”
What would change this diagnosis
A serious analysis publishes its falsifiers alongside its thesis.
Our diagnosis would narrow materially if the final EU framework prohibits generalized detection, confines measures to individually targeted and independently authorized cases, protects strong E2EE without content access, and guarantees rapid, effective remedy.
It would intensify if final law creates broad detection surfaces, vague risk concepts, compulsory access to E2EE content, or weak correction. Provider architecture changes, published error data, and court rulings can also move the assessment.
Until then, the rule is simple: do not sell a possible future as present fact. But do not wait for an update, order, or account incident to reveal the architecture. Confidential communication is a family and corporate governance function—not merely an app setting.
Four findings that narrow our thesis
The analysis remains credible only if it carries its counterevidence.
Targeted measure
A narrow, individually authorized measure against a specific suspect is not generalized chat control.
BOUNDARY · TEST TARGET AND SCOPEE2EE remains intact
A final framework protects strong encryption without content access. The infrastructure critique then narrows materially.
FALSIFIER · TEST FINAL TEXTHarmless product error
A false hit is stopped before referral and causes no consequence. Error alone does not prove political screening.
BOUNDARY · PROVE EFFECTExisting weakness
Disclosure came from a backup, participant, or compromised device—not EU regulation.
ALTERNATIVE CAUSE · TEST THE CHANNELWhat specialists must assess separately
No Borders Founder connects dependencies; case-specific conclusions remain with qualified specialists.
EU & fundamental-rights law
Final text, scope, authorization, proportionality, notice, and remedy.
Cybersecurity
Endpoint integrity, key management, backups, device management, identity verification, and incident response.
Data protection
Purpose, roles, retention, transfers, impact assessment, and data-subject rights.
Corporate & family governance
Information classes, participants, approvals, privilege, fallback channels, and responsibility for recovery.
Not individualized legal, privacy, or cybersecurity advice. Technical and legal implementation belongs with qualified counsel and security professionals.
Classify communication
Separate routine, internally confidential, transaction-critical, privileged, and security-critical information.
Map control points
Identify endpoints, backups, group-admin privileges, metadata, providers, and lawful-access exposure.
Test failure and correction
Rehearse identity verification, a separate channel, incident responsibility, evidence preservation, and recovery.
Is confidential communication actually governed?
- Which disclosures could cause irreversible harm?
- Which channels are approved for each information class?
- Are sensitive counterparties independently verified?
- Which endpoints and linked sessions can read content?
- Are backups truly end-to-end encrypted?
- Who can add members or change settings?
- Which metadata remains exposed?
- Where do exports, screenshots, and local archives exist?
- How is privileged communication separated?
- Who owns incidents and evidence preservation?
- Which independent fallback channel has been tested?
- Which legal or product change triggers review?
Reassess after final CSAR text, provider or backup changes, device replacement, account incidents, role changes, or new case law.
Frequently asked questions about EU Chat Control in 2026
Has the proposed permanent EU Chat Control regulation passed?
No. As of September 9, 2026, the proposed permanent CSAR had not been adopted. A separate temporary measure has been approved through April 3, 2028.
Are WhatsApp and Signal messages currently scanned by the EU?
The approved interim measure imposes no blanket scanning duty and excludes E2EE interpersonal communications. Product features, backups, and metadata require separate review.
What is client-side scanning?
An umbrella term for inspection at an endpoint before encryption or after local decryption. It is not a general requirement under the approved EU interim measure.
Does end-to-end encryption protect messages from client-side scanning?
It protects content between controlled endpoints from intermediary and service access. It cannot prevent inspection on the sender's or recipient's device before encryption or after decryption. The approved interim measure imposes no general client-side-scanning duty on E2EE messaging.
What is the difference between the interim measure and the permanent CSAR proposal?
The interim measure temporarily permits defined voluntary detection practices and excludes E2EE interpersonal communications. The permanent proposal is a separate, unfinished legislative framework whose final obligations remain unsettled.
Can users opt out of Chat Control?
There is no single opt-out governing every possible future framework. Rights and choices depend on final law, the provider, the service, and the specific process.
Which messenger is safest?
There is no responsible answer without a threat model. E2EE, backups, endpoints, metadata, recovery, group-admin privileges, and counterparties must be assessed together.
EU legislation and official negotiating documents, supplemented by identified technical research. Current through September 9, 2026; proposals, positions, the approved interim measure, and technical capability remain distinct.
- European Commission · COM(2022) 209 · CSAR proposal↗ (opens in a new tab)Commission proposal for the permanent CSAR framework; a proposal, not adopted permanent law.
- Council of the EU · Negotiating mandate · ST 15318/2025↗ (opens in a new tab)The Council's November 2025 negotiating mandate; it removes proposed detection orders but is not final legislation.
- Council of the EU · Preventing child sexual abuse online↗ (opens in a new tab)Live official status page for the interim measure and negotiations on the permanent framework.
- Council of the EU · Interim measure approved · 23 July 2026↗ (opens in a new tab)Official release on the voluntary interim measure through April 3, 2028 and its exclusion of end-to-end encrypted interpersonal communications.
- European Union · PE-CONS 14/26 · Adopted interim text↗ (opens in a new tab)Adopted text covering scope, safeguards, error controls, redress, and retention limits.
- European Parliament · Position on child sexual abuse online↗ (opens in a new tab)Parliament position favoring targeted measures, protection of strong encryption, and no blanket monitoring.
- EDPB–EDPS · Joint Opinion 04/2022↗ (opens in a new tab)Joint fundamental-rights and data-protection assessment of the Commission proposal.
- Abelson et al. · Bugs in Our Pockets · 2021↗ (opens in a new tab)Technical analysis of client-side scanning risks; research, not a description of current EU law.
- Jain et al. · Adversarial attacks against perceptual hashing · 2021↗ (opens in a new tab)Research on limitations and adversarial properties of perceptual hashing systems.

