European Union flags waving in the wind.

EU Chat Control: If Privacy Is Outlawed, Only Outlaws Have Privacy

Niclas Hedam

PhD, Computer Science

· 10 min read · 4 sources · Corrected 20 July 2026

  • Client-side scanning proposals shift private communication from targeted investigation to broad pre-emptive monitoring.
  • The technical burden lands on everyone, while determined offenders can still adapt by changing channels or adding encryption layers.
  • Once scanning infrastructure exists, expanding it to new policy categories becomes easier than reversing it.

I have spent my career looking for the ways a system breaks, and it is not a habit I can leave at work. Once you spend your days finding where things fail before anyone has to depend on them, you start doing it to everything — a new app, the card reader at the kiosk, Copenhagen’s driverless metro. So when the European Union put forward its “Chat Control” proposal, I turned the same habit on it without really meaning to. The closer I look, the more it worries me, not because of its goal, but because of what the tool would have to do to reach it.

We all want children to be safe. That instinct is right, and I share it. But the proposal would place scanning software on every phone in Europe, checking your private messages against a model before they are sent. That is not targeted investigation of a suspect; it is pre-emptive monitoring of everyone, where each of us is treated as worth checking until the software clears us. The stated aim is compassion, and the architecture is built on suspicion. It has to be tested: whether it is legitimate, effective and safe at the scale of a continent, and on all three the answer is not yet convincingly yes.

How the Scanning Would Work

The idea is straightforward: “detect abuse material and grooming early”. The implementation, however, is anything but simple. Chat apps today use end-to-end encryption, which means that the phone of the sender encrypts the message, and only the recipient’s phone can decrypt it. While the message is in transit or stored on servers, no one else can read it, not even the internet provider or app developer. This is a powerful privacy guarantee that protects not only criminals but also journalists, activists, domestic-violence survivors, and ordinary people.

If chat apps are to continue to use end-to-end encryption, scanning must happen on the phone before encryption, i.e. just as the message is being sent. The proposal allows “detection orders” for known images (hash matching), “new/similar” images (perceptual matching), and grooming text. The model that decides what to flag will not be public. You will not see the rules. You will only encounter the system if a classifier is confident enough to escalate your case to the authorities.

Proposal for a Regulation of the European Parliament and of the Council laying down rules to prevent and combat child sexual abuse — The official text of the Chat Control proposal, COM(2022)209, setting out the detection orders and obligations discussed throughout this brief.

Once device-level scanning is normalised, the relationship between citizen and state shifts, and so does your attack surface.

Two Uncomfortable Facts

Most politicians are not experts in cryptography, cybersecurity or artificial intelligence. That is not a failing; it is not their job. It does mean they have to rely on those who are, and to act on what they hear even when the answer is unwelcome. Look at what this proposal would actually require, and two uncomfortable facts stand out.

First, circumvention is relatively easy. If scanning happens before encryption, determined offenders can encrypt a second time before the scanner ever sees the message, or move to hardened, self-hosted infrastructure. Nothing sophisticated is needed: the scanner reads what is on the screen on its way out, so anything the sender and recipient have already agreed to disguise between themselves passes straight through. The system will scan the easy targets, catch the careless, and miss those who are most intent on avoiding detection. This is a point noted by both regulators and the Internet Society. Second, the attack surface increases: mandated on-device classifiers, their update channels, indicator feeds and escalation paths become attractive targets for criminals and hostile states.

Infrastructure Outlives Its Purpose

Surveillance infrastructure, once established, tends to expand in scope. Once device-level scanning is normalised and implemented, adding new categories, such as terrorism, extremism, “disinformation”, tax or copyright, becomes a configuration change, not a new public debate. The technical capability is already present; only political will is required to broaden its use.

Many surveillance mechanisms introduced with narrow initial justification have expanded over time. RIPA in the UK, introduced for investigating serious crime, was later used by councils to monitor dog-fouling and school catchment fraud. The question to ask about any surveillance infrastructure is not only “what will it be used for today?” but “what could it be used for in ten years, under a different government, with different political priorities?”

Who the Scanning Would Actually Reach

Chat Control focuses on mainstream platforms like WhatsApp, Messenger, Signal and Telegram. Determined offenders will move elsewhere once the scanning starts, so it would fall mostly on the law-abiding majority who stay.

Renaming the mechanism does not change that. Signal’s technical analysis responded to the re-branding of client-side scanning as “upload moderation”, which it read as an attempt to downplay the surveillance, and noted that the new name does not solve the core problem: if it happens before encryption, the end-to-end guarantee is broken. End-to-end encryption exists to guarantee that only the intended recipients can read the messages, and introducing scanning on the sender’s device compromises this guarantee.

If privacy is outlawed, only outlaws will have privacy.

Philip Zimmermann, the creator of PGP, wrote this decades ago, when the fight was over export controls on encryption software.

Client-Side Scanning: What It Is and Why It Threatens Trustworthy, Private Communication — Internet Society did an independent technical analysis concluding that circumvention is easy and that scanning primarily catches the careless while missing determined offenders.

New Branding, Same Scanning: “Upload Moderation” Undermines End-to-End Encryption — Signal’s response to the rebranding of client-side scanning as “upload moderation”, arguing the end-to-end guarantee is broken regardless of the terminology used.

A Small Error Rate, a Vast Population

Grant the premise of pre-emptive scanning for a moment, and the arithmetic is still unforgiving. A tiny error rate becomes an enormous number when applied across billions of messages and photos. Every time the system produces a false positive, someone at the police station must investigate, diverting resources from real cases. Each false report consumes investigator hours and can drag innocent families into processes they never deserved while real victims may wait longer for help.

At the same time, context is lost when a model sees only pixels, not relationships: pool photos, bath-time pictures to grandparents, dermatology images for a paediatric consult, screenshots from parenting forums. The artificial intelligence cannot understand who the people in these images are or who you are sending them to. Nor is there a point at which you get to explain: the first you hear of it is when someone else has already decided what the picture shows.

Who Gets Exempted

Then there is the question of who does not get scanned at all. A leaked Council text proposed two exemptions. The professional accounts of intelligence, police and military staff would be left out of the scanning altogether, and confidential information such as professional secrets would be excluded. The two are not the same kind of protection. The state’s own staff are exempted by account, which a provider can actually implement. A patient writing to a doctor, or a client to a lawyer, is protected only in principle, because the scanner would have to recognise a professional secret inside an ordinary chat, and as Patrick Breyer, the former MEP who published the leak, points out, no provider and no algorithm can tell whether a chat is being conducted with a doctor or a lawyer.

Leak: EU interior ministers want to exempt themselves from chat control bulk scanning of private messages — Former MEP and prominent Chat Control opponent Patrick Breyer, reproducing the leaked Council negotiating text, in which interior ministers sought to exempt the professional accounts of intelligence, police and military staff, and others bound by professional secrecy, from the scanning that would still apply to ordinary citizens.

If the technology is truly safe and necessary, why should any group be exempt at all? Professional secrecy is important, but so too is the privacy of ordinary citizens, including families, support workers, and vulnerable individuals. Exemptions risk creating a two-tier system, where privacy is protected for some but not for others.

Encryption Is Load-Bearing

End-to-end encryption supports the security of banking, healthcare, domestic-violence shelters, journalism, elections and the private lives of ordinary people. Mandated server backdoors and client-side scanners both weaken this chain. It is not possible to have “strong” end-to-end encryption and device-level surveillance at the same time.

In 2021, Apple announced plans to scan iCloud Photos on-device for CSAM before upload. After significant pushback from security researchers, privacy advocates, and civil liberties organisations, Apple abandoned the plan, opting instead for narrower, opt-in child safety features.

Apple had full control over its hardware, operating system and infrastructure and still could not make client-side scanning trustworthy enough to ship. The EU’s proposal would apply the same approach across hundreds of device manufacturers and operating systems.

What Actually Moves Outcomes

If the goal is fewer victims and more convictions, efforts should focus where harm and profit concentrate, rather than treating the entire population as suspects. Target distribution networks and repeat offenders, freeze hosting infrastructure and trace payments, improve reporting pipelines so investigators receive fewer, higher-quality tips with context, and run targeted, warrant-backed operations that stand up in court.

The Unanswered Questions

Before any of this becomes law, a few questions deserve clear answers in public. On legitimacy: what legal precedent justifies pre-emptive scanning of private correspondence at all? On effectiveness: what measured increase in arrests and convictions is expected from endpoint scanning over targeted warrants and infrastructure take-downs, and where are the peer-reviewed evaluations? On safety: what are the audited false-positive and false-negative rates per category of content at continental scale, and how will automated tips be kept from overwhelming frontline units? On security: what is the threat model for the mandated scanner itself, its update channels and indicator feeds, and how will hostile reuse of those hooks be prevented? If they cannot be answered cleanly, the mechanism is not ready.

Europe’s Choice

Europe does not have to choose between protecting children and protecting private correspondence. It can go after the places where abuse actually concentrates — distribution networks, hosting, payments — with warrants, resourced investigators and operations that stand up in court. Or it can put a scanner on every phone, accept the false positives that will land on frontline officers, and widen the attack surface for everyone. The first path is harder and slower. The second is easier to pass and far harder to undo.

I keep coming back to the same test. If the mechanism were truly safe and accurate, it would be safe enough to apply to everyone, the state’s own staff included, without a single exemption. That the proposal reaches instead for exemptions is the clearest signal we have of how far its own authors trust it. The wish to keep children safe is real and shared. The harder question is the one those exemptions dodge: whether each of us would accept, with no exemption of our own, the tool we mean to place on everyone.

  • Removed the paragraph citing individual cases of politicians in the exemption section; the argument does not depend on specific cases.

The views and perspectives expressed here are the author's own and do not represent any employer or affiliated organisation. The writing draws on public sources and the author's own experience, never on confidential information.

These briefs are written with the help of AI: it finds sources, drafts and checks. Every choice it makes in a draft is one the author reviews, and the ideas, the judgement and the final words are the author's own. What it does, and what it does not, is set out in the Authorship Was Never the Typing brief.

Niclas Hedam

PhD, Computer Science

Niclas Hedam holds a PhD in Computer Science from the IT University of Copenhagen. He is passionate about educating others on the importance of safeguarding personal information online.

A man lurking behind closed blinds.

Digitalisation: Lost Privacy by Design

· 10 min read · 8 sources

Digitalisation turns public records from manual lookups into mass extraction, exposing your name, address and finances to anyone willing to query them.