Last updated: August 15, 2026
On July 9, 2026, 314 members of the European Parliament voted to kill mass chat scanning. That was more than the opposition — 276 MEPs voted to keep it. The rejection won. And the law passed anyway.
Here’s the sentence that should make every builder’s blood run cold, then boil: a majority of voting MEPs rejected Chat Control 1.0 — the EU’s mass chat-scanning law — and it became law regardless. Not because of a conspiracy — because of a procedural mechanism most people have never heard of, run at a time of year designed to make resistance mathematically impossible.
This is the story of how a dead EU surveillance law came back through the back door — the sequel to our December 2026 deadline warning, what the revived law actually says (less than the headlines suggest), and — most importantly — exactly where the fight goes from here. Because the fight is not over. It has a date: September 2026.
The 90-Second Timeline

Six facts, all verifiable in the Official Journal:
- March 11, 2026 — Parliament approved a trilogue mandate that would have limited the scanning scope.
- March 26, 2026 — Parliament rejected the extension outright: 311 to 228, with 92 abstentions. A clear win. The interim derogation expired April 3.
- June 18 — EP President Roberta Metsola publicly invited the Council to reopen the file — asking member states to approve a bill her own Parliament had voted down. Politico called the move “without precedent.”
- July 2 — The Council adopted its first-reading position under Article 294(5) TFEU. Since an expired act can’t legally be “extended,” they simply re-enacted the entire text as a brand-new regulation.
- July 9 — Second reading in Parliament, on the last sitting day before summer recess. 314 MEPs voted to reject. Rejection required an absolute majority — 360 by euronews’ count, 361 by Breyer’s. The vote fell short. Under the procedure, the law was then automatically deemed adopted.
- July 23–24 — The Council formally adopted the revived regulation: Hungary against, Belgium abstaining, everyone else silent. It published July 28 as Regulation (EU) 2026/1881, entered into force July 31, and applies until April 3, 2028.
One more number: a majority of voting MEPs did vote to restrict scanning to judiciary-identified suspects — 322 to 255. That amendment passed. And it died anyway, because at second reading, amendments also need an absolute majority. Rapporteur Damian Sippel called the whole maneuver “unfair.” He was being polite.
The Back Door, Explained Like You’re a Builder

Think of it as a race condition exploited against a democratic system:
The ordinary legislative procedure assumes both institutions negotiate on roughly equal footing. But Article 294(5) TFEU has a failure mode: if Parliament can’t muster an absolute majority (of all MEPs, not just those present) to reject or amend the Council’s position at second reading, the Council’s text passes automatically. No majority needed. Silence is consent.
Now schedule that second-reading vote for the final sitting day before the summer recess — when, as former MEP Patrick Breyer put it, “significantly fewer MEPs are present on this day” — and bypass the normal committee scrutiny with an urgent procedure approved July 7. The result: a law that a plurality of present-and-voting MEPs opposed becomes binding on 450 million people.
You don’t need to believe in conspiracies. You just need to read the procedure. It’s a privileged escalation path, and they used it.
What the Law Actually Says: Regulation (EU) 2026/1881 Explained

Here’s where it gets less scary than the headlines — and the headlines were pretty scary. I pulled the full text of Regulation (EU) 2026/1881. Three things matter:
1. It’s still voluntary. The regulation “enabl[es] providers… to use specific technologies” for detection. That’s permission, not obligation. No provider anywhere is mandated to scan anything. That’s why Breyer notes European messaging and email providers “have never implemented chat control measures anyway.” The refusal lever is real, and it’s in the text.
2. End-to-end encryption is excluded — in the actual operative text. Not a press-release promise. Article 1(3): “This Regulation does not apply to interpersonal communications to which end-to-end encryption is, has been or will be applied.” Audio communications are excluded too. Recital 32 adds that nothing in the regulation “should… be interpreted as prohibiting or weakening end-to-end encryption.” Euronews calls the wording “cosmetic” — providers weren’t scanning E2EE content anyway — but cosmetic or not, it’s statutory.
3. No client-side scanning. Anywhere. The phrase “client-side” appears zero times in the regulation. Client-side scanning — spyware on your device — remains Chat Control 2.0 territory, and there it’s currently losing.
What IS covered: the non-E2EE direct-message layers of platforms like Instagram, Discord, Snapchat, Skype, Xbox, plus email services like Gmail and iCloud. Voluntarily. Until April 2028.
And here’s the accountability angle that should actually enrage you: when the derogation lapsed April 3, Google, Meta, Microsoft, and Snap signaled in a joint statement they’d “continue to take voluntary action” — scanning that EFF and netzpolitik point out has been operating without legal basis since the April expiry. The back-door law didn’t start the scanning. It laundered it.
The Real Fight Is September: Chat Control 2.0

Chat Control 1.0 is the temporary zombie. Chat Control 2.0 — the permanent CSAR regulation — is the actual war, and it’s in trilogue right now.
- Forced scanning of encrypted messages: member states gave it up, and per a leaked June 22 Council state-of-play, the provisional position now states the regulation does not “prohibit, make impossible, weaken, circumvent or otherwise undermine” encryption or create “any obligations for providers to decrypt.”
- Age verification is the new front line: the Council wants it compulsory for messaging services “that present a risk of solicitation”; Parliament wants it optional. This is exactly the identity-creep pattern we’ve been tracking state-by-state in the US arriving at EU scale.
- The fourth trilogue was May 11. Euronews reported in mid-July that negotiators “may be close to reaching a deal.” Talks resume in September.
EFF framed it precisely: “This is a zombie proposal. It keeps coming back and must not be allowed to return through the back door.” It just did — once. The second attempt is scheduled.
The Resistance Stack: What You Actually Do Now

Here’s the part most coverage gets wrong. This is not a “lie back and think of the children” moment. It’s a build-and-fight moment, and the law itself concedes the ground:
1. Move your sensitive comms to E2EE. It’s now legally carved out.
Signal, WhatsApp, any E2EE service: the operative text of the law does not apply to them. This isn’t a workaround; it’s Article 1(3). Your threat model for DMs should already have assumed the platform can read them — Instagram and Discord DMs were scannable before this law, during it, and after it. The fix is the same as it’s always been: E2EE for anything that matters.
2. Self-host your messaging. The scope definitions work in your favor.
The regulation only covers “number-independent interpersonal communications services” as defined in the EECC — and that definition applies to services “normally provided for remuneration.” Your personal Matrix or XMPP server, run for yourself and friends, is a different animal from a commercial provider. And since scanning under 2026/1881 is voluntary even for covered providers, a self-hosted server you control has no scanning path at all. That’s not a loophole — that’s architecture. (Full disclosure: no first-party EU statement names self-hosted servers explicitly; this is legal analysis from the statutory text, and I’d bet the farm on the text.)
3. Refuse, loudly, if you run a covered service.
European providers never implemented chat control — which is living proof that “voluntary” means optional. If you run a messaging or email service in the EU: you are not required to scan. Choosing not to is a lawful, precedented act of resistance. Say so publicly. Every European provider that refuses makes the “voluntary” fiction harder to maintain.
4. Make September loud.
The permanent law is negotiated by people who answer to voters. Fight Chat Control and EDRi’s action page are running exactly that campaign. The specific asks worth backing come from Breyer’s alternative framework: mandatory detection orders targeting suspects instead of indiscriminate scanning, an EU center for removing known abuse material from the open web, and Security-by-Design requirements for messaging apps. That’s a child-safety policy that doesn’t require surveilling everyone. It exists. It’s on the table. It needs votes.
5. Build the infrastructure that makes this permanent.
Every piece of the Sovereign Stack — self-hosted services, E2EE defaults, owned identity — shrinks the surface these laws can reach. Governments can revive zombie procedures. They cannot revive access to data that never existed on a scannable server. The identity migration playbook applies here too: pseudonymous, key-based identity is the countermeasure to compulsory age verification, and that fight is coming in September.
As Lyudmyla Kozlovska put it after the July vote: “The real fight for encryption and the privacy of communication is in September, over Chat Control 2.0. Between now and then, the resistance has to be strong enough that no procedural trick can carry it.”
What to Watch

- September 2026 — CSAR trilogue resumes. Watch for: does the encryption exclusion survive? Does age verification stay optional?
- Any “urgent procedure” or last-day-before-recess vote — that’s the signature of the back-door move. It worked once in July. Sunlight is the countermeasure.
- April 3, 2028 — the sunset on Regulation 2026/1881. Between now and then, expect at least one attempt to make the “temporary” scanning permanent by default.
- Your own stack — the only layer you fully control.
A law that passes without the consent of a voting majority is not a verdict on privacy. It’s a confession that its authors couldn’t win the argument on the merits. They needed an empty chamber. You don’t have to accept the frame that surveillance is inevitable — the text of their own law exempts encryption, excludes audio, mandates nothing, and expires. Build accordingly. Fight accordingly.
Stay free. Stay encrypted. Stay impossible to scan.
Primary Sources
- Regulation (EU) 2026/1881 — full text, Official Journal
- Council statement of reasons — the procedural paper trail
- euronews — “through the back door” vote analysis
- Patrick Breyer — Council adoption statement
- EFF Deeplinks — April win and what comes next
- Politico — Metsola vs. Parliament
Read next
How to Run GLM-5.2 Locally (2026): Ollama, VRAM, and the Honest Hardware Bill
5 min read·Published Aug 16, 2026NostrXFacebookRedditTelegramSMSCopyOn this page▾First, the Number That Decides EverythingPath 1: Ollama, One Command, Cloud-Backed (Start Here)Path 2: Actually…
The 2026 Sovereign Stack: Privacy Tools That Actually Resist Surveillance
8 layers of the sovereign stack verified live in 2026 — email, DNS, VPN, hosting, search, comms, money, AI. What to use,…
EU Chat Control 2026: The Deadline Every Builder Should Know
0 0 votes Article Rating Last updated: August 15, 2026 Part of Privacy + Digital Rights Hub Update (August 15, 2026): The…