For more than four years, the European Union has been negotiating a proposal for a Regulation aimed at preventing and combating child sexual abuse online, commonly referred to in public debate as “Chat Control”. Presented by the European Commission on 11 May 2022 (COM(2022) 209 final), the proposal introduces obligations on digital service providers concerning risk assessment, mitigation, detection, reporting, removal and blocking of child sexual abuse material (CSAM) and online grooming, and establishes a new EU Centre for the prevention and combating of child sexual abuse.
The most controversial issue, and the one from which the proposal derives its name, concerns detection orders, i.e. the possibility for an authority to require a communications service provider, including providers of end-to-end encrypted communications services, to deploy technologies that scan content exchanged by users for CSAM or signs of grooming. Negotiations on this issue have been deadlocked for years, while the voluntary regime that has meanwhile allowed platforms to continue scanning has itself gone through a period of significant institutional instability in recent months.
The framework of the proposal
The proposal applies to hosting service providers, providers of interpersonal communications services and operators of app stores, which are required to assess the risk that their services may be used to disseminate CSAM or for the grooming of minors and to adopt proportionate mitigation measures, such as age-verification or parental-control tools. Where such measures prove insufficient, the Commission’s proposal allows the national coordinating authority to request that an independent judicial or administrative authority issue a detection order requiring the provider to deploy scanning technologies, subject to a number of safeguards: a limited duration (up to 24 months for CSAM and 12 months for grooming), targeted application, the least intrusive technologies available, and rights of appeal for providers and users.
Alongside these orders, the proposal maintains a system of removal orders addressed to hosting providers, blocking orders directed at internet access providers in respect of content hosted outside the EU, and an exemption from criminal liability for providers that, in good faith, process CSAM for the purposes of its detection, reporting and removal.
The encryption issue
In its negotiating position of 22 November 2023, the European Parliament excluded end-to-end encrypted communications from the scope of detection orders. In the Council, successive Presidencies have explored intermediate solutions, including detection obligations limited to high-risk services and a scanning mechanism on the user’s device before encryption, subject to the user’s consent, but without securing sufficiently broad agreement among the Member States.
On 30 October 2025, the Danish Presidency acknowledged that the prospects of reaching a balanced compromise had been exhausted, owing to persistent concerns relating to users’ fundamental rights, cybersecurity and the reliability of the technologies available, and proposed removing mandatory detection orders from the text, thereby making permanent the currently temporary derogation provided for by Regulation (EU) 2021/1232.
The collapse and return to the voluntary regime
While negotiations on the permanent proposal remained deadlocked on this issue, the transitional regime introduced in 2021, which allows providers of interpersonal communications services to voluntarily scan content for CSAM in derogation from the ePrivacy Directive, reached a genuine breaking point. On 20 March 2026, the European Parliament rejected, by a single vote (307 to 306), an extension of the regime, which therefore expired on 3 April 2026 without replacement. On 9 July, the Parliament voted again, with an equally negative outcome: 311 against, 228 in favour and 92 abstentions.
Despite the two rejections, on 23 July 2026 the Council nevertheless finally adopted an interim Regulation reinstating the voluntary regime until 3 April 2028, with only Hungary voting against and Belgium abstaining. Its reactivation, without the Parliament’s consent, has reignited the debate over the institutional legitimacy of the procedure followed.
The state of the trilogue negotiations on the permanent proposal
In parallel, the three-way negotiations between the Commission, the Council and the Parliament on the permanent text are continuing. On 13 February 2026, the institutions reached a provisional agreement on certain provisions relating to the EU Centre, while detection obligations remain the main outstanding issue. According to the most recent accounts of the trilogue negotiations held in summer 2026, the negotiators appear to have moved towards protecting end-to-end encryption and substantially scaling back age-verification obligations, while the fundamental question remains open: namely, whether detection should remain mandatory or voluntary, targeted or generalised.
The next trilogue session, the sixth, is expected to take place on 29 September 2026, the first under the Irish Presidency of the Council, which has historically been close to Member States in favour of detection.
Fundamental rights safeguards
The underlying legal issue concerns the balancing of the protection of children, enshrined in Article 24(2) of the Charter of Fundamental Rights of the European Union, against the rights to respect for private life and communications (Article 7) and to the protection of personal data (Article 8) of all users of the services concerned.
In Joint Opinion 4/2022, the European Data Protection Board (EDPB) and the European Data Protection Supervisor (EDPS) had already pointed out that measures providing for general and indiscriminate access to the content of communications risk interfering with the very essence of the rights guaranteed by Articles 7 and 8 of the Charter, and that technologies for detecting previously uncategorised material still have significant error rates. In its subsequent Statement 1/2024, the EDPB observed that the definition of “reasonable grounds for suspicion” adopted by the Parliament does not, in itself, yet guarantee that detection orders will remain genuinely targeted rather than general and indiscriminate.
These concerns are consistent with the established case law of the Court of Justice of the European Union, according to which general and indiscriminate retention of traffic and location data, without distinctions or limitations linked to the objective pursued, is incompatible with Articles 7, 8 and 52(1) of the Charter, save in exceptional circumstances relating to serious and present threats to national security (see Digital Rights Ireland and Seitlinger, Joined Cases C-293/12 and C-594/12; Tele2 Sverige, Joined Cases C-203/15 and C-698/15; La Quadrature du Net, Case C-470/21). Although these judgments concern the retention of metadata rather than the scanning of content, the same principles of strict necessity and proportionality are the benchmark against which the EDPB and EDPS assess the compatibility of detection orders with the Charter.
What happens next
The issue is now playing out along two parallel tracks. On the one hand, the voluntary regime remains in force until 3 April 2028, but its legal basis has been called into question by the manner in which it was reactivated, bypassing two negative votes by the Parliament, and it cannot be ruled out that the matter may ultimately be brought before the courts. On the other hand, the outcome of the permanent proposal will depend on the next trilogue negotiations, starting with the session scheduled for 29 September 2026, and in particular on the choice, which remains entirely open, as to whether the detection obligations should be mandatory or voluntary.
We will continue to monitor developments in the negotiations and will provide further updates as soon as the proposal moves further forward.