Chat control secretly extended: What the new EU ruling means for your chats
Xpert Pre-Release
Available in 27 languages 📢
Prefer Xpert.Digital on GoogleⓘPublished on: July 23, 2026 / Updated on: July 23, 2026 – Author: Konrad Wolfenstein

Chat monitoring secretly extended: What the new EU ruling means for your chats – Image: Xpert.Digital
High rate of false alarms: Why the new EU chat control is facing such heavy criticism
Procedural trick in the EU Parliament: Mass surveillance of private messages returns
The EU's zombie law: How the controversial chat control was finally pushed through
The so-called EU chat control is back – and with it, one of the most heated debates surrounding the protection of our privacy and the threat of mass state surveillance. Although the proposal has already been democratically rejected several times in the European Parliament, a controversial expedited vote has paved the way for extending the exemption until April 2028. This means that providers of unencrypted communication services can continue to automatically scan private messages for illegal content. While proponents defend this as an essential step for child protection, data protection advocates are sounding the alarm in light of massive error rates and far-reaching infringements on fundamental rights. End-to-end encrypted messengers like WhatsApp and Signal are spared for now by the current compromise, but behind the scenes, the next political power struggle over permanent "chat control 2.0" is already brewing. The following article examines the substantive pitfalls of the proposal, the questionable procedural tricks in Parliament, and the drastic consequences for our digital civil liberties.
Chat control 1.0: Return of the exception rule in the context of procedural tricks and pressure on fundamental rights
A bitter power struggle over private messages: When child protection becomes a pretext for the largest surveillance machine in EU history
The European Union is once again at the center of a bitter debate over the monitoring of private communications. After a transitional arrangement for so-called chat monitoring expired at the beginning of April 2026, representatives of the member states agreed on a temporary exception to European data protection rules that would again allow messaging services to automatically search private chats for indications of child sexual abuse. This agreement followed a vote in the European Parliament that paved the way for the measure, albeit under conditions that made the entire process one of the most controversial legislative procedures in recent EU history. The German government, under Chancellor Friedrich Merz and Interior Minister Alexander Dobrindt, had exerted considerable pressure for the reinstatement of the regulation, criticizing the lack of a legal basis after the expiration of the previous exception. At the same time, data protection advocates have been warning for years that the measure effectively amounts to indiscriminate mass surveillance of millions of innocent citizens.
The conflict surrounding chat monitoring is therefore far more than a technical detail of internet policy. It touches upon fundamental questions about the relationship between national security, the economic interests of large technology companies, and the constitutionally enshrined right to privacy. Furthermore, the manner in which this decision was reached raises serious questions about the democratic legitimacy of European legislative processes.
The substantive content of the new regulation
At the heart of the proposal is the authorization for services like WhatsApp, Instagram, Google, and Microsoft to automatically scan private messages for depictions of child sexual abuse and report suspicious content to authorities. This exemption is intended to remain in effect until April 2028, thus representing a temporary solution rather than a permanent legal framework. Crucially, the compromise includes a clear distinction: end-to-end encrypted messages, standard with WhatsApp, Signal, and Threema, will continue to be protected from scanning. Client-side scanning, meaning checking directly on the end device before encryption, is also not permitted under this transitional model.
This primarily affects services that use unencrypted communication. These include email providers like Gmail and Outlook, social networks like Instagram, Discord, and Snapchat, gaming platforms like the Xbox infrastructure, and cloud services like iCloud. Participation in the scanning remains voluntary for companies; there is no legal obligation, only permission to scan despite existing data protection policies. Google, Meta, Microsoft, and Snap have already announced that they will continue voluntary child protection measures regardless of the final outcome of the legislative process.
A legislative process with a dubious aftertaste
What makes this compromise particularly controversial is the path that led to it. The extension of chat monitoring had already failed in the European Parliament, and not just once. On March 26, 2026, MEPs rejected an extension by a vote of 311 to 228, with 92 abstentions. As a result, the existing exemption expired on April 3, 2026. At the time, Chancellor Merz expressed his deep disappointment that the voluntary monitoring of chats could not be continued.
After the issue was considered settled, it was surprisingly put back on the agenda. On July 7, 2026, the European Parliament voted 331 to 304, with 11 abstentions, in favor of an expedited procedure that allowed for a new vote. Critics call this a questionable procedure because a proposal that had already been democratically rejected twice was revived through procedural means. Netzpolitik.org describes the process as a procedural trick by which the conservative Parliament President, Roberta Metsola, nevertheless pushed through a controversial exception.
The real trick lay in the chosen voting logic. In the final vote on July 9, 2026, the usual burden of proof was reversed: A motion to halt the creation of the legal framework garnered a relative majority of the members of parliament, but failed to achieve the required absolute majority of 361 out of 719 seats. In practical terms, this meant that the proposal was automatically considered adopted unless enough members actively objected. Any absence from the plenary session shortly before the summer recess thus played into the project's hands. A blog post succinctly summarized the figures: 314 to 276 votes against chat monitoring version 1.0, yet it was extended nonetheless.
Political fronts and their arguments
The Greens and the AfD accused the proponents of trying to push through a previously rejected regulation through the back door. This unusual partisan alliance from the left and right fringes of parliament demonstrates that resistance to chat monitoring cuts across the political spectrum and cannot be reduced to a classic left-right divide. The CDU and CSU rejected the criticism, arguing that without the exemption, important tools in the fight against child sexual abuse would be lost. This position aligns with the federal government's stance, which considered the lack of a legal basis after the old regulation expired in April to be problematic.
Following the vote, the Freedom Foundation held a discussion with FDP MEP Moritz Körner, who is among the critics of the revived regulation. Former MEP Patrick Breyer, one of the most prominent opponents of chat monitoring, also documented that, according to their own statements, major US platforms continued scanning without a legal basis even during the loophole. This fact fuels the suspicion that, in practice, technical reality and the legal situation had already been disconnected for months before the new regulation even came into effect.
Thought-provoking figures
A look at the results of chat monitoring to date significantly puts some of the promises of its proponents into perspective. Data from the Federal Criminal Police Office (BKA) shows that around 48 percent of automatically generated reports are not criminally relevant. Nearly half of all reports resulting from automated scanning thus turn out to be false alarms. This error rate casts a harsh light on the proportionality of the measure, because behind every false report is potentially an innocent citizen whose private communication was scrutinized without any concrete reason.
Critics of the Digital Society Association (Digitalen Gesellschaft e. V.) also point to even more drastic figures from earlier evaluations: Overall, only a vanishingly small fraction of the scanned messages were actually illegal material, while false-positive rates of up to 20 percent were documented for the scanning technologies used. Even the EU Commission itself, in its legally mandated evaluation of the existing measures, was unable to establish a clear link between the millions of reports and actual convictions, and it also failed to provide reliable figures on the number of children actually saved. When specifically questioned in the Parliament's Committee on Civil Liberties, Justice and Home Affairs, the responsible EU Commissioner for Home Affairs was unable to provide any evidence of the measures' effectiveness.
Our EU and German expertise in business development, sales and marketing
Industry focus areas: B2B, digitalization (from AI to XR), mechanical engineering, logistics, renewable energies and industry
More information here:
A thematic hub offering insights and expertise:
- Knowledge platform covering global and regional economies, innovation and industry-specific trends
- A collection of analyses, insights, and background information from our key areas of focus
- A place for expertise and information on current developments in business and technology
- A hub for companies seeking information on markets, digitalization, and industry innovations
Chat control until 2028: Why the debate about encryption is only just beginning
The encryption issue as the actual core of the dispute
The regulation currently adopted applies exclusively to unencrypted communication and leaves end-to-end encrypted services untouched. The real fundamental rights conflict, however, lies in the parallel, permanent regulation being negotiated, often referred to as Chat Control 2.0 or the CSA Regulation. This regulation has long centered on a potential obligation for client-side scanning, meaning the inspection of content directly on the end device before encryption. Such an obligation would effectively negate the protective effect of end-to-end encryption, because on-device scanning software would simultaneously create a technical gateway for abuse, whether by state actors, the companies themselves, or third parties who could exploit such a backdoor.
While the mandatory client-side scanning component has been removed from the current draft proposal for a permanent regulation, negotiations are now focused on a voluntary solution. Germany had already clearly positioned itself against mandatory surveillance in October 2025, a stance of considerable consequence given the importance of encrypted services like Signal, Threema, and Wire for the digital security of businesses and individuals. Netzpolitik.org published classified internal negotiating documents in July 2026, revealing that EU member states are continuing to work towards implementing stricter, permanent chat monitoring regulations, despite repeated opposition from the Parliament. The term "zombie project," circulating among critics, aptly describes this pattern: a proposal that is repeatedly rejected democratically but always reappears in a new form.
The further legislative roadmap
Parliament's approval does not yet definitively conclude the process. For the new regulation to finally enter into force, the Council of the European Union must also give its consent within three months. In its vote, Parliament also called for amendments to the original proposal, which the Council of Member States must now decide on. Should the Council not approve these amendments, a further conciliation procedure will be necessary.
The extension now agreed upon, until April 2028, is explicitly intended as a transitional solution. The actual negotiations on the permanent regulation, i.e., chat monitoring 2.0, are scheduled to begin as early as September 2026. This means that the current compromise by no means marks the end of the debate, but merely provides a temporary reprieve while, in the background, the more fundamental and far-reaching issue of the permanent and potentially mandatory monitoring of private communication continues to be debated.
An assessment of the interests involved
When assessing the compromise, it is worthwhile to consider the various interest groups involved in the outcome. The federal government and the Federal Criminal Police Office (BKA) pressed for a swift reinstatement because they deemed an existing legal loophole in the fight against child abuse unacceptable. This position is understandable, as child sexual abuse is one of the most serious crimes, and any delay in investigation can have grave consequences in individual cases.
At the same time, the available data show that current practices have significant weaknesses. An error rate of almost half in automatically generated reports means that, in practice, law enforcement agencies have to devote a considerable portion of their resources to reviewing irrelevant leads, while millions of private messages belonging to innocent citizens are being searched. The lack of demonstrable causality between the millions of automated reports and actual convictions, as even the European Commission had to acknowledge in its own evaluation, undermines the central justification for this far-reaching infringement of fundamental rights.
Added to this is the technological dimension. Large US technology companies like Meta, Google, and Microsoft benefit economically and in terms of reputation by appearing active in child protection; at the same time, by scanning unencrypted communication, they are venturing into territory that gives them additional insights into user data. The fact that these companies claim to have continued scanning even during the period without a valid legal basis also demonstrates how limited the actual control of European institutions over the practices of large platform operators is.
The democratic process as the actual point of contention
Beyond the substantive assessment of chat monitoring, the specific path to agreement raises fundamental questions about the democratic culture of European legislation. A parliament that rejects a proposal twice within a few months by a clear majority, only to then push it through via an expedited procedure with reversed burden of proof, sets a precedent that extends beyond the specific issue of chat monitoring. If a rejection is no longer accepted as a final democratic decision, but rather treated as a mere interim result in an ongoing political struggle, trust in democratic institutions as a whole declines.
This criticism is exacerbated by the fact that leading representatives of the CDU, CSU, and SPD in Germany have publicly promised in the past not to support indiscriminate chat monitoring. When such promises are made during national election campaigns but not kept at the European level, a breach of trust occurs that, beyond the issue itself, damages the credibility of political pledges in general. The question of how seriously election promises should actually be taken in a multi-tiered political system comprising national and European levels is therefore one of the most relevant long-term aspects of this conflict.
Chat control 2028: Temporary measure or political precedent?
The current compromise on chat monitoring does not represent a final solution, but rather a temporary postponement of the actual conflict. Until April 2028, providers of unencrypted communication services may continue to voluntarily search for indications of child abuse, while encrypted services will remain untouched for the time being. However, the fundamental decision on a potentially permanent and more comprehensive regulation, which will enter its decisive negotiation phase as early as September 2026, is still pending.
Those who view the debate solely through the lens of child protection overlook the structural weaknesses of current practices, which are documented by reliable figures on error rates and lack of effectiveness. Those who view the debate solely through the lens of data protection risk underestimating the real and serious problem of digital child abuse. The true challenge for European policy lies in creating effective investigative tools that actually convict perpetrators without subjecting the communications of millions of innocent citizens to constant algorithmic scrutiny. Until this balance is convincingly achieved, chat monitoring will repeatedly resurface on the European agenda.

















