Tech Current
SoftwareJul 7, 2026

Chat Control 1.0 and 2.0 Explained

The EU is dealing with two different “Chat Control” tracks at once: a temporary scanning regime that expired and is now being revived, and a separate permanent proposal that is still stuck in negotiations.

Published by Tech Current · Publisher Alex Naz
Chat Control 1.0 and 2.0 Explained
AI-assisted editorial illustration for this article.

What happened

The term “Chat Control” is being used for two separate EU legislative tracks that are moving in parallel, which helps explain why the latest reporting can sound inconsistent.

The first track, often described as Chat Control 1.0, is Regulation (EU) 2021/1232. It created a temporary exception to the ePrivacy Directive that allowed providers to voluntarily scan private messages for potential child sexual abuse material. According to the source, the law did not require scanning, and it was mainly used by large unencrypted services. It also did not directly scan end-to-end encrypted communications, though providers could use client-side scanning under this framework.

That temporary regime expired on 4 April 2026 after the European Parliament refused to extend it. The source says the Council is now trying to bring it back through a fast-tracked “new” law with identical content, even though Parliament had already rejected the extension.

The second track, Chat Control 2.0, is the proposed Child Sexual Abuse Regulation. This is a permanent proposal that would make detection and reporting of child sexual abuse material a legal requirement for digital platforms. Unlike the temporary law, this proposal is still in trilogue negotiations and has not reached agreement.

The source describes a central disagreement over scanning. The original proposal required scanning of private communications. The Council’s later position shifted toward “voluntary” suspicionless detection paired with broad risk-mitigation obligations. Parliament’s position is more restrictive: scanning of private communications should be limited to specific users or groups suspected of links to child sexual abuse, based on a court order.

The treatment of end-to-end encrypted services remains unresolved in the permanent proposal.

Why it matters

The policy debate is not just about child protection goals. It is also about where the line is drawn between targeted investigation and broad scanning of private communications.

For Chat Control 1.0, the source says the legal basis for voluntary scanning ended when the derogation expired. Yet major companies named in the source — including Google, Meta, Microsoft, and Snap — said they would continue scanning private messages regardless. That makes the legal and technical landscape more complicated than a simple expiration date might suggest.

Illustration for Chat Control 1.0 and 2.0 Explained
AI-assisted editorial illustration for this article.

Chat Control 2.0 raises a different but related issue: whether a platform can be legally pushed into broad detection systems that, in practice, may influence how private messaging works. The source notes that the Council Legal Service itself warned that the “voluntary” scanning model still amounts to generalized scanning of communications and may conflict with Article 7 of the EU Charter without reasonable suspicion and prior judicial authorization.

This matters to developers, service operators, and privacy-focused users because the rules could affect product design, content handling, and encryption architecture. Even where a law is framed as voluntary, the source suggests that accompanying obligations may create strong incentives to scan more widely.

The policy process also matters. The source says five trilogue rounds have failed to produce a deal on Chat Control 2.0, and that the latest talks continue under the Irish presidency. Meanwhile, the attempted revival of Chat Control 1.0 is proceeding through an unusual expedited route after Parliament had already rejected the extension.

What to watch

  • Whether Parliament approves the urgency procedure for the revived Chat Control 1.0 text.
  • Whether the revived text is treated as a second-reading vote, which would require an absolute majority of all MEPs to stop or amend it.
  • Whether the Council continues to push for suspicionless scanning in the permanent Chat Control 2.0 proposal.
  • Whether Parliament’s preferred limits — targeted scanning, judicial authorization, and restrictions on encrypted communications — survive the negotiations.
  • Whether mandatory age verification remains in the draft, since the source says progress has been reported on excluding it, but no final agreement has been reached.

Taken together, the two tracks show a broader institutional conflict: one over renewing an expired temporary scanning regime, and another over whether a permanent EU framework should require any form of message detection at all.

For now, the source’s core message is simple: Chat Control is not one law, but two separate processes with different legal statuses, different scopes, and different political fights.

Watch next

Flock’s Trust Problem Deepens After Public Reversals Over ALPR Claims
SoftwareJul 21, 2026

Flock’s Trust Problem Deepens After Public Reversals Over ALPR Claims

An ACLU account says Flock Safety has repeatedly given inaccurate or misleading answers about its license-plate readers, data access, and privacy controls — including in a Wisconsin city council meeting that approved and then reversed a contract in one day.

Cursor’s agent swarms point to a new cost curve for AI software work
SoftwareJul 21, 2026

Cursor’s agent swarms point to a new cost curve for AI software work

Cursor says its latest swarm system outperformed an earlier version on a Rust rewrite of SQLite, while using different planner-worker mixes to sharply reduce cost and coordination overhead.

Larry Ellison once struggled to keep the lights on while building software. Now he owns most of a Hawaiian island
SoftwareJul 21, 2026

Larry Ellison once struggled to keep the lights on while building software. Now he owns most of a Hawaiian island

The Oracle co-founder’s early days involved payment trouble, investor rejection and a CIA code name that became a company brand. Decades later, he bought nearly all of Lānaʻi and tied it to a renewable-energy vision.

Sources

Analytics, advertising, and privacy choices

We use analytics and advertising cookies only with your permission. You can change this choice later from the footer.

Privacy policy