A European line that many thought had been closed has just been reignited. The Council of the European Union confirmed on July 23, 2026, the reinstatement of a temporary measure allowing certain digital services to voluntarily detect child sexual abuse material in online communications. Presented as an essential measure for the protection of children, the decision has immediately re-entered public debate under its most explosive name: ‘Chat Control’.
The issue is global, as it touches on the most sensitive balance of modern Internet: how to identify serious crimes without turning private messaging into a space of widespread surveillance? The adopted text is more limited than some viral messages suggest. It does not create a universal obligation to read all conversations and excludes end-to-end encrypted messaging services, such as WhatsApp or Signal, from its scope. However, it does reinstate, until April 3, 2028, a controversial exemption to European privacy rules.
What the European Union Has Actually Decided
The temporary measure allows communication service providers to voluntarily use technologies to search for and report child sexual abuse material, known by the English acronym CSAM. The mechanism already existed but expired on April 3, 2026. The European Union had thus faced a legal vacuum for several months that the Council claims it wants to fill.
According to the EU Council, this measure is intended to help identify endangered children, facilitate investigations, and prevent criminal images from continuing to circulate. The stated objective is hardly debated: online child sexual abuse demands a rapid and coordinated response. The controversy revolves around the technical means, their accuracy, and the precedent set when a private company can analyze communications normally protected by the confidentiality of exchanges.
WhatsApp and Signal Are Not Directly Included in This Text
This is the essential point to understand the news without succumbing to exaggeration. According to Euronews, member states have validated the version already passed by the European Parliament, with an amendment removing end-to-end encrypted services from the scope of the temporary measure. This means that WhatsApp, Signal, and other messaging services relying on full encryption are not authorized by this specific text to scan the content of messages thus protected.
This exclusion is significant. In an end-to-end encrypted system, only the sender and the recipient should be able to read the conversation. Introducing an analysis tool before or after encryption, according to many cryptographers, amounts to creating a vulnerability that could be exploited by criminals, espionage groups, or authoritarian governments. The temporary version reinstated in July avoids this frontal breach, but it does not close the broader debate.
Why the Term ‘Mass Surveillance’ Returns Despite Safeguards
Digital rights advocates argue that voluntary control can still affect a very large number of users who are suspected of nothing. Even when a technology searches only for fingerprints of already identified files, it operates in spaces that citizens consider private. The risk of false positives, erroneous reports, or gradual expansion of the scope thus fuels distrust.
The European Parliament had sought to tighten the use of detection tools around content already recognized as illegal or reported by a user, organization, or trusted actor. This choice illustrates the sought compromise: to maintain a detection capability while limiting the indiscriminate analysis of ordinary conversations. For opponents, these protections remain insufficient. For supporters, abandoning any mechanism would deprive investigators of thousands of potentially useful reports.
The Trap of the Two Files Called ‘Chat Control’
A significant part of the confusion arises from the fact that two different debates are often mixed. The first, the subject of the July 2026 decision, is a temporary exemption that allows voluntary detection and excludes end-to-end encryption. The second is the proposed permanent European regulation against child sexual abuse, which is much broader and still at the center of intense negotiations.
This future permanent framework could set lasting obligations for platforms and determine under what conditions detection orders would be possible. This is where the heaviest battle for the future of encryption in Europe is played out. To assert that Brussels can now automatically read every WhatsApp message would therefore be false. To say that the reinstatement of the temporary regime has no consequences would be equally misleading: it keeps open a legal and technical architecture that deeply divides institutions, businesses, and civil society.
A European Decision with Global Consequences
The European Union is not an ordinary digital market. When it imposes or authorizes a new rule, major international platforms often have to adapt their products for hundreds of millions of users. European choices can then become references elsewhere, as was the case with the GDPR or certain provisions regarding giant platforms.
The signal sent is therefore of interest to the United States, the United Kingdom, Asia, and African democracies that are also working on the accountability of messaging services. If Europe manages to build a targeted, controlled, and technically reliable system, it could set a standard. If it undermines privacy without demonstrating proportionate effectiveness, it will conversely provide a powerful argument to regimes that want to normalize access to private conversations.
What This Changes for Users in France
For someone using an end-to-end encrypted messaging service, the decision of July 23 does not cause any immediate visible change in the application. It does not give the police a button to open all conversations. However, it does restore the legal framework within which certain other services can continue voluntary detection, under the conditions set by European legislation.
Vigilance must therefore focus on three points: the services actually concerned, the technologies they use, and the guarantees offered when content is reported. Users need to know whether the analysis relies on already identified files, on artificial intelligence interpreting new images, or on behavior detection. These methods do not have the same level of reliability or the same impact on privacy.
The Decisive Battle Is Just Beginning
The reinstatement until 2028 offers time for European institutions, but it also increases pressure. Two years can serve to measure the actual effectiveness of reports, publish transparent figures, audit tools, and build a solid judicial oversight. They can also establish a practice before the democratic debate on the permanent system is concluded.
The real shock of ‘Chat Control’ lies in this tension. Europe wants to prevent intolerable crimes without renouncing the privacy model it has presented for years as a fundamental value. The decision of July is neither an authorization to read all messages nor a mere technical formality. It is a temporary compromise that places the protection of children, the power of platforms, and the security of encryption on the same fault line. The next step will determine whether this line becomes a solid boundary or a door that no one can close.
Sources
- Council of the European Union â Temporary measure reinstated to combat online child sexual abuse, July 23, 2026
- Euronews â EU extends controversial communication scanning regime until 2028, July 23, 2026
- European Parliament â Position on the extension and guarantees of the temporary measure, March 2026
- Council of the European Union â Position aimed at filling the legal vacuum, July 2, 2026


