A surprising shift in Council positions
The path to a unified EU Member State stance on the CSA Regulation proved extraordinarily difficult, with seven consecutive presidencies unable to forge consensus. That changed in late 2025 when Denmark's government succeeded where others had failed. The bloc had been sharply divided: one group of nations, led by Denmark, championed large-scale scanning of private messages including encrypted ones, while another faction—notably Poland, Czechia and the Netherlands—resisted, arguing that fundamental rights and encryption protections must not be sacrificed even for child safety goals.
On November 13 2025, Denmark tabled a proposal that reversed course dramatically: it called for eliminating compulsory detection systems and strengthening safeguards for encrypted communications. The shift raised questions about whether years of polarised debate had finally given way to recognition that basic constitutional protections matter, whether the FightChatControl.eu citizen campaign had influenced the outcome, and how Germany—long a data protection advocate—came to drop its resistance to "chat control."
The Council's new position means that any final CSA Regulation should not compel platforms such as Signal or WhatsApp to scan all user messages or weaken their encryption. These provisions align with the European Parliament's 2023 stance, marking a genuinely significant moment for digital rights protection across Europe and beyond.
What lies ahead remains murky
The Council's agreement, while welcome, falls short of perfection, and the road to a final law stretches far ahead. Cyprus, holding the Council Presidency, scheduled final negotiations for 29 June 2026, though reported delays suggest that timeline may slip.
The Council's "general approach" has shed the Commission's most legally questionable elements, yet troubling provisions persist. National authorities face no independence requirement under the proposal, and a search engine delisting clause risks obscuring the fundamental principle that illegal content should be removed at source rather than merely hidden from view.
The negotiating landscape has grown complicated by institutional divergence. The Council and Parliament broadly agree on blocking mandatory scanning, but diverge on details: the Council favours a permanent "voluntary" framework resembling the 2021 interim ePrivacy derogation (extended in 2024 amid criticism), while Parliament supports mandatory scanning only under narrow conditions—essentially requiring reasonable suspicion of crime, akin to a warrant requirement.
On 19 December 2025, the Commission proposed extending the interim ePrivacy derogation—colloquially "Chat Control 1.0"—by two additional years, citing concerns that long-term framework talks could drag on. This move came despite insufficient evidence of necessity or proportionality in the temporary system.
Though only the Council and Parliament formally legislate, the European Commission wields substantial influence through its facilitative role. The dossier carries a troubling record of inappropriate and occasionally unlawful Commission conduct. While ex-Commissioner Ylva Johansson no longer oversees the file, the Commission continues pressing to preserve its original "Chat Control" vision, leaving the outcome of final trilogue negotiations uncertain.
Age verification emerges as the gravest remaining peril
A development commanding urgent attention from digital rights advocates is the push for mandatory age verification or age assurance—mechanisms that gate access to services by requiring identity documents, facial scans or behavioural information. Both the Commission and Council back making this compulsory for services deemed risky under the CSA framework. The proposal's risk criteria are deeply flawed: any genuinely secure and privacy-conscious service would automatically qualify as risky, triggering mass identity-verification infrastructure.
Under such a regime, users would need to submit facial data or government IDs simply to send encrypted messages via Signal or WhatsApp, compose emails or install applications. Failure to comply would mean exclusion from private digital communication altogether.
This represents an existential threat to privacy, freedom of expression and human dignity. Citizens would lose the ability to communicate digitally without state or corporate surveillance. Activism, journalism, whistleblowing and professional confidentiality for doctors, therapists and lawyers would face severe compromise. The chilling effect on legitimate speech and information-seeking would be profound.
Populations lacking digital ID infrastructure or possessing non-standard credentials—young people, elderly individuals, undocumented migrants and structurally marginalised communities—would face de facto exclusion from private online spaces. Facial recognition systems notoriously underperform on people of colour and those with facial differences, compounding discriminatory barriers.
While strengthening online safety for adults and children alike deserves serious policy attention, age verification represents a misguided approach, particularly for private messaging. From a legal standpoint, the CSA Regulation is an inappropriate vehicle for such requirements. The Digital Services Act already permits age verification for social media and comparable platforms under Article 28, where individual circumstances demonstrate necessity and proportionality.
Mandating age-gating across all chats, locking millions from private digital spaces and enabling governmental or corporate surveillance of personal communication is not the solution. The European Parliament's position on age verification, though imperfect, represents the least damaging path: if providers employ age verification, it must satisfy stringent privacy and security standards. Should the final CSA Regulation exceed this threshold, the digital rights community must mobilise to prevent what could become one of the most significant contemporary assaults on digital civil liberties.
Source: EDRi (European Digital Rights)



