Chat Control is the informal name for a legislative proposal by the European Commission β formally known as the CSAR (Child Sexual Abuse Regulation) β that would require online platforms to automatically scan private messages, photos, and files for illegal content. On the surface, the stated goal is protecting children from exploitation. Nobody argues against that goal. The problem is the method.
The proposal demands that encrypted messaging services β Signal, WhatsApp, iMessage, Proton Mail β scan the content of your messages before they're encrypted, or after they're decrypted on the recipient's device. This means breaking or bypassing the very encryption that protects everyone's privacy. Including yours. Including journalists'. Including activists' in authoritarian regimes who rely on EU-made software to stay alive.
In short: to catch criminals, the proposal requires surveilling everyone, all the time, without suspicion.
May 2022 β The European Commission publishes the original CSAR proposal. It suggests mandatory detection orders that could force any messaging service to scan all user communications for known CSAM (child sexual abuse material), new CSAM, and "grooming" patterns.
2023 β Massive pushback from cybersecurity experts, cryptographers, digital rights organizations (EFF, EDRi, Privacy International), and even some EU member states. The concept of "client-side scanning" β scanning images on your phone before they're sent β emerges as the only technically possible way to scan end-to-end encrypted messages. Experts universally warn it's fundamentally insecure.
2024 β The European Council attempts to reach a compromise. Several proposals are floated, including voluntary scanning, age verification, and geoblocking. None address the core contradiction: you cannot scan encrypted content without breaking encryption.
2025-2026 β Negotiations continue behind closed doors. Public attention fades. The regulation quietly evolves. Each iteration narrows scope on paper while expanding surveillance infrastructure in practice. This is how mass surveillance typically becomes law β not in one dramatic vote, but through slow erosion of opposition.
The technical mechanism at the heart of Chat Control is called client-side scanning (CSS). Here's how it would work:
Your phone runs an algorithm that scans every photo, every file, every message you send β on your device, before encryption happens. If the algorithm flags something suspicious, it reports to a central server. The scanning happens locally, so encryption "technically" remains intact.
Except it doesn't. Here's why:
1. It creates a backdoor on every device. If your phone can scan your messages and report them, then your phone is no longer your phone. It's a surveillance device that happens to also make calls. And any backdoor designed for one purpose can be repurposed β by hackers, by authoritarian governments, by anyone who gains access.
2. False positives are inevitable. Perceptual hash algorithms (like PhotoDNA) produce false matches. Apple's own CSAM scanning system, introduced and then quickly shelved in 2021, demonstrated this risk. A family sharing vacation photos. A doctor sending medical images. A lawyer exchanging case files. All it takes is one hash collision to turn an innocent person into a suspect.
3. The scanning target expands. Today it's CSAM. Tomorrow it's terrorism content. Then copyright violations. Then political dissent. Mission creep isn't speculation β it's the documented history of every surveillance power ever granted to governments. The infrastructure doesn't disappear when the original justification does. It simply finds new targets.
4. It doesn't work against actual criminals. Anyone serious about evading detection will use tools that bypass client-side scanning β custom clients, steganography, alternative platforms. The only people caught in the net are ordinary citizens whose privacy is collateral damage.
// SECURITY ADVISORY: Client-side scanning is equivalent to having a government agent reading over your shoulder. The fact that the agent is software doesn't make it less invasive β it makes it worse. Software scales infinitely and never forgets.
For encryption: The proposal effectively outlaws true end-to-end encryption within the EU. Services would either comply by implementing scanning (breaking their own encryption) or withdraw from the European market entirely. Signal has publicly stated they would rather shut down in the EU than compromise their encryption. Proton has said the same. When the companies building secure communication systems tell you a law makes security impossible, that's not opinion β it's engineering reality.
For privacy: The fundamental right to private communication β enshrined in Article 8 of the European Convention on Human Rights β is replaced with "private, except when we're watching." That's not privacy. That's monitored communication with gaps.
For security researchers and journalists: Encrypted communication isn't just for privacy enthusiasts β it's operational security for people whose lives depend on confidentiality. Sources, whistleblowers, activists in hostile environments. Breaking encryption for everyone breaks it for the people who need it most.
For democracy: Mass surveillance infrastructure, once built, is rarely dismantled. The capabilities created under Chat Control would persist long after the current political context. Future governments β possibly less democratic, less restrained β would inherit a system capable of monitoring all digital communication. History teaches us that powers granted in crisis are almost never returned.
The entire debate comes down to one sentence:
You cannot have a backdoor that only good people can walk through.
Encryption is mathematics. It doesn't distinguish between authorized and unauthorized access. A weakness that lets law enforcement read your messages also lets attackers read your messages. There is no "golden key." There is no "secure backdoor." These are contradictions in terms.
Protecting children is a legitimate and important goal. But destroying the privacy of 450 million Europeans to do it isn't just disproportionate β it's mathematically counterproductive. You don't protect vulnerable people by making everyone vulnerable.
// they who would give up essential liberty to purchase a little temporary safety deserve neither // - benjamin franklin