Chat Control 2.0 Trilogue Update: No mass scanning deal for now – European Parliament stands firm against “Search Plans”
Late yesterday, the crucial trilogue negotiation on the Child Sexual Abuse Regulation (CSAR) concluded.
The good news: The “dirty deal” to permanently legalize mass scanning of private communications did not happen. Thanks to the pressure from civil society (thank you!) and a firm stance by the European Parliament’s negotiating team, the Council’s attempt to push through broad “Search Plans” for private chats has failed for the time being.
Key Outcomes of the September 29 Trilogue:
1. Mass Scanning of Private Chats Postponed
The Irish Presidency’s plan to reach a final political agreement on the entire package was blocked. A major point of contention was the Council’s demand to allow unrestricted mass scanning of private messages and files. The European Parliament negotiators remained steadfast, insisting that scanning of private communications must remain strictly limited to persons linked to child sexual abuse.
Below this message you will find more information on what Council proposed ahead of the trilogue.
A technical but important win was achieved regarding “mitigation measures”. The text will clarify that authorities cannot enforce voluntary scanning of private communications through the back door of “mitigation measures”.
2. Tentative Agreement on Public Content
Negotiators reached a preliminary political agreement on searching publicly accessible content (such as social media and publicly accessible cloud content).
- EU Centre: Its tasks were provisionally agreed upon, including the task to search for both known and new CSAM in public spaces. (This crawling had been proposed by the European Parliament and is much more effective in curbing circulation of CSAM than sniffing in private communications.)
- Agreement on Public Detection Orders: Administrative authorities (not only courts) can order hosting service providers (including social media and cloud providers) to scan publicly accessible content for known CSAM. These platforms will be obliged to continuously monitor all public uploads (not limited to uploads by users suspected of a crime, as the European Parliament had proposed). Public scanning orders can be issued to any hosting provider regardless of size.
What happens next?
This is not a final victory, but a successful defense. The fight is moving to the next stage:
- Technical Level Negotiations: Experts will continue to negotiate potential rules for “non-public” (private) detection throughout October.
- Next Trilogue in November: A final attempt at a political deal is expected in November.
- The Threat Remains: The Council still insists in, at least, keeping the “Chat Control 1.0” voluntary mass scanning regime as a loophole. We must ensure that any final deal fully terminates this failed system.
Strategy:
We have bought ourselves a few weeks. The fact that the Parliament stood firm despite intense pressure shows that our mobilization is working. We can use this time well to prepare better for mobilization ahead of the November trilogue.
Thank you for your work so far. All emails, calls, and public actions made the difference in preventing a catastrophic deal yesterday.
I will keep you updated.
This is what Council (EU governments) proposed in the trilogue
Permanent “voluntary” Chat Control (own-initiative searches by providers in non-public content)
- Providers may choose to scan non-public content (including messenger chats and non-public hosted content).
- Fake “targeted” scanning: Allows providers to scan large parts or their service or chat groups without limiting the scanning to individual criminal suspects.
- Automatic “silent approval”: Providers can submit a scanning (“search”) plan and start searching private chats and content automatically unless an authority actively steps in to veto it.
- Permanent voluntary Chat Control: The proposal would make permanent what the Chat Control 1.0 interim regulation allows only until 2028.
- “Voluntary” scanning made mandatory: The proposal sneaks voluntary searches into enforceable “risk mitigation” rules, meaning platforms could be forced to scan private chats just to avoid heavy regulatory fines.
Permanent “mandatory” Chat Control (detection orders in non-public content)
- Administrative authorities can order communications and hosting service providers to scan non-public content (including messenger chats and e-mails).
- Mass surveillance without a specific suspect: Weak legal thresholds so that orders to intercept private messages are not limited to users suspected of a crime.
- AI-based classification: Extends chat detection beyond known illegal images to AI-powered image and text analysis for “suspected content”, risking massive false positives on innocent private conversations.
- No court order required: Grants non-judicial administrative agencies the power to order the interception of private communications without approval from a court.
The “Voluntary” Loophole (Chat Control 1.0)
If the European Parliament continues to refuse indiscriminate Chat Control powers, Council will likely propose to maintain the interim “Chat Control 1.0” regulation, which allows for voluntary mass scanning until 2028. While the mandate of the European Parliament is to replace indiscriminate Chat Control with detection court orders targeting specific suspects, there is a severe risk that negotiators could instead compromise on keeping “Chat Control 1.0” as a parallel loophole. This system is a proven disaster: German police data shows that over half of investigations target minors themselves for consensual sexting, while 75% of all flagged chats are not actionable. We cannot accept a deal unless this failed mass-scanning regime is fully phased out and replaced.
