EU Chat Control, Explained: Which Messages Can Be Scanned (And Which Can't)

EU Chat Control lets some apps voluntarily scan unencrypted private messages for child abuse material. Here's what's in scope, what's excluded, and how to keep your conversations private.
We receive compensation from the products and services mentioned in this story, but the opinions are the author's own. Compensation may impact where offers appear. We have not included all available products or offers. Learn more about how we make money and our editorial policies.

If you've seen EU Chat Control described as the European Union reading everyone's private messages, that's not what's happening — at least, not exactly. EU Chat Control is a nickname for rules that allow, but do not currently require, certain communication providers to voluntarily scan private messages that aren't end-to-end encrypted for child sexual abuse material (CSAM) and signs of child solicitation.[1]

The temporary law is active right now, but a broader permanent proposal is still being negotiated. Here's what that means for your messages, which apps are in scope, and what you can do if you want your conversations kept outside the current scanning rules.

In this article
What is EU Chat Control?
Chat Control 1.0 vs. Chat Control 2.0
Which apps and messages does Chat Control affect?
Why EU Chat Control is so controversial
Bottom line
FAQs

What is EU Chat Control?

"Chat Control" isn't an official EU term. Critics coined the nickname for rules dealing with detection of child sexual abuse in private electronic communications.

The version in force today is a temporary exemption from parts of the EU's ePrivacy Directive, which normally protects the confidentiality of electronic communications. You may see it called a derogation, meaning a temporary exception to a rule. Regulation (EU) 2026/1881 lets providers such as webmail and messaging services voluntarily use certain technologies to detect and report online child sexual abuse and remove CSAM.

The law expressly excludes end-to-end encrypted (E2EE) communications. E2EE means only the sender and intended recipient can read the message contents — not the platform carrying them.

The final law also isn't limited to hash-matching known images. It can cover technology aimed at previously unidentified CSAM and possible child solicitation. However, new material and solicitation must receive human confirmation before being reported, and text-scanning technology cannot be designed to deduce the substance of a conversation.

Chat Control isn't the law's real name. It's a nickname used for two different EU measures: a temporary voluntary regime that's active now and a separate permanent proposal that's still being negotiated.

Chat Control 1.0 vs. Chat Control 2.0

Chat Control 1.0 is the temporary regime described above. An earlier version expired on April 3, 2026, creating a gap in the rules. The European Parliament and Council agreed to reinstate the measure in July, and Regulation (EU) 2026/1881 entered into force at the end of that month. It applies until April 3, 2028, unless a permanent framework replaces it first.

You can read our coverage of the July 2026 EU Chat Control vote for more detail.

Chat Control 2.0 generally refers to the proposed permanent Child Sexual Abuse Regulation (CSAR). The Commission proposed it in 2022, but Parliament and the Council are still negotiating the final rules. The original proposal contemplated mandatory detection orders, helping drive debate over client-side scanning: checking content on your device before E2EE encrypts it.

Such a mechanism could weaken private messaging or be repurposed, but effective detection tools are needed to protect children. Client-side scanning is not part of the temporary law now in force.

If you see trilogue in coverage, it means informal negotiations among Parliament, the Council, and the Commission over EU legislation.

Chat Control is also separate from other EU internet rules, including the Digital Services Act and decisions about very large online platforms and search engines.

Which apps and messages does Chat Control affect?

The easiest rule to remember is this: under the current law, E2EE communications are outside the scanning exemption.

Unencrypted private communications may be in scope, but the provider still chooses whether to use qualifying detection technology. Being "in scope," therefore, does not mean a company definitely scans every message.

Here is a non-exhaustive list of apps that could be affected:

App or service In scope for voluntary scanning? Why
Gmail Potentially Personal Gmail isn't E2EE; some Workspace users can enable client-side encryption.
Apple iCloud Mail Potentially iCloud Mail isn't E2EE, although S/MIME is optional.
Instagram DMs Potentially Meta ended Instagram's E2EE messaging option May 8, 2026.[2]
Messenger Usually no for E2EE personal chats Meta says the vast majority of users have default E2EE for personal messages.[3]
Discord Text: potentially; calls: no Discord text isn't E2EE, though audio and video calls are.[4]
Snapchat Potentially Snap doesn't describe ordinary Snaps and Chats as universally E2EE and allows limited safety-related access.
Xbox messaging Potentially Microsoft has some automated systems that detect harmful messages.
WhatsApp No for personal E2EE chats Personal messages and calls use default E2EE.
Signal No Signal says every conversation is always end-to-end encrypted.[5]
iMessage No for iMessage conversations iMessage content is E2EE; SMS/MMS are different.[6]
Proton Mail Depends Proton-to-Proton mail is E2EE; ordinary external email isn't E2EE by default.

For non-EU readers, this isn't a worldwide scanning mandate. But global platforms also operate in Europe, and communications involving EU users can be subject to EU rules. Nevertheless, E2EE conversations are excluded. A VPN doesn't change that because it can't stop a platform from processing content the platform itself can read.

Why EU Chat Control is so controversial

Supporters argue that providers' voluntary detection systems are an important child-safety tool. The European Commission says proactive detection by companies has helped identify children facing abuse, while the Council says voluntary detection contributes to investigations and reducing the spread of abusive material.

Critics counter that scanning private messages without suspicion can become mass surveillance. The European Data Protection Board and European Data Protection Supervisor warned that generalized scanning could create false positives and undermine E2EE if detection were pushed onto encrypted services. The 2026 temporary law excludes E2EE and requires human oversight and reporting of error rates.

When All About Cookies surveyed 1,000 U.S. adults in February 2026 about age verification laws — a different child-safety measure, not an EU Chat Control survey — we found a similar tension. 79% supported age verification laws for adult content, while 79% also named privacy and data security as a concern. And 85% said existing laws were too easy to get around.

Bar chart showing the top concerns about age verification laws

When asked for the best way to keep kids safe online, 55% chose parental controls and monitoring, compared with 20% who chose age-verification laws.

Circle chart showing the most popular ways to protect kids online

Our guide to the best parental control apps compares those tools.

Bottom line

EU Chat Control today isn't a blanket order for the EU to read everyone's texts. It is a temporary legal framework that lets providers voluntarily use qualifying detection tools on communications that aren't end-to-end encrypted. The current version expressly puts E2EE chats outside its scope, while the permanent CSAR remains unsettled.

If message privacy is your priority, use E2EE for sensitive conversations and choose email that offers end-to-end or zero-access encryption. A VPN can still protect your network traffic, but it doesn't make an unencrypted chat invisible to the service carrying it.

If you’re worried about your children's online safety, you can also start with our guide on how to protect your kids online.

FAQs

Is EU Chat Control active right now?

Yes. Regulation (EU) 2026/1881 is in force and applies until April 3, 2028, unless a permanent framework replaces it sooner. It permits qualifying voluntary detection on non-E2EE communications; it doesn't require every provider to scan every message.

Does Chat Control apply to WhatsApp and Signal?

Not to their end-to-end encrypted conversations under the current temporary regulation. The law expressly excludes communications to which E2EE is, has been, or will be applied, and both WhatsApp and Signal say their personal conversations use E2EE.

Will the EU pass Chat Control 2.0?

It's too early to say. The permanent CSAR is still being negotiated as of August 2026. The Commission's original proposal, Parliament's position, and the Council's negotiating position do not all take the same approach, so details can still change before any final law is adopted.

Does EU Chat Control affect people outside the EU?

The EU law governs relevant services and processing in the EU; it doesn't create a worldwide scanning mandate. However, non-EU users can communicate with people in the EU on the same global services. Whether a provider can see a particular conversation depends primarily on how that service is designed and whether the conversation is end-to-end encrypted. The current EU exemption does not apply to E2EE communications.


5.0
Editorial Rating
Get Deal
On Qustodio's website
2026 Editors’ Choice
Best Parental Control App for Android
Parental Controls
Qustodio
  • Parental controls app with a free plan, plus per-app screen time limits in 15-minute increments
  • Panic Button lets kids instantly alert trusted contacts with their location from their Android device
  • Activity reports update quickly, showing app usage, web searches, and screen time all in one dashboard
Author Details
Thomas Kent is a multi-disciplined reporter with over a decade of experience covering online platforms, digital trends, and consumer-facing tech. Tom focuses on digital privacy, data tracking, and user behavior, with a particular interest in how cookies, online surveillance, and platform design shape the modern internet experience. His reporting takes a research-driven, news-focused approach, translating complex technical topics into clear, accessible insights.

Citations

[1] Regulation (EU) 2026/1881 — EUR-Lex

[2] Instagram Help Center - End-to-end encryption on Instagram

[3] Reflecting on Meta’s $8 Billion Investment in Privacy

[4] Meet DAVE: Discord’s New End-to-End Encryption for Audio & Video

[5] Signal Support - Is it private? Can I trust it?

[6] iMessage security overview