Chat Control: The EU’s Plan to Scan Your Private Messages — And Why It Matters

Imagine a law that required every letter you send to be opened, read by a government-approved system, and flagged if it matched a list of prohibited content — before being resealed and delivered to the recipient. You’d consider that a surveillance state. You’d call it a fundamental breach of the right to private communication.
That’s essentially what the European Commission’s Chat Control proposal — formally, the CSAM Regulation — would do to your digital messages.
This article breaks down what Chat Control is, how it works technically, why critics across the political spectrum are alarmed, and what its passage would mean for the privacy and security of digital communication for hundreds of millions of people.
What Is Chat Control?
Chat Control is a proposed EU regulation officially titled the Regulation Laying Down Rules to Prevent and Combat Child Sexual Abuse. The stated goal is to combat the distribution of child sexual abuse material online and detect grooming.
The mechanism is automated client-side scanning — software built into messaging apps that scans the content of every message before it is encrypted and sent, comparing it against databases of known illegal material and, in some versions, using AI to detect unknown material or grooming patterns.
If a match is detected, the message — and potentially other account data — is flagged and reported to authorities.
The proposal has been controversial since its first draft in 2022. It has faced significant opposition, been revised multiple times, and as of 2025 remains a live legislative battle — but has not gone away.
Why Is This So Controversial?
It Fundamentally Breaks End-to-End Encryption
This is the core technical problem — and it’s not a matter of opinion. It’s a matter of mathematics.
End-to-end encryption (E2EE) means that a message is encrypted on the sender’s device and can only be decrypted on the recipient’s device. The platform — WhatsApp, Signal, iMessage — cannot read the content because it doesn’t hold the keys.
Client-side scanning bypasses E2EE not by breaking the encryption, but by scanning the content before it’s encrypted. The encryption itself remains intact — but the private content is analysed before it leaves your device.
The practical result: your messages are no longer truly private. A scanning system has read them. Whether that system is “just an algorithm” and not a human is a distinction that matters less when the algorithm reports flagged content to authorities.
As a coalition of the world’s leading cryptographers and security researchers stated in a landmark 2021 paper: “The choice is not between a communications system that enables lawful interception and one that does not. The choice is between a system that is secure against all attackers and one that is not.”
You cannot have a backdoor that only the good guys can use. A system built to scan content is a system that can be compelled to scan for other content.
The Scope Creep Problem
Laws designed for one purpose have a long history of being applied more broadly over time. A scanning infrastructure built to detect CSAM could, under future legislation or executive pressure, be applied to detect:
- Political dissent
- Encrypted journalism
- Organised labour activity
- Religious or ethnic communication
- Any content deemed “problematic” by a future government
This is not hypothetical catastrophising. It is the documented history of surveillance infrastructure in multiple countries. The infrastructure, once built, persists across governments.
False Positives at Scale
Any automated detection system produces false positives — cases where innocent content is incorrectly flagged. At the scale of billions of messages per day, even a system with 99.9% accuracy would produce millions of false flags daily.
Each false positive means an innocent person’s private messages are reviewed — potentially by human moderators at the platform, potentially by law enforcement. The chilling effect on free expression, even from the possibility of being flagged, is significant.
The AI-based grooming detection components are even more problematic. Detecting grooming requires reading and interpreting conversational patterns — far more invasive and error-prone than hash-matching known illegal images.
It Undermines Security for Everyone
Security professionals and the cybersecurity community have unanimously opposed Chat Control — not because they are indifferent to child protection, but because a system designed to scan encrypted communications introduces vulnerabilities that can be exploited by anyone: state-level hackers, criminal organisations, and hostile governments benefit from the same backdoor built for law enforcement.
Who Opposes It?
Opposition spans the entire political spectrum and most of the security and tech community:
- The European Data Protection Board
- The European Parliament’s LIBE committee
- The UN Special Rapporteur on Privacy
- Signal (who stated publicly they would exit the EU market rather than implement client-side scanning)
- Hundreds of independent security researchers
- Civil liberties organisations across Europe
- Multiple EU member state governments
The proposal has also been described as unconstitutional by multiple legal experts, as it conflicts with Article 7 (right to private life) and Article 8 (protection of personal data) of the EU Charter of Fundamental Rights.
Where Does It Stand Now?
As of 2025, the regulation remains in legislative limbo. The European Parliament has rejected the most aggressive versions of the proposal. The Council of the EU has struggled to reach a qualified majority. But the proposal has not been withdrawn — the Commission continues to push for some version of scanning, potentially framed as “voluntary” for encrypted platforms.
The outcome will shape the future of private communication for hundreds of millions of Europeans — and set a precedent that other governments worldwide will observe closely.
What You Can Do
At the policy level:
- Contact your MEP and express opposition — legislative outcomes are shaped by constituent pressure
- Follow EDRi (European Digital Rights) and the EFF for updates and action alerts
- Share this information — most people have no idea this proposal exists
At the messaging level:
- Use Signal — it has committed publicly to refusing client-side scanning and would exit the EU market before complying
- Enable disappearing messages by default
- Use end-to-end encrypted email (ProtonMail or Tutanota) for sensitive written communication
The Device Layer: Why Your OS Is Part of This
Client-side scanning is dangerous precisely because it operates on your device — before encryption happens. It doesn’t break the encryption. It goes around it, at the hardware/software layer.
This reveals an uncomfortable truth: even perfect end-to-end encryption is only as trustworthy as the device running it. An operating system that can be compelled to scan content — or that already does, through existing telemetry — is a vulnerability that exists independent of which app you use to message.
This is why device-level privacy matters, not just app-level privacy.
GrapheneOS removes the telemetry from the OS layer entirely. It eliminates the Google Play Services that run with near-root access on stock Android. It gives you per-app network controls and a hardened environment that even a compromised app finds difficult to escape.
A GrapheneOS device cannot be compelled to scan your messages through a mandatory update the same way a stock Android device controlled by its manufacturer can. You own the device. You control the software.
NordSecure ships Google Pixel phones pre-flashed with GrapheneOS, verified boot re-locked on delivery. No Google account. No manufacturer back-channel. A secure phone that belongs to you from day one.
→ See the NordSecure phone · → What Is GrapheneOS?
Keep reading
Ready to act on this? a phone number that isn’t tied to your identity.
Written by
The NordSecure team · Privacy & security
Written by the people who flash, harden and support the devices and private connectivity NordSecure sells — so what you read here comes from the same hands that build the product.
Read next
Is Using an SMS Verification Service Safe and Legal?
An SMS verification service gives you a temporary, real mobile number to receive a one-time sign-up code, so you can register for something without handing over your personal number. The number is single-use and expires, usually within…
How to Pay Online Without Revealing Your Identity
“Anonymous payment” is a spectrum, not a switch — and the gap between feeling private and being private is where most people get caught. Understanding where each method sits is the difference between real privacy and a comfortable illusion…
How to Use an eSIM Anonymously While Travelling
An eSIM is a SIM card built into your phone as software instead of a plastic chip. You install one by scanning a QR code, it activates the first time it connects to a network, and it runs alongside your normal SIM — so you keep your usual…
Ready for a phone that's private by default?
Skip the setup — we flash, harden, and verified-boot re-lock it for you. Travelling instead? Grab an anonymous data eSIM.


