YOUR
Search

    20.09.2026

    Chat Control: where does the UE proposal on combating children sexual abuse online stand?


    For more than four years, the European Union has been negotiating a proposal for a Regulation aimed at preventing and combating child sexual abuse online, commonly referred to in public debate as “Chat Control”. Presented by the European Commission on 11 May 2022 (COM(2022) 209 final), the proposal introduces obligations on digital service providers concerning risk assessment, mitigation, detection, reporting, removal and blocking of child sexual abuse material (CSAM) and online grooming, and establishes a new EU Centre for the prevention and combating of child sexual abuse.

    The most controversial issue, and the one from which the proposal derives its name, concerns detection orders, i.e. the possibility for an authority to require a communications service provider, including providers of end-to-end encrypted communications services, to deploy technologies that scan content exchanged by users for CSAM or signs of grooming. Negotiations on this issue have been deadlocked for years, while the voluntary regime that has meanwhile allowed platforms to continue scanning has itself gone through a period of significant institutional instability in recent months.

     

    The framework of the proposal

    The proposal applies to hosting service providers, providers of interpersonal communications services and operators of app stores, which are required to assess the risk that their services may be used to disseminate CSAM or for the grooming of minors and to adopt proportionate mitigation measures, such as age-verification or parental-control tools. Where such measures prove insufficient, the Commission’s proposal allows the national coordinating authority to request that an independent judicial or administrative authority issue a detection order requiring the provider to deploy scanning technologies, subject to a number of safeguards: a limited duration (up to 24 months for CSAM and 12 months for grooming), targeted application, the least intrusive technologies available, and rights of appeal for providers and users.

    Alongside these orders, the proposal maintains a system of removal orders addressed to hosting providers, blocking orders directed at internet access providers in respect of content hosted outside the EU, and an exemption from criminal liability for providers that, in good faith, process CSAM for the purposes of its detection, reporting and removal.

     

    The encryption issue 

    In its negotiating position of 22 November 2023, the European Parliament excluded end-to-end encrypted communications from the scope of detection orders. In the Council, successive Presidencies have explored intermediate solutions, including detection obligations limited to high-risk services and a scanning mechanism on the user’s device before encryption, subject to the user’s consent, but without securing sufficiently broad agreement among the Member States.

    On 30 October 2025, the Danish Presidency acknowledged that the prospects of reaching a balanced compromise had been exhausted, owing to persistent concerns relating to users’ fundamental rights, cybersecurity and the reliability of the technologies available, and proposed removing mandatory detection orders from the text, thereby making permanent the currently temporary derogation provided for by Regulation (EU) 2021/1232.

     

    The collapse and return to the voluntary regime

    While negotiations on the permanent proposal remained deadlocked on this issue, the transitional regime introduced in 2021, which allows providers of interpersonal communications services to voluntarily scan content for CSAM in derogation from the ePrivacy Directive, reached a genuine breaking point. On 20 March 2026, the European Parliament rejected, by a single vote (307 to 306), an extension of the regime, which therefore expired on 3 April 2026 without replacement. On 9 July, the Parliament voted again, with an equally negative outcome: 311 against, 228 in favour and 92 abstentions.

    Despite the two rejections, on 23 July 2026 the Council nevertheless finally adopted an interim Regulation reinstating the voluntary regime until 3 April 2028, with only Hungary voting against and Belgium abstaining. Its reactivation, without the Parliament’s consent, has reignited the debate over the institutional legitimacy of the procedure followed.

     

    The state of the trilogue negotiations on the permanent proposal

    In parallel, the three-way negotiations between the Commission, the Council and the Parliament on the permanent text are continuing. On 13 February 2026, the institutions reached a provisional agreement on certain provisions relating to the EU Centre, while detection obligations remain the main outstanding issue. According to the most recent accounts of the trilogue negotiations held in summer 2026, the negotiators appear to have moved towards protecting end-to-end encryption and substantially scaling back age-verification obligations, while the fundamental question remains open: namely, whether detection should remain mandatory or voluntary, targeted or generalised.

    The next trilogue session, the sixth, is expected to take place on 29 September 2026, the first under the Irish Presidency of the Council, which has historically been close to Member States in favour of detection.

     

    Fundamental rights safeguards

    The underlying legal issue concerns the balancing of the protection of children, enshrined in Article 24(2) of the Charter of Fundamental Rights of the European Union, against the rights to respect for private life and communications (Article 7) and to the protection of personal data (Article 8) of all users of the services concerned.

    In Joint Opinion 4/2022, the European Data Protection Board (EDPB) and the European Data Protection Supervisor (EDPS) had already pointed out that measures providing for general and indiscriminate access to the content of communications risk interfering with the very essence of the rights guaranteed by Articles 7 and 8 of the Charter, and that technologies for detecting previously uncategorised material still have significant error rates. In its subsequent Statement 1/2024, the EDPB observed that the definition of “reasonable grounds for suspicion” adopted by the Parliament does not, in itself, yet guarantee that detection orders will remain genuinely targeted rather than general and indiscriminate.

    These concerns are consistent with the established case law of the Court of Justice of the European Union, according to which general and indiscriminate retention of traffic and location data, without distinctions or limitations linked to the objective pursued, is incompatible with Articles 7, 8 and 52(1) of the Charter, save in exceptional circumstances relating to serious and present threats to national security (see Digital Rights Ireland and Seitlinger, Joined Cases C-293/12 and C-594/12; Tele2 Sverige, Joined Cases C-203/15 and C-698/15; La Quadrature du Net, Case C-470/21). Although these judgments concern the retention of metadata rather than the scanning of content, the same principles of strict necessity and proportionality are the benchmark against which the EDPB and EDPS assess the compatibility of detection orders with the Charter.

     

    What happens next

    The issue is now playing out along two parallel tracks. On the one hand, the voluntary regime remains in force until 3 April 2028, but its legal basis has been called into question by the manner in which it was reactivated, bypassing two negative votes by the Parliament, and it cannot be ruled out that the matter may ultimately be brought before the courts. On the other hand, the outcome of the permanent proposal will depend on the next trilogue negotiations, starting with the session scheduled for 29 September 2026, and in particular on the choice, which remains entirely open, as to whether the detection obligations should be mandatory or voluntary.

    We will continue to monitor developments in the negotiations and will provide further updates as soon as the proposal moves further forward.

    ADVANT Nctm steps up its focus on the digital economy: launch of the Digital, Tech and Data Department
    ADVANT Nctm is taking a further step forward in the digital economy with the…
    Read more
    Artificial intelligence putting corporate governance to the test: adequate arrangements, model 231 and liability
    The use of artificial intelligence is (also) progressively becoming part of…
    Read more
    Data breach notification: what changes with the EDPB common template
    On 10 June 2026, the European Data Protection Board (“EDPB”) adopted a draft…
    Read more
    GEMA v. Suno: a new european precedent on the relationship between generative AI and copyright
    The very recent judgment handed down by the Regional Court of Munich in the GEMA…
    Read more
    Online contracts and terms requiring specific approval: the Italian Supreme Court reconsiders an established practice
    By Order No. 20945 of 20 June 2026, the Third Civil Division of the Italian…
    Read more
    EU KIDS Act: Brussels rewrites the rules for digital services for Minors
    On 17 September 2026, the European Commission presented its proposal for a…
    Read more
    THE RULES OF ARTIFICIAL INTELLIGENCE: FROM THE “PRIMACY” OF THE AI ACT TO MULTILEVEL FRAGMENTATION
    Until recently, the AI Act could present itself as “the world’s first regulatory…
    Read more
    ARTIFICIAL INTELLIGENCE: NEW CRIMINAL LAW IMPLICATIONS REGARDING CORPORATE LIABILITY UNDER ITALIAN LEGISLATIVE DECREE No. 231/2001
    On 15 September 2026, Legislative Decree No. 160 of 9 September 2026 (the…
    Read more