All About Cookies is an independent, advertising-supported website. Some of the offers that appear on this site are from third-party advertisers from which All About Cookies receives compensation. This compensation may impact how and where products appear on this site (including, for example, the order in which they appear).
All About Cookies does not include all financial or credit offers that might be available to consumers nor do we include all companies or all available products. Information is accurate as of the publishing date and has not been provided or endorsed by the advertiser.
The All About Cookies editorial team strives to provide accurate, in-depth information and reviews to help you, our reader, make online privacy decisions with confidence. Here's what you can expect from us:
- All About Cookies makes money when you click the links on our site to some of the products and offers that we mention. These partnerships do not influence our opinions or recommendations. Read more about how we make money.
- Partners are not able to review or request changes to our content except for compliance reasons.
- We aim to make sure everything on our site is up-to-date and accurate as of the publishing date, but we cannot guarantee we haven't missed something. It's your responsibility to double-check all information before making any decision. If you spot something that looks wrong, please let us know.
If you've seen EU Chat Control described as the European Union reading everyone's private messages, that's not what's happening — at least, not exactly. EU Chat Control is a nickname for rules that allow, but do not currently require, certain communication providers to voluntarily scan private messages that aren't end-to-end encrypted for child sexual abuse material (CSAM) and signs of child solicitation.[1]
The temporary law is active right now, but a broader permanent proposal is still being negotiated. Here's what that means for your messages, which apps are in scope, and what you can do if you want your conversations kept outside the current scanning rules.
Chat Control 1.0 vs. Chat Control 2.0
Which apps and messages does Chat Control affect?
Why EU Chat Control is so controversial
Bottom line
FAQs
What is EU Chat Control?
"Chat Control" isn't an official EU term. Critics coined the nickname for rules dealing with detection of child sexual abuse in private electronic communications.
The version in force today is a temporary exemption from parts of the EU's ePrivacy Directive, which normally protects the confidentiality of electronic communications. You may see it called a derogation, meaning a temporary exception to a rule. Regulation (EU) 2026/1881 lets providers such as webmail and messaging services voluntarily use certain technologies to detect and report online child sexual abuse and remove CSAM.
The law expressly excludes end-to-end encrypted (E2EE) communications. E2EE means only the sender and intended recipient can read the message contents — not the platform carrying them.
The final law also isn't limited to hash-matching known images. It can cover technology aimed at previously unidentified CSAM and possible child solicitation. However, new material and solicitation must receive human confirmation before being reported, and text-scanning technology cannot be designed to deduce the substance of a conversation.
Chat Control 1.0 vs. Chat Control 2.0
Chat Control 1.0 is the temporary regime described above. An earlier version expired on April 3, 2026, creating a gap in the rules. The European Parliament and Council agreed to reinstate the measure in July, and Regulation (EU) 2026/1881 entered into force at the end of that month. It applies until April 3, 2028, unless a permanent framework replaces it first.
You can read our coverage of the July 2026 EU Chat Control vote for more detail.
Chat Control 2.0 generally refers to the proposed permanent Child Sexual Abuse Regulation (CSAR). The Commission proposed it in 2022, but Parliament and the Council are still negotiating the final rules. The original proposal contemplated mandatory detection orders, helping drive debate over client-side scanning: checking content on your device before E2EE encrypts it.
Such a mechanism could weaken private messaging or be repurposed, but effective detection tools are needed to protect children. Client-side scanning is not part of the temporary law now in force.
If you see trilogue in coverage, it means informal negotiations among Parliament, the Council, and the Commission over EU legislation.
Chat Control is also separate from other EU internet rules, including the Digital Services Act and decisions about very large online platforms and search engines.
Which apps and messages does Chat Control affect?
The easiest rule to remember is this: under the current law, E2EE communications are outside the scanning exemption.
Unencrypted private communications may be in scope, but the provider still chooses whether to use qualifying detection technology. Being "in scope," therefore, does not mean a company definitely scans every message.
Here is a non-exhaustive list of apps that could be affected:
| App or service | In scope for voluntary scanning? | Why |
| Gmail | Potentially | Personal Gmail isn't E2EE; some Workspace users can enable client-side encryption. |
| Apple iCloud Mail | Potentially | iCloud Mail isn't E2EE, although S/MIME is optional. |
| Instagram DMs | Potentially | Meta ended Instagram's E2EE messaging option May 8, 2026.[2] |
| Messenger | Usually no for E2EE personal chats | Meta says the vast majority of users have default E2EE for personal messages.[3] |
| Discord | Text: potentially; calls: no | Discord text isn't E2EE, though audio and video calls are.[4] |
| Snapchat | Potentially | Snap doesn't describe ordinary Snaps and Chats as universally E2EE and allows limited safety-related access. |
| Xbox messaging | Potentially | Microsoft has some automated systems that detect harmful messages. |
| No for personal E2EE chats | Personal messages and calls use default E2EE. | |
| Signal | No | Signal says every conversation is always end-to-end encrypted.[5] |
| iMessage | No for iMessage conversations | iMessage content is E2EE; SMS/MMS are different.[6] |
| Proton Mail | Depends | Proton-to-Proton mail is E2EE; ordinary external email isn't E2EE by default. |
For non-EU readers, this isn't a worldwide scanning mandate. But global platforms also operate in Europe, and communications involving EU users can be subject to EU rules. Nevertheless, E2EE conversations are excluded. A VPN doesn't change that because it can't stop a platform from processing content the platform itself can read.
Why EU Chat Control is so controversial
Supporters argue that providers' voluntary detection systems are an important child-safety tool. The European Commission says proactive detection by companies has helped identify children facing abuse, while the Council says voluntary detection contributes to investigations and reducing the spread of abusive material.
Critics counter that scanning private messages without suspicion can become mass surveillance. The European Data Protection Board and European Data Protection Supervisor warned that generalized scanning could create false positives and undermine E2EE if detection were pushed onto encrypted services. The 2026 temporary law excludes E2EE and requires human oversight and reporting of error rates.
When All About Cookies surveyed 1,000 U.S. adults in February 2026 about age verification laws — a different child-safety measure, not an EU Chat Control survey — we found a similar tension. 79% supported age verification laws for adult content, while 79% also named privacy and data security as a concern. And 85% said existing laws were too easy to get around.
When asked for the best way to keep kids safe online, 55% chose parental controls and monitoring, compared with 20% who chose age-verification laws.
Our guide to the best parental control apps compares those tools.
Bottom line
EU Chat Control today isn't a blanket order for the EU to read everyone's texts. It is a temporary legal framework that lets providers voluntarily use qualifying detection tools on communications that aren't end-to-end encrypted. The current version expressly puts E2EE chats outside its scope, while the permanent CSAR remains unsettled.
If message privacy is your priority, use E2EE for sensitive conversations and choose email that offers end-to-end or zero-access encryption. A VPN can still protect your network traffic, but it doesn't make an unencrypted chat invisible to the service carrying it.
If you’re worried about your children's online safety, you can also start with our guide on how to protect your kids online.
FAQs
Is EU Chat Control active right now?
Yes. Regulation (EU) 2026/1881 is in force and applies until April 3, 2028, unless a permanent framework replaces it sooner. It permits qualifying voluntary detection on non-E2EE communications; it doesn't require every provider to scan every message.
Does Chat Control apply to WhatsApp and Signal?
Not to their end-to-end encrypted conversations under the current temporary regulation. The law expressly excludes communications to which E2EE is, has been, or will be applied, and both WhatsApp and Signal say their personal conversations use E2EE.
Will the EU pass Chat Control 2.0?
It's too early to say. The permanent CSAR is still being negotiated as of August 2026. The Commission's original proposal, Parliament's position, and the Council's negotiating position do not all take the same approach, so details can still change before any final law is adopted.
Does EU Chat Control affect people outside the EU?
The EU law governs relevant services and processing in the EU; it doesn't create a worldwide scanning mandate. However, non-EU users can communicate with people in the EU on the same global services. Whether a provider can see a particular conversation depends primarily on how that service is designed and whether the conversation is end-to-end encrypted. The current EU exemption does not apply to E2EE communications.
[1] Regulation (EU) 2026/1881 — EUR-Lex
[2] Instagram Help Center - End-to-end encryption on Instagram
[3] Reflecting on Meta’s $8 Billion Investment in Privacy
[4] Meet DAVE: Discord’s New End-to-End Encryption for Audio & Video
[5] Signal Support - Is it private? Can I trust it?
[6] iMessage security overview