EU Chat Control: Governments push “Search Plans” to permanently legalise chat mass scanning in Final Trilogue Showdown
As European negotiators enter what is intended to be the final trilogue on the Child Sexual Abuse Regulation (CSAR or “Chat Control 2.0”) on September 29, internal leaked documents reveal EU governments pushing a “compromise” based on “search plans” that would enable large-scale scanning of private communications — while insisting the permanent law must not “achieve less” than the current Chat Control 1.0 mass-scanning status quo.
Under the EU Council’s proposal, an authority could grant platforms a “license to scan” parts of their service—namely private chats and e-mails—for months at a time.
“In practice, the proposed ‘search plans’ for ‘parts of a service’ still mean scanning millions of innocent users without individual suspicion,” expains Patrick Breyer, former MEP and digital rights advocate. “It is a semantic trick to rebrand mass surveillance. Trying to protect children with indiscriminate mass surveillance is as ineffective as frantically mopping the floor while the tap is still running.”
“Illegal by Design”
Internal legal analysis (8787/23) reveals the Council is pushing this compromise despite a warning from its own Legal Service, which stated that scanning an entire service or parts of it is “highly probable” to be considered “general and indiscriminate” surveillance—and therefore illegal under EU law.
“By moving away from individual suspicion, the Council is knowingly pushing for a regime that will leave authorities empty-handed when the EU Court of Justice strikes it down,” says Breyer.
The Mass-Scanning Loophole Trap
The push follows the controversial re-enactment of the temporary “Chat Control 1.0” law in July—a move pushed through until 2028 despite a majority of voting MEPs opposing it. EU governments are now attempting to use this momentum to force a permanent deal that would normalize indiscriminate mass surveillance. Leaked document 13158/26 even reveals a fallback plan: excluding non-public chats from the new Regulation altogether, only to keep the failed 1.0 regime alive as a factually permanent parallel loophole.
“The European Parliament must not accept a permanent regulation that fails to replace the temporary mass-scanning loophole,” Breyer said. ”This system is a documented failure: 75% of flagged chats are not actionable, and in Germany, over half of investigations for ‘youth pornography’ target minors themselves, often for consensual sexting. This system overwhelms the police with false alarms, robbing them of desperately needed capacity to investigate actual abusers.”
Parliament’s alternative: prevention, web-cleaning and targeted warrants
The European Parliament’s cross-party negotiating mandate takes a different approach designed to protect children more effectively and within legal limits:
- Security by Design: safety-focused default settings and features to reduce grooming and exploitation risks (e.g. limiting unsolicited contact and content sharing by default, child-appropriate privacy defaults, and on-device, user-controlled warnings and guidance before displaying/sharing sensitive content).
- Proactive “web cleaning”: empowering the EU Centre to proactively search publicly accessible content for known CSAM.
- Targeted enforcement: searching private communications only under judicial authorisation and only targeted to specific persons or groups where there are reasonable grounds linking them to child sexual abuse offences — producing higher-quality leads and avoiding overload from mass false positives.
With intense pressure to “get a deal,” there is a risk that political group leadership will push negotiators to accept Council’s mass-scanning model tomorrow despite Parliament’s cross-party mandate. Any such reversal would likely trigger a major political backlash and risk failure in plenary.
Growing Public Resistance
Over the weekend, activists gathered outside the European Commission building in Warsaw to protest the plans (see call for action and photos). Simultaneously, the fightchatcontrol.eu campaign has seen a surge in citizen mobilization, calling on MEPs to stand firm and reject any deal that does not fully terminate the failed voluntary scanning regime.
Background: https://chatcontrol.eu
Summary of Leaked Internal Documents
- Doc 13158/26 (State of Play): This document shows the Council is hardening its position. It confirms that the Presidency wants to maintain the “level of reports” from the failed voluntary regime. It introduces the concept of “Search Plans” as a compromise, which would allow administrative authorities to bypass the need for specific judicial warrants against individuals. It also sketches a fallback option to exclude non-public content from CSAR if no “effective” compromise is reached—risking a permanent parallel loophole via Chat Control 1.0.
- Doc 11956/26 (Council Reflection): Admits that targeted policing already works effectively in Spain and Portugal, yet dismisses its “added value” to justify a broad EU-wide dragnet.
- Doc 8787/23 (Legal Service Warning): In this earlier leak, the Council’s own lawyers explain that scanning “parts” of a service is still “indiscriminate” and would likely be struck down by the CJEU (par. 47 and 79).
FAQ: Debunking the Council’s Narrative
Q: Which services are affected?
A: The scanning affects direct messages on platforms like Instagram, Discord, Snapchat, Skype, and Xbox, as well as emails via Google’s Gmail and Apple’s iCloud. End-to-end encrypted chats, such as those on WhatsApp, have so far been exempt from these scans. European providers of messaging and email services have not implemented chat control measures so far.
Q: The Council claims that the individual targeting requested by the European Parliament is “not operationalizable.” Is that true?
A: No. The Council’s own leaked documents (11956/26) prove that targeted models already work. Spain uses judicial authorization to identify specific users based on “objective indications of criminality.” Portugal targets individuals with relevant criminal records via international cooperation. Europol’s “Operation Alice” proved that massive successes are achieved through targeted detective work, not mass dragnets.
Q: The Council claims the Parliament’s “targeted” approach offers “no added value.” Is that true?
A: On the contrary, the Parliament’s approach is the only one that offers proactive, preventative protection. The Council’s model is reactive: it waits for abuse to happen and then relies on unreliable algorithms or AI to search for it. The Parliament’s mandate adds immense value by requiring apps to be “Safe by Design” for children and to stop grooming through the following specific measures:
- Strict Limits on Unsolicited Contact: Apps must, by default, prevent strangers from establishing unsolicited contact. Users must confirm they want to communicate with an unknown person before messages or content are even displayed.
- Protection of Minors’ Data: To prevent predators from harvesting information, services must ensure that, by default, no user can access a minor’s contact details or location.
- On-Device Empowerment (Not Mass Surveillance): Instead of platform-wide scanning, the EP mandate uses purely on-device functionality under full user control. This technology asks for user confirmation and offers guidance before displaying or sharing sensitive content (like nudity) and displays real-time warnings to users at risk of victimization or offending.
- Privacy-Respecting Parental Tools: It provides device-based parental control tools that allow guardians to protect children while strictly respecting the confidentiality of their communications.
- Proactive Web Cleaning: Beyond redesigning apps, the Parliament tasks a new EU Centre with automated crawling of the public web and Darknet to identify and remove known abuse material at the source—a far more effective method than monitoring private messages.
By focusing on these structural safeguards and limiting private message scanning to judicially designated suspects, law enforcement is spared from sifting through a “whole stream” of intercepted content. This avoids overburdening investigators with the 75% false-positive rate inherent in mass scanning. It frees up capacity for targeted undercover investigations. Europol’s recent “Operation Alice,” has proven that traditional detective work is the only effective way to rescue children and convict predators.
Q: Why is Chat Control mass scanning the wrong approach?
A: The data from Chat Control 1.0 confirms it is a documented failure:
- Police Overwhelmed: The German BKA reports that 52 percent of alerts are not criminally relevant. Investigators waste time on fictional content (Hentai) or AI-generated visuals.
- Criminalizing Children: In Germany, 40% to 53% of investigations target minors themselves (often for consensual sexting). In 2025 alone, this criminalized over 20,000 teenagers.
- No Evidence of Success: The EU Commission admits there is no proven link between mass scanning and an increase in convictions or children rescued. 99% of Meta’s reports consist of previously “known” material, which does not stop active, ongoing abuse.
Act now to save online privacy
Call the offices of Members of the European Parliament that fightchatcontrol.eu marks as “SUPPORTS”. Act before Tuesday, 18:00 to keep our chats private!
