“Chat Control” is the political shorthand used in the EU debate over scanning private messages for child sexual abuse material (CSAM) and grooming. Critics use “Chat Control 1.0” for the temporary 2021–2025 ePrivacy derogation framework, while “Chat Control 2.0” refers to the European Commission’s 11 May 2022 proposal for a permanent regulation. In 2025, the key dispute is whether detection can be required without weakening end-to-end encryption.
What chat control is
This image was generated by AIChat control is an informal label for EU rules or proposals that would let or require online services to detect child sexual abuse material and grooming in private communications. The term is not the official name of an EU law; it is mainly used in political debate and media coverage, especially since the European Commission published its proposal on 11 May 2022.
The phrase “Chat Control 1.0” is commonly used by critics for the temporary 2021–2025 ePrivacy regime, which allowed providers to use voluntary detection measures while a longer-term law was being negotiated. That label matters because it describes a stopgap period rather than a formal regulation called “Chat Control 1.0,” and the legal setup has been discussed as a temporary derogation framework instead of one permanent system.
“Chat Control 2.0” usually means the Commission’s proposal of 11 May 2022 for a new regulation to prevent and combat child sexual abuse. Under that proposal, providers would have to assess and mitigate risk, and detection obligations could be imposed in some cases through legal mechanisms tied to known CSAM, new CSAM, or grooming, rather than through one universal automatic scanning rule in every service from day one.
The reason people keep searching for this topic in 2024 and 2025 is that the file stayed politically active after the Council reached a general approach on 28 November 2023 but no final EU law was agreed. In 2024, debate continued around new compromise efforts, and on 14 June 2024 the European Parliament adopted its position with stronger privacy protections and narrower measures than many critics feared.
How chat control would work
This image was generated by AIChat control would work through a combination of risk assessment, mitigation duties, and possible detection or reporting obligations for certain providers. In the 11 May 2022 proposal, the basic idea is not just “scan every message,” but to create a legal framework where services may first have to evaluate risk and then, in specified cases, face requirements connected to detecting and reporting child sexual abuse material or grooming.
The hardest technical issue is client-side scanning, which means analyzing text, images, or attachments on a user’s device before a message is encrypted or after it is decrypted. That issue matters because many messaging apps, including end-to-end encrypted services, rely on encryption precisely so the provider cannot read message content in transit, and critics argue that device-level scanning could undermine that protection.
A provider identifies whether its service creates a relevant risk of CSAM or grooming under the proposed framework discussed since 11 May 2022.
The provider applies mitigation measures first, rather than jumping immediately to broad content scanning in every case.
If authorities issue a detection-related obligation under the final legal framework, the provider may need to use technology aimed at known CSAM, new CSAM, or grooming, depending on the exact scope of the order.
If material is flagged, the provider may have to report it to the relevant authorities or designated EU system under the final rules.
Disputes then focus on accuracy, safeguards, redress, encryption impact, and whether the technology scans communications broadly or only in targeted circumstances.
Explanatory simplification of the proposed logic
Risk assessment -> Risk mitigation -> Possible detection-related order ->
Targeted detection technology -> Flag/report -> Review and safeguards
Note: This is a simplified explanation, not the literal legal procedure or final adopted EU law.As of 2025, the unresolved legal question is whether any final EU law can require detection without effectively forcing broad scanning of private messages, especially in end-to-end encrypted apps. That is why the debate is less about one app in isolation and more about whether the EU can design detection obligations that do not break the privacy model used by services such as encrypted messengers.
Chat Control 1.0 vs 2.0 vs Parliament's 2024 position
This image was generated by AIThe simplest way to understand the EU debate is to compare the temporary setup, the Commission proposal, and the Parliament’s June 2024 position. These three reference points explain why public discussion often sounds inconsistent between 2021, 2022, and 2024.
| Reference point | Date | What it means in practice | Main controversy |
|---|---|---|---|
| Informal “Chat Control 1.0” | 2021–2025 | Political nickname for the temporary ePrivacy derogation framework that let providers use voluntary detection measures while long-term rules were negotiated | Temporary patchwork approach; not an official law title |
| Commission proposal often called “Chat Control 2.0” | 11 May 2022 | Proposed permanent regulation with risk assessment, mitigation duties, and potential detection/reporting obligations in some cases | Whether detection orders could force scanning that affects encrypted communications |
| Council general approach | 28 Nov 2023 | Member states agreed an internal Council position, but that did not create final EU law | Disagreement remained over scope, safeguards, and encryption |
| European Parliament position | 14 Jun 2024 | Parliament backed stronger privacy protections and narrower measures than broader scanning models | How to protect children without creating blanket monitoring of private chats |
| 2025 political dispute | 2025 | No final law yet; institutions still face unresolved design choices | Whether detection can happen without broad scanning or weakening end-to-end encryption |
The Commission’s 2022 proposal is broader than the temporary 2021–2025 arrangement because it aims to build a lasting EU regulatory framework instead of relying on voluntary measures during a transition period. The Parliament’s 14 June 2024 position, by contrast, pushed toward narrower and more privacy-protective limits, which is one reason no final text was settled immediately after 2024.
Common errors people make about chat control
A common error is thinking Chat Control 1.0 and 2.0 are official EU law names. They are not. The first is mainly a nickname for the temporary ePrivacy-era arrangement discussed for 2021–2025, and the second is a nickname for the Commission proposal published on 11 May 2022.
Another error is assuming the proposal automatically means every message in every app is already scanned in the EU. That is incorrect as of 2025 because the permanent proposal has not become final EU law, and the file remained unresolved after the Council’s 28 November 2023 general approach and the Parliament’s 14 June 2024 position.
A third error is reducing the whole issue to one sentence like “the EU wants to ban encryption.” The more precise problem, according to the technical debate, is whether detection obligations could be imposed in a way that affects end-to-end encrypted services, including through client-side scanning before encryption or after decryption on the device.
A fourth error is treating critics’ concerns as only theoretical. Opponents specifically argue that scanning systems can create false positives, expand monitoring beyond CSAM, and establish a precedent for surveillance of private communications. Those objections are part of the reason the proposal has not reached final agreement.
Tips for following the issue without getting confused
The best way to follow chat control is to track three dates first: 11 May 2022 for the Commission proposal, 28 November 2023 for the Council general approach, and 14 June 2024 for the Parliament position. Those dates tell you which institution is being discussed whenever a headline appears in 2025.
Check whether an article is talking about the temporary 2021–2025 regime or the permanent proposal from 11 May 2022.
Look for the words “proposal,” “Council position,” or “Parliament position,” because each term describes a different stage in the EU legislative process.
Watch for references to client-side scanning, because that is the clearest marker of the encryption controversy in the 2024–2025 debate.
Separate voluntary detection measures from detection obligations that could follow from a final regulation.
Treat phrases like “the law has passed” carefully unless the report states that the EU institutions reached a final adopted text.
If you only remember one practical thesis, make it this: chat control is not one settled EU law but an ongoing fight over whether child-safety detection duties can be designed without turning private messaging into broad message scanning. That single distinction explains most headlines from 2022, 2023, 2024, and 2025.
FAQ
Is Chat Control already law in the EU?
Not in the sense of a final permanent regulation. As of 2025, the Commission proposal from 11 May 2022 has not become final EU law, even though the Council adopted a general approach on 28 November 2023 and the Parliament adopted its position on 14 June 2024.
What is the difference between Chat Control 1.0 and 2.0?
“Chat Control 1.0” is an informal label for the temporary 2021–2025 ePrivacy derogation framework that allowed voluntary detection measures. “Chat Control 2.0” is the nickname for the Commission’s 11 May 2022 proposal for a permanent regulation.
Would Chat Control affect WhatsApp, Signal, or other encrypted apps?
Potentially, yes, depending on the final legal text. The controversy described since 2022 is that detection obligations could apply to interpersonal communications services, including end-to-end encrypted services, which is why client-side scanning is so contested.
Why is client-side scanning controversial?
Client-side scanning analyzes content on the device before encryption or after decryption. Critics argue that this can undermine the practical privacy promise of end-to-end encryption, create security risks, and increase false positives.
Why do supporters and opponents disagree so strongly?
Supporters argue the framework is aimed at detecting known CSAM, new CSAM, and grooming linked to child protection goals. Opponents argue the same mechanisms could create false positives, broaden surveillance, and set a precedent for monitoring private communications.