Chat Control explained: the EU CSAM rules in force and still in talks
Chat Control is the nickname, popularised by critics, for EU rules on scanning private online communications for child sexual abuse material (CSAM) and grooming. As of October 2026 the label covers two separate measures: a temporary regulation, in force since 31 July 2026 and applying until 3 April 2028, that lets messaging and email providers scan voluntarily but excludes end-to-end encrypted chats; and a permanent Child Sexual Abuse Regulation, proposed in May 2022, that the European Parliament and the Council are still negotiating.
No EU law in force as of October 2026 requires a messaging service to scan its users' private messages.
Chat Control 1.0 and 2.0: two different laws
The debate often mixes up two instruments with very different legal effects:
- "Chat Control 1.0" is the interim derogation from the ePrivacy Directive. It permits, but does not require, voluntary detection by providers. The rules now in force are set out in Regulation (EU) 2026/1881.
- "Chat Control 2.0" is the proposed regulation laying down rules to prevent and combat child sexual abuse, COM(2022) 209, usually shortened to the CSA Regulation or CSAR. It would set binding obligations for online services and create a new EU agency.
A separate provisional agreement of 22 June 2026 on updating EU criminal law on child sexual abuse, which still needs formal adoption, covers offences and penalties, not message scanning.
The interim rules: what applies as of October 2026
Why a temporary exemption exists
On 21 December 2020 the European Electronic Communications Code brought messaging, web-based email and internet voice services under the ePrivacy Directive. Its confidentiality rules (Articles 5(1) and 6(1)) would otherwise stop providers from analysing message content and traffic data. Regulation (EU) 2021/1232 created a temporary exemption in 2021, and Regulation (EU) 2024/1307 extended it to 3 April 2026.
The April 2026 lapse and the July reinstatement
- On 19 December 2025 the Commission proposed a two-year extension, to 3 April 2028.
- On 11 March 2026 Parliament backed a shorter and narrower extension, until August 2027. Talks with the Council did not produce a deal, and on 26 March MEPs rejected the Commission proposal with 228 votes in favour, 311 against and 92 abstentions, according to Parliament's press release. The old rules expired after 3 April 2026.
- The Council adopted its position on reinstating the rules on 2 July 2026. On 9 July Parliament amended that text to exclude end-to-end encrypted communications.
- The Council accepted Parliament's amendments on 23 July. Regulation (EU) 2026/1881 was signed on 24 July, published in the Official Journal on 28 July and entered into force on 31 July 2026.
What the interim regulation allows and excludes
- Who it covers: providers of number-independent interpersonal communications services, such as messaging apps, web-based email and internet calling.
- What it allows: the voluntary use of technology to detect, report and remove CSAM, and to detect and report the solicitation of children (grooming). Nothing in the text makes scanning mandatory.
- What it excludes: communications to which end-to-end encryption is, has been or will be applied (Article 1(3)), and any scanning of audio communications (Article 1(2)).
Providers that rely on the exemption must meet the conditions in Article 3, including:
- using the least privacy-intrusive technology available; tools that scan text may only flag patterns and must not be able to deduce what a conversation is about;
- a prior data protection impact assessment and consultation with the national data protection authority;
- human oversight, and human confirmation before material not previously identified as CSAM, or suspected grooming, is reported;
- a complaints procedure, plus clear information telling users that the exemption is being used;
- keeping data on suspected cases for no longer than 12 months.
Deadlines set by Regulation 2026/1881
- 1 September and 1 October 2026 (passed): providers were to give the Commission the names of the public-interest organisations they report to, and the Commission was to publish that list.
- 1 November 2026: the Commission is due to set the standard reporting form by implementing act.
- 1 February 2027: providers publish their first reports, then by 31 January each year.
- 1 April 2027: a grace period ends for providers that used a technology before 31 July 2026 without completing consultation with their data protection authority, provided they started it before 1 September 2026.
- 1 August 2027: Member States publish their first annual statistics on reports received, children identified and offenders convicted.
- 1 February 2028: the Commission presents its implementation report.
- 3 April 2028: the regulation stops applying.
The permanent CSA Regulation ("Chat Control 2.0")
What the Commission proposed in 2022
The proposal of 11 May 2022 would require hosting and interpersonal communications services to assess and reduce the risk that their services are used for child sexual abuse. Where a significant risk remained, a national coordinating authority could ask a court or an independent administrative authority to issue a detection order requiring a specific service to detect known CSAM, new CSAM or grooming. Orders could run for up to 24 months for material and 12 months for grooming. App stores would have to use age verification or age assessment to keep children away from apps with a significant grooming risk. The text would also create an EU Centre on Child Sexual Abuse, with a proposed seat in The Hague.
In a joint opinion adopted on 28 July 2022, the European Data Protection Board and the European Data Protection Supervisor warned that, in practice, the proposal could become the basis for generalised and indiscriminate scanning of almost every type of electronic communication of all users in the EU and EEA.
Parliament's position (November 2023)
Parliament's Civil Liberties Committee adopted its position on 14 November 2023, and the mandate to negotiate was confirmed on 22 November 2023. The rapporteur is Javier Zarzalejos (EPP, Spain). The text keeps detection orders only as a last resort: time-limited, approved by a judicial authority and aimed at individuals or groups where there are reasonable grounds to suspect a link to child sexual abuse. End-to-end encryption is excluded from the scope of detection orders. Parliament's text calls the new agency the EU Centre for Child Protection.
The Council's position (November 2025)
Member States agreed their negotiating mandate on 26 November 2025, leaving the seat of the EU Centre to a separate procedure. The mandate is built on risk assessment and mitigation, with services classed as high, medium or low risk, and lets national authorities order the removal or blocking of material and the delisting of search results. It would also make the voluntary detection exemption permanent. As Euronews reported, the compromise does not include the compulsory scanning obligations for private communications that the Commission had proposed.
Where the trilogue stands as of October 2026
Negotiations between the institutions have run since the Council adopted its mandate. The sixth political trilogue took place on 29 September 2026. According to Agence Europe, negotiators reached an agreement in principle on detection orders for large platforms covering publicly accessible content and on the tasks of the EU Centre, but not on detection in private messages. The same report said the deal allowed the Commission to formally launch the procedure for choosing the Centre's seat, and that the date of the next trilogue had not been confirmed. Council justice and home affairs counsellors were scheduled to discuss the outcome and next steps on 5 October 2026.
Private content is the main open question. Before the September round, Agence Europe reported that the Irish Council presidency wanted voluntary searches to keep covering known material, new material and grooming, while Parliament wanted automated detection limited to known material and supervised by judicial or independent administrative authorities.
What Chat Control means for end-to-end encryption
Under the interim regulation the position is clear. Encrypted chats are outside its scope, and recital 32 says the regulation must not be read as banning or weakening end-to-end encryption. Where providers scan unencrypted content, they must tell users.
The permanent regulation is less settled. When it accepted Parliament's encryption carve-out in July 2026, the Council stated that this did not mean it would accept similar amendments in the talks on the long-term rules.
The technical issue behind the dispute is client-side scanning: checking content on a user's device before it is encrypted and sent. Critics argue that any duty to detect material inside an end-to-end encrypted service could only be met through such on-device checks, because the provider cannot read messages on its servers. The EDPB and EDPS also noted in 2022 that detection of this kind could be bypassed by encrypting content with a separate app before sending it.
What to watch next
- The date of the next trilogue and whether a compromise on private communications emerges.
- The Commission's reporting form, due by 1 November 2026, and the first provider reports in February 2027.
- The selection procedure for the EU Centre's seat, which the co-legislators left to a separate decision.
- 3 April 2028, when the interim regulation lapses unless a permanent law or another extension replaces it.
We track the file in our Policy section and, since messaging and webmail fall under EU electronic communications law, in Telecom. The largest platforms face separate risk-assessment duties under the Digital Services Act; see our list of very large online platforms and search engines.
Frequently asked questions
Is Chat Control already law in the EU?
Partly. The interim regulation allowing voluntary scanning, Regulation (EU) 2026/1881, has applied since 31 July 2026, while the permanent CSA Regulation, which would add binding obligations, is still being negotiated as of October 2026.
Does Chat Control scan end-to-end encrypted messages?
Not under the rules in force. The interim regulation does not apply to end-to-end encrypted communications, and whether the permanent regulation will contain any detection duty for private messages is still under negotiation.
How long do the interim Chat Control rules apply?
Regulation (EU) 2026/1881 applies until 3 April 2028. It is meant to bridge the gap until a permanent framework is adopted and starts to apply.
When will the permanent CSA Regulation be adopted?
There is no fixed date. After the sixth trilogue on 29 September 2026 the institutions had still not agreed on rules for private communications, and any deal would need formal approval by both Parliament and the Council.
What is the difference between Chat Control 1.0 and 2.0?
Chat Control 1.0 is the temporary exemption that lets providers scan voluntarily. Chat Control 2.0 is the proposed permanent regulation that would impose obligations on online services and set up an EU Centre to support implementation.