PriChat
DE Open app

10 July 2026Digital policy6 min read

Chat control 2026: what was decided on 9 July

On 9 July 2026 voluntary chat control slipped through the EU Parliament via a procedural trick. Here is a calm look at what was actually decided, and what was not.

On 9 July 2026, on the last sitting day before the summer break, the European Parliament voted on what is known as chat control. The result is honestly disappointing, and it is worth taking a calm look at what actually happened, because a lot is being mixed up right now.

First things first: there are two chat controls

This sounds pedantic, but it is the root of all the confusion. You have to keep two things cleanly apart:

  • Chat control 1.0 is a temporary exemption. It lets providers of messengers, email and cloud services voluntarily scan unencrypted messages for known abuse material. End-to-end encrypted content is explicitly excluded. This extension is exactly what the 9 July vote was about.
  • Chat control 2.0, officially the CSA Regulation, is the big one. It is meant to become permanent and to include mandatory detection orders, including scanning directly on your device. It is still stuck and was not on the table on 9 July at all.

What really happened on 9 July

Parliament could have rejected the Council's position. But that would have required an absolute majority, that is 361 of 720 votes. In the end 314 members voted for rejection, 276 against, with 17 abstentions. So the majority of those present were against it, but the required threshold was missed. And here is the catch: because the absolute majority was not reached, the Council's position counts as not rejected. It is effectively through.

Let us be honest, that was no accident. Parliament President Roberta Metsola had put the proposal, already rejected in March, back on the agenda in late June via an urgent procedure, right on the thinly attended last sitting day before the break. On a day like that, an absolute majority is almost impossible to reach. Critics call it a procedural trick, and honestly, that fits quite well.

For context: the old interim rule had expired on 4 April 2026 after Parliament rejected an extension on 26 March. The Council pushed a nearly identical version on 2 July.

What the now-extended 1.0 actually means

Stay calm here. The 1.0 is not the end of the world, and that matters to me, because there is a lot of panic going around online. Concretely it means:

  • Scanning is voluntary, no provider is forced.
  • It affects unencrypted content in messengers, email and cloud.
  • End-to-end encrypted messages are excluded, an amendment to that effect was adopted.
  • No mandatory scanning on your device.

The text now goes back to the Council, which has to adopt it within three months. That keeps voluntary scanning possible until 3 April 2028.

The real heavy weight is still 2.0

And this is where it gets uncomfortable. The planned CSA Regulation wants mandatory detection orders, and at its core sits what is called client-side scanning. That means your message is searched on your own device before it is even encrypted. That would effectively break end-to-end encryption, no matter how strong it is. The plan is a mix of matching known content, AI detection of new content, grooming detection and, in parts, age verification.

The fifth and supposedly final trilogue on 29 June failed on exactly this point. The next round is scheduled for September 2026 under the Irish Council presidency. The conflict stays the same: the Council wants to enshrine untargeted scanning permanently, Parliament wants to limit it to suspicion-based, court-ordered cases and protect encryption.

Why so many experts are sounding the alarm

This is not a handful of activists. More than 800 scientists and cryptographers have warned of unacceptably high error rates. Think about what that means: with millions of messages a day, even a tiny error rate dumps huge numbers of harmless private photos and chats onto reviewers. On top of that comes the basic criticism that this scans the communication of innocent citizens without cause, instead of targeting offenders. Germany's data protection authorities have also called on the EU to drop chat control fully and permanently.

What this means for you and for PriChat

Very directly: nothing changes at PriChat for now. With us the server never sees your plaintext anyway, only ciphertext. Your messages are encrypted on your device and only decrypted again at the recipient. The now-extended 1.0 explicitly excludes encrypted content, so it does not affect us.

The point that really matters is 2.0 with its client-side scanning. Because it would strike at the one place where your message is still in plaintext, namely right on your device. And that is exactly why I think it is so important that this is discussed openly now, and not waved through in a half-empty session.

What you can do

Use end-to-end encryption, stay informed on the topic, and if it matters to you, write to your representatives. Sounds old-fashioned, but it works. The last votes were close, and every vote in Parliament really counts here.

In short

Voluntary chat control 1.0 was extended with a procedural trick, but it does not touch encrypted messages. The dangerous 2.0 with on-device scanning is not through yet, but it returns to the table in September. It is worth staying on it.

← Back to the guide

Ready?

Chat privately, no explanations needed.

Get started for free