'Chat Control' has been stuck for years

The EU's proposed CSA Regulation—colloquially known as 'Chat Control'—has languished in negotiations for an extended period. During December 2024, Hungary's EU Council Presidency made an aggressive push to advance the legislation, attempting to pressure national governments into backing its version of the text.

Hungary's pressure tactics backfired. The effort instead exposed widespread resistance to mass surveillance and encryption-breaking measures, with at least ten member states—among them Germany, the Netherlands and Luxembourg—openly opposing the approach.

Polish government officials had previously voiced concerns that the proposal represented a misguided strategy for addressing child safety online. Yet when January 2025 arrived, Poland's Presidency joined the succession of administrations seeking to resolve the Council's impasse.

A new approach from the Polish Presidency

Though imperfect, Poland's revised proposal represents a marked improvement over earlier iterations from Hungary and Belgium. The most significant change: Poland has proposed eliminating Detection Orders entirely.

Detection Orders formed the core of the original European Commission proposal, mandating that providers such as Signal and WhatsApp scan all user messages. This requirement would have necessitated breaking encryption and compromising the security of all platforms for both businesses and individuals.

Poland's alternative introduces what it terms 'voluntary measures' instead. Drawing from the interim ePrivacy derogation currently in force, the revised text would permit service providers to scan content without requiring them to do so.

What could happen if Poland is successful?

Numerous unresolved questions remain, and a substantial bloc of countries continues to resist Poland's efforts to safeguard end-to-end encryption. Should Poland's text advance to trilogues—the negotiation phase between Council and Parliament—the following scenarios merit consideration.

Detection orders: what could happen in trilogues

A three-column table compares different positions on 'Detection Orders' from the European Commission, Parliament, and Polish Presidency. 1. Commission Proposal (2022, official): Detection Orders could force online service providers (social media, chat apps) to scan users' public or private communications without requiring individual-level suspicion. 2. Parliament Position (2023, official): Detection Orders must be targeted and based on specific suspicion, similar to a warrant. 3. Polish Presiden

Detection Orders represent the most contentious element of the CSA Regulation proposal. They enable authorities to mandate that interpersonal communications services deploy AI-powered Client-Side-Scanning to mass monitor private communications on user devices, and can require hosting services to employ upload filters assessing all uploaded content.

Finding consensus between co-legislators will prove difficult given their divergent positions. Nevertheless, both Parliament and a hypothetical Council position would likely oppose government-mandated mass scanning of innocent citizens' private communications. However, 'voluntary' scanning carries risks as severe as mandatory approaches—particularly since Poland's proposal still mandates reporting of hits to law enforcement.

End-to-end encryption: what could happen in trilogues

A table outlining different stances on encrypted messaging and email services. Commission Proposal (2022, official): Includes all E2EE services in scanning requirements, despite criticism for being technically risky and misleading. Parliament Position (2023, official): Excludes E2EE chats and emails from scanning. Polish Presidency (January 2025, draft): Prevents forced scanning of E2EE services but allows providers to be encouraged to scan and mandates their assistance in developing scanning ba

End-to-end encryption underpins contemporary communication platforms including messaging services, cloud storage and email. It serves as essential protection for personal data and confidential exchanges in digital environments, and proves vital for journalists, whistleblowers, civil rights advocates and others whose safety depends on communication confidentiality. Weakening encryption would diminish security for all users.

Despite former Home Affairs Commissioner Ylva Johansson's aggressive stance against encryption, insufficient political appetite exists across Europe to dismantle it. This makes sense: doing so would affect every individual seeking secure digital communication, including government officials themselves. The European Court of Human Rights has established that encryption constitutes a fundamental component of twenty-first-century privacy rights. Yet this represents perhaps Poland's proposal's greatest vulnerability, as nations like Spain have openly stated that the CSA Regulation offers their opportunity to undermine encryption continent-wide—a goal they will resist abandoning.

Scope of scanning: what could happen in trilogues

A three-column table comparing different positions on scanning for CSAM (Child Sexual Abuse Material) across the European Commission, Parliament, and Polish Presidency. Commission Proposal (2022, official): Suggests AI tools should be used to scan both 'known' and 'unknown' CSAM, as well as detect solicitation patterns. Parliament Position (2023, official): Allows detection orders for 'known' and 'unknown' CSAM but excludes solicitation from scanning. Solicitation tools may still be used for ris

Three scanning categories have been identified: 'known' content (previously verified by authorities as CSAM), 'unknown' content (not yet identified), and patterns suggesting grooming solicitation.

Co-legislators have only partially grasped the fundamental unreliability of tools designed to identify unknown CSAM or grooming patterns. Whilst both Council and Parliament texts incorporate safeguards for scanning technologies, neither goes sufficiently far, nor do they adequately acknowledge the inherent constraints of AI-based scanning systems. This gap creates risk: individuals across the EU could face false accusations of CSA offences.

Age verification: what could happen in trilogues

A table comparing proposals on mandatory age verification for chat and messaging apps. Commission Proposal (2022, official): Mandates age verification for all high-risk chat/messaging apps, which could affect most privacy-focused platforms. Parliament Position (2023, official): Limits mandatory age verification to pornography platforms, while other services must meet data protection requirements. Polish Presidency (January 2025, draft): Maintains mandatory age verification for high-risk chat app

Age verification involves predicting or establishing a person's age through methods such as document-based verification or biometric age estimation. Each approach carries distinct risks, and no EU-wide tool currently exists that aligns with children's digital rights.

Given current political momentum and enthusiasm for technological solutions around age verification, concern exists that any final agreement could mandate such measures. The CSA Regulation represents an inappropriate venue for this—these matters warrant more deliberate, nuanced treatment and already possess potential legal foundations in the GDPR, DSA and AVMSD. Mandatory age verification across all messaging platforms, absent reliable technical solutions, risks severe digital exclusion and could prevent individuals from contacting friends and family.

Where does this leave us?

Uncertainty continues to cloud the path forward. The politicisation of this legislation by DG HOME since 2022 has obscured the possibility of an evidence-based, law-grounded resolution, though Poland's Presidency deserves credit for exploring rights-respecting alternatives to the Commission's original proposal.

Meanwhile, on-the-ground realities demonstrate that governments are failing to meet elementary obligations for combating online CSAM—a point underscored by recent German documentary evidence. Against this backdrop, the CSA Regulation functions merely as a temporary fix for a fundamentally broken system.

EDRi remains committed to ensuring that measures addressing online CSAM are pursued through methods that prove effective, proportionate, and fully aligned with the EU Charter of Fundamental Rights.

Source: EDRi (European Digital Rights)