SYSTEM AUDIT · PRIVATE COMMUNICATION · EU 2026

EU Chat Control 2026: What It Means for WhatsApp, Signal, and Private Messages

What is in force, what a permanent CSAR could change, and why confidential founder and family communications require more than the right app.

17 min read
Share article
Smartphone and confidential files in a European boardroom behind a glass boundary
PRIVATE COMMUNICATION · THE CONTROL POINT IS NOT ONLY IN THE NETWORK
Status on September 9, 2026Permanent CSAR framework not adopted
Current interim measureVoluntary · through April 3, 2028 · E2EE excluded
Technical fault lineInspection at the endpoint before or after transport encryption
Decision questionWhich communications must not depend on one control point?

The decisive question is not whether Brussels can read every message tomorrow. It is whether a reusable inspection interface will be legitimized inside confidential communication—and whether errors can be identified, explained, and corrected in time.

What applies now

The renewed interim measure permits certain voluntary practices for non-end-to-end-encrypted communication. It does not require scanning every chat and excludes E2EE interpersonal communication.

What remains open

The proposed Regulation to Prevent and Combat Child Sexual Abuse (CSAR) remains in the legislative process. The Commission proposal, Council mandate, and Parliament position differ materially.

What matters operationally

E2EE protects content between controlled endpoints from intermediary and service access. Confidentiality also depends on endpoints, backups, metadata, account powers, participants, escalation, and effective correction.

In this analysis01 · Has the proposed permanent EU Chat Control regulation passed? No—and the architecture question is still real.02 · Three layers the debate keeps collapsing into one03 · The system behind the system: the Confidentiality Chain04 · What end-to-end encryption protects—and what it never promised05 · Detection is not one technical act06 · The strongest case for intervention is morally serious—and technically incomplete07 · Are WhatsApp and Signal affected? A simple yes or no is misleading.08 · The Communication Exposure Audit09 · What would change this diagnosis
01

Has the proposed permanent EU Chat Control regulation passed? No—and the architecture question is still real.

Conflating an approved interim measure, a permanent proposal, and a technical capability produces either panic or false reassurance.

As of September 9, 2026, the EU's permanent framework for combating online child sexual abuse has not been adopted. Negotiations continue. The Commission's 2022 proposal, Parliament's position, and the Council's negotiating mandate are different texts with materially different intervention models.

A separate temporary measure has been approved and reinstated. It permits providers to use certain voluntary practices to detect, report, and remove abuse material. It is not a general duty to inspect every private message. The 2026 text expressly excludes interpersonal communications to which end-to-end encryption applies and runs through April 3, 2028.

So the claim that the EU is now scanning every WhatsApp or Signal message is wrong. The claim that the issue is over is equally complacent. A credible position holds both facts: the approved interim framework is narrower than many headlines suggest, while the permanent architecture remains unsettled.

Scenario, not a reported case: On the evening before an acquisition, a founder sends an unresolved decision to family members and two advisors. The service encrypts it between endpoints. A preview appears on a linked tablet, an old cloud backup remains readable, and a former assistant still holds group-admin privileges. No EU system had to read the message. It was still not confidential end to end. That gap between a product symbol and the real communications environment is where this analysis begins.

Privacy does not begin only when someone reads a message. It weakens when the communications path itself becomes an inspection point.

Alexander Erber
02

Three layers the debate keeps collapsing into one

Current law, a political design, and a technical capability are not interchangeable.

Layer one is current law: the temporary, voluntary ePrivacy derogation with defined scope and safeguards. Layer two is the permanent legislative process, where institutions are negotiating text that can still change. Layer three is technology: hashing, classifiers, and endpoint inspection may be built or discussed without being legally mandated.

The label Chat Control attracts attention but explains no mechanism. An architect asks who may trigger a measure, against what threshold, what a provider must do, where content is inspected, how a hit is escalated, who confirms it, and what notice and remedy follow.

Precision does not sand off the edge. It makes the edge defensible. Protecting children is a legitimate and urgent objective. That fact cannot, by itself, settle whether every proposed technical architecture is necessary and proportionate.

A forceful diagnosis becomes more credible when every claim carries its exact legal and technical status.

NBF Confidentiality Equation

Effective confidentiality is constrained by its weakest critical transition.

01Legal scope

02Endpoint

03E2EE channel

04Account & identity

05Metadata

06Correction

E2EE protects content between controlled endpoints from intermediaries and service access. It cannot govern the other five layers.
03

The system behind the system: the Confidentiality Chain

No single actor controls the entire system. Practical power accumulates across handoffs.

The chain begins with a legal trigger and scope. That can create a provider permission or duty. The provider operates a detection surface. A tool classifies content or conduct. A hit is rejected, confirmed, or reported. Authority review, human judgment, action, notice, and remedy follow.

Each handoff changes the risk. An individually authorized measure is not blanket monitoring. Matching confirmed known files is not the same as predicting whether a new image or a conversation is unlawful. An automated flag is not a verified report, and a report is not proof of guilt.

The decisive architecture lies in thresholds, error budgets, and escalation. Reducing the debate to encrypted or unencrypted misses the process. Describing every institution as one command center is just as misleading.

Modern control rarely arrives in uniform. It arrives as an update, a threshold, and a process step.

Alexander Erber
Confidential family-business boardroom with separated documents and communications channel
GOVERNANCE · CONFIDENTIALITY NEEDS ROLES, CLASSES, AND FALLBACKS
04

What end-to-end encryption protects—and what it never promised

The lock protects a route. It does not govern the entire communications environment.

End-to-end encryption can prevent a service provider or network operator from reading message content in transit. That is a critical protection. But readable content still exists on the sender's device before encryption and on the recipient's device after decryption.

Backups, notification previews, linked desktops, compromised devices, screenshots, cloud accounts, administrators, metadata, and other participants remain separate trust zones. Secure transport cannot repair a compromised endpoint or an unmanaged group.

Client-side scanning is an umbrella term for inspecting content at an endpoint before encryption or after local decryption. It need not break the cipher mathematically to defeat the expected confidentiality of the system. And it is not imposed as a general E2EE scanning duty by the current EU interim measure.

A lock icon proves encryption. It does not prove control over the endpoint, backup, metadata, identity, or lawful access.

Alexander Erber

What is established—and what the claim does not prove

FindingDefensible statementUnsupported shortcut
2026 interim measure
Limited voluntary practices
Every chat must be scanned
E2EE under interim text
Excluded from scope
EU currently reads WhatsApp and Signal
Permanent CSAR
Legislative process continues
Final architecture already exists
Client-side scanning
Possible endpoint inspection
General duty under the approved interim text
Automated hit
Signal for review and process
Proof of guilt
E2EE product
Content protection between controlled endpoints
All communication is automatically private
05

Detection is not one technical act

Known files, new images, and grooming demand different evidence standards.

Matching a file against a confirmed reference set is comparatively determinate, although implementation failures, adversarial manipulation, and reference quality still matter. Predicting whether a previously unseen image is unlawful is a different problem.

Novel-content and grooming classifiers are probabilistic and context-sensitive. Family exchanges, medical contexts, jokes, or benign images can be misunderstood. As scope expands and thresholds fall, base rates, precision, human confirmation, and the consequence of error become decisive.

The current interim text recognizes error as a governance issue. It requires error-minimization measures, human confirmation in defined cases, avenues of redress, and reporting on false positives. That establishes no universal error rate. It establishes that error cannot be dismissed as rhetoric.

Smartphone behind layered glass between a private office and technical infrastructure
ENDPOINT · A SEPARATE TRUST ZONE EXISTS BEFORE ENCRYPTION
06

The strongest case for intervention is morally serious—and technically incomplete

Child protection is not a pretext. That is precisely why the instrument must be tested against its actual effect.

Private communications services can host real abuse. Investigators, victim organizations, and platforms face a genuine operational and moral imperative to identify known material, stop ongoing harm, and find offenders. Any position that treats those facts as theater is not credible.

The hard question remains: which measures reach offenders effectively without turning a vast population's confidential communications into a generalized detection surface? Targeted orders, verified reference sets, independent authorization, narrow duration, and effective remedy are architecturally different from a standing capability for broad inspection.

The fault line is not child safety versus privacy. It is whether objective, intervention, error control, and oversight remain proportionate—and whether infrastructure built for one purpose can later be widened more easily than the political promise that created it.

07

Are WhatsApp and Signal affected? A simple yes or no is misleading.

A list of apps is not a threat model.

The current EU interim measure excludes end-to-end-encrypted interpersonal communications. It therefore does not impose blanket scanning of encrypted WhatsApp or Signal messages. Whether a particular feature is E2EE, how backups work, and what metadata remains available are separate product questions.

The permanent process could alter the regulatory framework. That does not establish that every service will deploy the same architecture, or that a provider can satisfy every future demand without changing its product promise. Products should be evaluated by actual function, not brand reputation.

For founders and families, the better question is where a sensitive fact exists: in which channel, on which endpoints, in which backups, among which participants, and under whose account powers. Switching apps can change a symbol while leaving the core dependency intact.

08

The Communication Exposure Audit

The opposite of panic is not complacency. It is a precise threat model.

First, content: what disclosure would cause irreversible harm? Second, identity: who is actually on the other end? Third, endpoint: which devices and linked sessions can see the content? Fourth, storage: which backups, exports, screenshots, or archives exist?

Fifth, role: who can add members or change settings? Sixth, metadata: what relationships, timing, location, or contact pattern is visible without message text? Seventh, recovery: who can reset an account, preserve evidence, and keep the family or company operating after compromise?

The result is not a ranking of the safest messenger. It is a classification system: routine, internally confidential, transaction-critical, legally privileged, and security-critical. The higher the class, the less one provider, device, or administrator should carry the whole burden.

Sovereignty is not a product here either. It is architecture, discipline, and decision.

Alexander Erber
09

What would change this diagnosis

A serious analysis publishes its falsifiers alongside its thesis.

Our diagnosis would narrow materially if the final EU framework prohibits generalized detection, confines measures to individually targeted and independently authorized cases, protects strong E2EE without content access, and guarantees rapid, effective remedy.

It would intensify if final law creates broad detection surfaces, vague risk concepts, compulsory access to E2EE content, or weak correction. Provider architecture changes, published error data, and court rulings can also move the assessment.

Until then, the rule is simple: do not sell a possible future as present fact. But do not wait for an update, order, or account incident to reveal the architecture. Confidential communication is a family and corporate governance function—not merely an app setting.

Four findings that narrow our thesis

The analysis remains credible only if it carries its counterevidence.

Targeted measure

A narrow, individually authorized measure against a specific suspect is not generalized chat control.

BOUNDARY · TEST TARGET AND SCOPE

E2EE remains intact

A final framework protects strong encryption without content access. The infrastructure critique then narrows materially.

FALSIFIER · TEST FINAL TEXT

Harmless product error

A false hit is stopped before referral and causes no consequence. Error alone does not prove political screening.

BOUNDARY · PROVE EFFECT

Existing weakness

Disclosure came from a backup, participant, or compromised device—not EU regulation.

ALTERNATIVE CAUSE · TEST THE CHANNEL

What specialists must assess separately

No Borders Founder connects dependencies; case-specific conclusions remain with qualified specialists.

EU & fundamental-rights law

Final text, scope, authorization, proportionality, notice, and remedy.

Cybersecurity

Endpoint integrity, key management, backups, device management, identity verification, and incident response.

Data protection

Purpose, roles, retention, transfers, impact assessment, and data-subject rights.

Corporate & family governance

Information classes, participants, approvals, privilege, fallback channels, and responsibility for recovery.

Not individualized legal, privacy, or cybersecurity advice. Technical and legal implementation belongs with qualified counsel and security professionals.

01

Classify communication

Separate routine, internally confidential, transaction-critical, privileged, and security-critical information.

02

Map control points

Identify endpoints, backups, group-admin privileges, metadata, providers, and lawful-access exposure.

03

Test failure and correction

Rehearse identity verification, a separate channel, incident responsibility, evidence preservation, and recovery.

12-point review

Is confidential communication actually governed?

  1. Which disclosures could cause irreversible harm?
  2. Which channels are approved for each information class?
  3. Are sensitive counterparties independently verified?
  4. Which endpoints and linked sessions can read content?
  5. Are backups truly end-to-end encrypted?
  6. Who can add members or change settings?
  7. Which metadata remains exposed?
  8. Where do exports, screenshots, and local archives exist?
  9. How is privileged communication separated?
  10. Who owns incidents and evidence preservation?
  11. Which independent fallback channel has been tested?
  12. Which legal or product change triggers review?

Reassess after final CSAR text, provider or backup changes, device replacement, account incidents, role changes, or new case law.

Frequently asked questions about EU Chat Control in 2026

Has the proposed permanent EU Chat Control regulation passed?

No. As of September 9, 2026, the proposed permanent CSAR had not been adopted. A separate temporary measure has been approved through April 3, 2028.

Are WhatsApp and Signal messages currently scanned by the EU?

The approved interim measure imposes no blanket scanning duty and excludes E2EE interpersonal communications. Product features, backups, and metadata require separate review.

What is client-side scanning?

An umbrella term for inspection at an endpoint before encryption or after local decryption. It is not a general requirement under the approved EU interim measure.

Does end-to-end encryption protect messages from client-side scanning?

It protects content between controlled endpoints from intermediary and service access. It cannot prevent inspection on the sender's or recipient's device before encryption or after decryption. The approved interim measure imposes no general client-side-scanning duty on E2EE messaging.

What is the difference between the interim measure and the permanent CSAR proposal?

The interim measure temporarily permits defined voluntary detection practices and excludes E2EE interpersonal communications. The permanent proposal is a separate, unfinished legislative framework whose final obligations remain unsettled.

Can users opt out of Chat Control?

There is no single opt-out governing every possible future framework. Rights and choices depend on final law, the provider, the service, and the specific process.

Which messenger is safest?

There is no responsible answer without a threat model. E2EE, backups, endpoints, metadata, recovery, group-admin privileges, and counterparties must be assessed together.

EU legislation and official negotiating documents, supplemented by identified technical research. Current through September 9, 2026; proposals, positions, the approved interim measure, and technical capability remain distinct.

  1. European Commission · COM(2022) 209 · CSAR proposal (opens in a new tab)Commission proposal for the permanent CSAR framework; a proposal, not adopted permanent law.
  2. Council of the EU · Negotiating mandate · ST 15318/2025 (opens in a new tab)The Council's November 2025 negotiating mandate; it removes proposed detection orders but is not final legislation.
  3. Council of the EU · Preventing child sexual abuse online (opens in a new tab)Live official status page for the interim measure and negotiations on the permanent framework.
  4. Council of the EU · Interim measure approved · 23 July 2026 (opens in a new tab)Official release on the voluntary interim measure through April 3, 2028 and its exclusion of end-to-end encrypted interpersonal communications.
  5. European Union · PE-CONS 14/26 · Adopted interim text (opens in a new tab)Adopted text covering scope, safeguards, error controls, redress, and retention limits.
  6. European Parliament · Position on child sexual abuse online (opens in a new tab)Parliament position favoring targeted measures, protection of strong encryption, and no blanket monitoring.
  7. EDPB–EDPS · Joint Opinion 04/2022 (opens in a new tab)Joint fundamental-rights and data-protection assessment of the Commission proposal.
  8. Abelson et al. · Bugs in Our Pockets · 2021 (opens in a new tab)Technical analysis of client-side scanning risks; research, not a description of current EU law.
  9. Jain et al. · Adversarial attacks against perceptual hashing · 2021 (opens in a new tab)Research on limitations and adversarial properties of perceptual hashing systems.
Alexander Erber, founder of No Borders Founder
ALEXANDER ERBER · FOUNDER · NO BORDERS FOUNDER

The most consequential decision rarely looks like a ban. It looks like a technical necessity whose control point later stops being questioned.

For internationally active founders and families, private communication is not a convenience. It carries transactions, disputes, health information, succession, and decisions before they become public or formally documented. Protecting that sphere requires neither paranoia nor digital asceticism. It requires an architecture connecting content, endpoint, identity, role, storage, and recovery—and an honest account of where it must trust an institution, provider, or person.

Family Office Advisory · Communication Governance

Govern confidential communication before an incident reveals its architecture.

No Borders Founder maps information classes, key people, jurisdictions, and failure consequences. Qualified specialists handle technical and legal implementation.

Check mandate fitRead Strategic Sovereignty