If you send a message on Signal or WhatsApp today, EU law does not apply to it for now. If you send the same photo through an unencrypted app, it may already be checked by an automated system before anyone reads it. This distinction, rather than a broad claim that “the EU reads your DMs,” reflects the core issue in the ongoing debate over Chat Control and the detection of child sexual abuse material (CSAM) online.
ADVERTISEMENT
ADVERTISEMENT
A revived temporary regulation, in force until 2028, allows platforms to voluntarily scan private messages, photos, and videos for CSAM. This does not apply to end-to-end encrypted services like WhatsApp or Signal in the same way it applies to other platforms. A separate permanent proposal, “Chat Control 2.0”, is still being negotiated. Whether it eventually reaches encrypted chats remains the central unresolved question.
How the system decides what to flag
Detection tools work in two main ways. The first is hash matching: an image or video is converted into a cryptographic fingerprint and compared against a database of material confirmed as illegal. It is fast and precise for exact or near-identical copies but easy to defeat with a small edit. The second is machine-learning classification, used for new or altered content and, more controversially, for scanning text for language patterns associated with grooming.
Patrick Breyer, a digital rights activist, jurist and former MEP for the Greens/European Free Alliance, argues both methods are less reliable than policymakers assume. Hash matching, the more accurate of the two, “comes with a very high rate of false positives of falsely incriminating people,” he says, pointing to Germany, where recent figures show “more than 50 percent of most reports are actually not criminally relevant.”
Part of the problem, he explains, is upstream: databases are often built and vetted abroad rather than assessed against European criminal law. “Some staff of providers, wherever they are located in the world, enter stuff in databases” without a proper legal assessment of intent, a requirement for something to be criminally relevant in the first place.
Where the scan happens
On unencrypted platforms, this checking can happen on the provider’s own servers. On end-to-end encrypted services, the provider cannot read a message once it’s encrypted. So any detection has to move earlier in the chain: onto the device itself before encryption is applied or into a separate secure hardware layer built for the purpose.
This is called client-side scanning. It is the main reason the encryption debate hasn’t gone away: the message is inspected while still readable, “before the lock closes,” rather than intercepted afterwards.
What happens after a match
A flagged item does not go straight to a police file. According to providers like Google, a match, whether from hash comparison or an AI model, is typically routed to trained human reviewers at the company who confirm it before anything is reported. That confirmation step is where Breyer says the process breaks down at scale.
Reviewers assess against varying legal standards, do not always establish intent, and frequently misclassify ordinary teenage sexting or self-generated images shared as jokes within a chat group. He notes many minors caught in these reports never intended to send or receive anything illegal, they simply forwarded something in a group chat “about something else.”
Image hashing compares against confirmed illegal material. Text is a different problem. Grooming language can closely resemble ordinary teenage or adult conversation, which is why researchers flag text-based detection as the most error-prone layer of the system. That distinction matters for the permanent proposal. Expanding any future rule from images to conversational text would multiply the false-positive problem Breyer describes in image scanning.
The alternative on the table
Breyer doesn’t reject detection fully. He rejects doing it in bulk. He argues scanning is justified only when “an independent court confirms” reasonable suspicion against a specific person, comparable to a warrant to open someone’s mail. Scanning everyone “just in case,” he says, is a different category of intrusion entirely.
As an alternative, he points to two things: proactive scanning of the open web and dark web for already-known illegal material and reporting it for removal, used in the UK and Canada, not yet in the EU, and “security by design,” where apps warn users on-device before they share a phone number or nude image, without any content ever leaving the phone.
Where this leaves your data
For now, what happens to a message depends entirely on which app carries it. On unencrypted platforms, content can be fingerprinted or algorithmically scanned before or immediately after sending, reviewed by trained staff at the provider, and reported if confirmed. On end-to-end encrypted apps, that pipeline does not apply, though the unresolved permanent proposal could still change where and how early that scanning line is drawn.

