EU Chat Scanning Returns Through 2028
Coverage from Human Rights Research Center, SMEX, and others

The European Parliament renewed a temporary EU framework allowing online service providers to voluntarily scan some private communications for child sexual abuse material, with the measure scheduled to remain in force through April 2028.
The decision followed earlier votes against extending the framework and a failed rejection vote in July. The dispute centers on how to detect abuse material while protecting private communications and encryption; negotiations on a permanent framework continue.
The key change is procedural: after earlier rejection, the European Parliament now approved a renewed temporary legal basis for voluntary CSAM scanning through 2028. The story also sharpens around the unresolved permanent framework, especially debates over encryption, oversight, and whether any future rules should remain targeted.
The key change is procedural reversal: the EU first rejected extending the temporary CSAM-scanning framework, then restored it through 2028. At the same time, the permanent Chat Control fight is now described as more stalled and specific, with fresh fault lines around targeted warrants, age verification, risk mitigation, and encryption.
- Parliament first rejected, then later approved, the temporary framework.
- The revived derogation runs through 2028.
- Permanent Chat Control talks are politically stalled.
- Debate now includes targeted warrants and age verification.
- Opponents cite false positives and evasion risks.
The story has shifted from a mostly resolved privacy clampdown to an active, unresolved legislative process. New reporting shows temporary ePrivacy exemptions may now run into 2028 and the debate is moving through formal EU vote and negotiation steps toward a possible permanent Chat Control framework.
- Temporary scanning exemptions may have been extended or reactivated into 2028.
- The file is advancing through second-reading and renewal steps.
- Encrypted services are being treated as a central carve-out issue.
- Google, Meta, Microsoft, Snap, TikTok, and Apple are named as likely implementers.
- Negotiations now point toward a permanent Chat Control 2.0 framework.
The cluster is centered on the EU’s move away from blanket scanning of private messages and images, with Parliament rejecting or blocking key Chat Control and CSAM-scanning provisions and the temporary legal derogation for platform scanning expiring. The dominant pattern is a privacy-versus-child-safety regulatory conflict, now tilted toward tighter limits on mass surveillance, while voluntary scanning by major platforms and continued negotiations over targeted detection keep the issue unsettled.
