{"id":853,"date":"2026-08-15T21:25:00","date_gmt":"2026-08-15T21:25:00","guid":{"rendered":"https:\/\/thethriftydev.com\/blog\/eu-chat-control-back-door\/"},"modified":"2026-08-15T23:25:29","modified_gmt":"2026-08-15T23:25:29","slug":"eu-chat-control-back-door","status":"publish","type":"post","link":"https:\/\/thethriftydev.com\/blog\/eu-chat-control-back-door\/","title":{"rendered":"Chat Control 1.0 Passed Through the Back Door (EU, 2026)"},"content":{"rendered":"<p>On July 9, 2026, 314 members of the European Parliament voted to kill mass chat scanning. That was more than the opposition \u2014 276 MEPs voted to keep it. The rejection won. And the law passed anyway.<\/p>\n<p>Here&#8217;s the sentence that should make every builder&#8217;s blood run cold, then boil: <strong>a majority of voting MEPs rejected Chat Control 1.0 \u2014 the EU&#8217;s mass chat-scanning law \u2014 and it became law regardless.<\/strong> Not because of a conspiracy \u2014 because of a procedural mechanism most people have never heard of, run at a time of year designed to make resistance mathematically impossible.<\/p>\n<p>This is the story of how a dead EU surveillance law came back through the back door \u2014 the sequel to <a href=\"https:\/\/thethriftydev.com\/blog\/eu-chat-control-2026-deadline-builders\/\">our December 2026 deadline warning<\/a>, what the revived law actually says (less than the headlines suggest), and \u2014 most importantly \u2014 exactly where the fight goes from here. Because the fight is <em>not<\/em> over. It has a date: September 2026.<\/p>\n<h2>The 90-Second Timeline<\/h2>\n<figure class=\"ttd-section-figure\"><img decoding=\"async\" src=\"https:\/\/thethriftydev.com\/blog\/wp-content\/uploads\/2026\/08\/01-timeline.png\" alt=\"Timeline of the back-door revival of Chat Control 1.0: March rejection, April expiry, June Council maneuver, July adoption\" width=\"1600\" height=\"900\" loading=\"lazy\" \/><figcaption>The path from rejection to law: every date verifiable in the Official Journal.<\/figcaption><\/figure>\n<p>Six facts, all verifiable in the Official Journal:<\/p>\n<ul>\n<li><strong>March 11, 2026<\/strong> \u2014 Parliament approved a trilogue mandate that would have <em>limited<\/em> the scanning scope.<\/li>\n<li><strong>March 26, 2026<\/strong> \u2014 Parliament rejected the extension outright: <strong>311 to 228, with 92 abstentions<\/strong>. A clear win. The interim derogation expired <strong>April 3<\/strong>.<\/li>\n<li><strong>June 18<\/strong> \u2014 EP President Roberta Metsola publicly invited the Council to reopen the file \u2014 asking member states to approve a bill her own Parliament had voted down. Politico called the move &#8220;without precedent.&#8221;<\/li>\n<li><strong>July 2<\/strong> \u2014 The Council adopted its first-reading position under Article 294(5) TFEU. Since an expired act can&#8217;t legally be &#8220;extended,&#8221; they simply re-enacted the entire text as a brand-new regulation.<\/li>\n<li><strong>July 9<\/strong> \u2014 Second reading in Parliament, on the last sitting day before summer recess. 314 MEPs voted to reject. Rejection required an <em>absolute majority<\/em> \u2014 360 by euronews&#8217; count, 361 by Breyer&#8217;s. The vote fell short. Under the procedure, the law was then <em>automatically deemed adopted<\/em>.<\/li>\n<li><strong>July 23\u201324<\/strong> \u2014 The Council formally adopted the revived regulation: Hungary against, Belgium abstaining, everyone else silent. It published July 28 as <a href=\"https:\/\/eur-lex.europa.eu\/legal-content\/EN\/TXT\/HTML\/?uri=CELEX:32026R1881\" rel=\"nofollow noopener\" target=\"_blank\">Regulation (EU) 2026\/1881<\/a>, entered into force July 31, and applies until <strong>April 3, 2028<\/strong>.<\/li>\n<\/ul>\n<p>One more number: a majority of voting MEPs <em>did<\/em> vote to restrict scanning to judiciary-identified suspects \u2014 322 to 255. That amendment passed. And it died anyway, because at second reading, amendments also need an absolute majority. Rapporteur Damian Sippel called the whole maneuver &#8220;unfair.&#8221; He was being polite.<\/p>\n<h2>The Back Door, Explained Like You&#8217;re a Builder<\/h2>\n<figure class=\"ttd-section-figure\"><img decoding=\"async\" src=\"https:\/\/thethriftydev.com\/blog\/wp-content\/uploads\/2026\/08\/02-procedure.png\" alt=\"Article 294(5) TFEU absolute-majority trap: Parliament voted to reject but could not reach the 361-vote threshold\" width=\"1600\" height=\"900\" loading=\"lazy\" \/><figcaption>The exploit: silence is consent at second reading.<\/figcaption><\/figure>\n<p>Think of it as a race condition exploited against a democratic system:<\/p>\n<p>The ordinary legislative procedure assumes both institutions negotiate on roughly equal footing. But Article 294(5) TFEU has a failure mode: if Parliament can&#8217;t muster an <em>absolute majority<\/em> (of all MEPs, not just those present) to reject or amend the Council&#8217;s position at second reading, the Council&#8217;s text passes <strong>automatically<\/strong>. No majority needed. Silence is consent.<\/p>\n<p>Now schedule that second-reading vote for the final sitting day before the summer recess \u2014 when, as former MEP Patrick Breyer put it, &#8220;significantly fewer MEPs are present on this day&#8221; \u2014 and bypass the normal committee scrutiny with an urgent procedure approved July 7. The result: a law that a plurality of present-and-voting MEPs opposed becomes binding on 450 million people.<\/p>\n<p>You don&#8217;t need to believe in conspiracies. You just need to read the procedure. It&#8217;s a privileged escalation path, and they used it.<\/p>\n<h2>What the Law Actually Says: Regulation (EU) 2026\/1881 Explained<\/h2>\n<figure class=\"ttd-section-figure\"><img decoding=\"async\" src=\"https:\/\/thethriftydev.com\/blog\/wp-content\/uploads\/2026\/08\/03-scope.png\" alt=\"Covered services versus Article 1(3) exclusions in Regulation EU 2026\/1881\" width=\"1600\" height=\"900\" loading=\"lazy\" \/><figcaption>Covered vs excluded: read the operative text, not the headlines.<\/figcaption><\/figure>\n<p>Here&#8217;s where it gets less scary than the headlines \u2014 and the headlines were pretty scary. I pulled the full text of Regulation (EU) 2026\/1881. Three things matter:<\/p>\n<p><strong>1. It&#8217;s still voluntary.<\/strong> The regulation &#8220;enabl[es] providers&#8230; to use specific technologies&#8221; for detection. That&#8217;s permission, not obligation. No provider anywhere is <em>mandated<\/em> to scan anything. That&#8217;s why Breyer notes European messaging and email providers &#8220;have never implemented chat control measures anyway.&#8221; The refusal lever is real, and it&#8217;s in the text.<\/p>\n<p><strong>2. End-to-end encryption is excluded \u2014 in the actual operative text.<\/strong> Not a press-release promise. Article 1(3): <em>&#8220;This Regulation does not apply to interpersonal communications to which end-to-end encryption is, has been or will be applied.&#8221;<\/em> Audio communications are excluded too. Recital 32 adds that nothing in the regulation &#8220;should&#8230; be interpreted as prohibiting or weakening end-to-end encryption.&#8221; Euronews calls the wording &#8220;cosmetic&#8221; \u2014 providers weren&#8217;t scanning E2EE content anyway \u2014 but cosmetic or not, it&#8217;s statutory.<\/p>\n<p><strong>3. No client-side scanning. Anywhere.<\/strong> The phrase &#8220;client-side&#8221; appears zero times in the regulation. Client-side scanning \u2014 spyware on your device \u2014 remains Chat Control 2.0 territory, and there it&#8217;s currently losing.<\/p>\n<p>What IS covered: the non-E2EE direct-message layers of platforms like Instagram, Discord, Snapchat, Skype, Xbox, plus email services like Gmail and iCloud. Voluntarily. Until April 2028.<\/p>\n<p>And here&#8217;s the accountability angle that should actually enrage you: when the derogation lapsed April 3, Google, Meta, Microsoft, and Snap <a href=\"https:\/\/www.eff.org\/deeplinks\/2026\/04\/eu-parliament-blocks-mass-scanning-our-chats-whats-next\" rel=\"nofollow noopener\" target=\"_blank\">signaled in a joint statement<\/a> they&#8217;d &#8220;continue to take voluntary action&#8221; \u2014 scanning that EFF and netzpolitik point out has been operating without legal basis since the April expiry. The back-door law didn&#8217;t start the scanning. It laundered it.<\/p>\n<h2>The Real Fight Is September: Chat Control 2.0<\/h2>\n<figure class=\"ttd-section-figure\"><img decoding=\"async\" src=\"https:\/\/thethriftydev.com\/blog\/wp-content\/uploads\/2026\/08\/04-csar2.png\" alt=\"CSAR trilogue open disputes: encryption exclusion, age verification compulsory versus optional, detection order design\" width=\"1600\" height=\"900\" loading=\"lazy\" \/><figcaption>The September front: encryption is provisionally safe, age verification is the dispute.<\/figcaption><\/figure>\n<p>Chat Control 1.0 is the temporary zombie. Chat Control 2.0 \u2014 the permanent CSAR regulation \u2014 is the actual war, and it&#8217;s in trilogue right now.<\/p>\n<ul>\n<li>Forced scanning of <strong>encrypted<\/strong> messages: member states <strong>gave it up<\/strong>, and per a leaked June 22 Council state-of-play, the provisional position now states the regulation does not &#8220;prohibit, make impossible, weaken, circumvent or otherwise undermine&#8221; encryption or create &#8220;any obligations for providers to decrypt.&#8221;<\/li>\n<li><strong>Age verification is the new front line<\/strong>: the Council wants it compulsory for messaging services &#8220;that present a risk of solicitation&#8221;; Parliament wants it optional. This is exactly the identity-creep pattern we&#8217;ve been <a href=\"https:\/\/thethriftydev.com\/blog\/age-verification-creep-tracker\/\">tracking state-by-state in the US<\/a> arriving at EU scale.<\/li>\n<li>The fourth trilogue was May 11. Euronews reported in mid-July that negotiators &#8220;may be close to reaching a deal.&#8221; Talks resume in September.<\/li>\n<\/ul>\n<p>EFF framed it precisely: &#8220;This is a zombie proposal. It keeps coming back and must not be allowed to return through the back door.&#8221; It just did \u2014 once. The second attempt is scheduled.<\/p>\n<h2>The Resistance Stack: What You Actually Do Now<\/h2>\n<figure class=\"ttd-section-figure\"><img decoding=\"async\" src=\"https:\/\/thethriftydev.com\/blog\/wp-content\/uploads\/2026\/08\/05-resistance.png\" alt=\"Five lawful resistance layers: E2EE defaults, self-hosted messaging, provider refusal, September campaign, sovereign stack\" width=\"1600\" height=\"900\" loading=\"lazy\" \/><figcaption>Five layers, all lawful, all buildable today.<\/figcaption><\/figure>\n<p>Here&#8217;s the part most coverage gets wrong. This is not a &#8220;lie back and think of the children&#8221; moment. It&#8217;s a build-and-fight moment, and the law itself concedes the ground:<\/p>\n<h3>1. Move your sensitive comms to E2EE. It&#8217;s now legally carved out.<\/h3>\n<p>Signal, WhatsApp, any E2EE service: the operative text of the law does not apply to them. This isn&#8217;t a workaround; it&#8217;s Article 1(3). Your threat model for DMs should already have assumed the platform can read them \u2014 Instagram and Discord DMs were scannable before this law, during it, and after it. The fix is the same as it&#8217;s always been: E2EE for anything that matters.<\/p>\n<h3>2. Self-host your messaging. The scope definitions work in your favor.<\/h3>\n<p>The regulation only covers &#8220;number-independent interpersonal communications services&#8221; as defined in the EECC \u2014 and that definition applies to services &#8220;normally provided for remuneration.&#8221; Your personal Matrix or XMPP server, run for yourself and friends, is a different animal from a commercial provider. And since scanning under 2026\/1881 is voluntary <em>even for covered providers<\/em>, a self-hosted server you control has no scanning path at all. That&#8217;s not a loophole \u2014 that&#8217;s architecture. (Full disclosure: no first-party EU statement names self-hosted servers explicitly; this is legal analysis from the statutory text, and I&#8217;d bet the farm on the text.)<\/p>\n<h3>3. Refuse, loudly, if you run a covered service.<\/h3>\n<p>European providers never implemented chat control \u2014 which is living proof that &#8220;voluntary&#8221; means optional. If you run a messaging or email service in the EU: you are not required to scan. Choosing not to is a lawful, precedented act of resistance. Say so publicly. Every European provider that refuses makes the &#8220;voluntary&#8221; fiction harder to maintain.<\/p>\n<h3>4. Make September loud.<\/h3>\n<p>The permanent law is negotiated by people who answer to voters. <a href=\"https:\/\/fightchatcontrol.eu\/\" rel=\"nofollow noopener\" target=\"_blank\">Fight Chat Control<\/a> and <a href=\"https:\/\/edri.org\/our-work\/chat-control-what-is-actually-going-on\/\" rel=\"nofollow noopener\" target=\"_blank\">EDRi&#8217;s action page<\/a> are running exactly that campaign. The specific asks worth backing come from Breyer&#8217;s alternative framework: mandatory detection orders targeting <em>suspects<\/em> instead of indiscriminate scanning, an EU center for removing known abuse material from the open web, and Security-by-Design requirements for messaging apps. That&#8217;s a child-safety policy that doesn&#8217;t require surveilling everyone. It exists. It&#8217;s on the table. It needs votes.<\/p>\n<h3>5. Build the infrastructure that makes this permanent.<\/h3>\n<p>Every piece of the <a href=\"https:\/\/thethriftydev.com\/blog\/sovereign-stack-2026\/\">Sovereign Stack<\/a> \u2014 self-hosted services, E2EE defaults, owned identity \u2014 shrinks the surface these laws can reach. Governments can revive zombie procedures. They cannot revive access to data that never existed on a scannable server. The <a href=\"https:\/\/thethriftydev.com\/blog\/mandatory-id-social-media-phone-kyc-nostr\/\">identity migration playbook<\/a> applies here too: pseudonymous, key-based identity is the countermeasure to compulsory age verification, and that fight is coming in September.<\/p>\n<p>As Lyudmyla Kozlovska put it after the July vote: &#8220;The real fight for encryption and the privacy of communication is in September, over Chat Control 2.0. Between now and then, the resistance has to be strong enough that no procedural trick can carry it.&#8221;<\/p>\n<h2>What to Watch<\/h2>\n<figure class=\"ttd-section-figure\"><img decoding=\"async\" src=\"https:\/\/thethriftydev.com\/blog\/wp-content\/uploads\/2026\/08\/06-watch.png\" alt=\"Radar: September trilogue, urgent-procedure votes as the procedural tell, April 3 2028 sunset\" width=\"1600\" height=\"900\" loading=\"lazy\" \/><figcaption>Four things to watch \u2014 and the only layer you fully control.<\/figcaption><\/figure>\n<ul>\n<li><strong>September 2026<\/strong> \u2014 CSAR trilogue resumes. Watch for: does the encryption exclusion survive? Does age verification stay optional?<\/li>\n<li><strong>Any &#8220;urgent procedure&#8221; or last-day-before-recess vote<\/strong> \u2014 that&#8217;s the signature of the back-door move. It worked once in July. Sunlight is the countermeasure.<\/li>\n<li><strong>April 3, 2028<\/strong> \u2014 the sunset on Regulation 2026\/1881. Between now and then, expect at least one attempt to make the &#8220;temporary&#8221; scanning permanent by default.<\/li>\n<li><strong>Your own stack<\/strong> \u2014 the only layer you fully control.<\/li>\n<\/ul>\n<p>A law that passes without the consent of a voting majority is not a verdict on privacy. It&#8217;s a confession that its authors couldn&#8217;t win the argument on the merits. They needed an empty chamber. You don&#8217;t have to accept the frame that surveillance is inevitable \u2014 the text of their own law exempts encryption, excludes audio, mandates nothing, and expires. Build accordingly. Fight accordingly.<\/p>\n<p>Stay free. Stay encrypted. Stay impossible to scan.<\/p>\n<h3>Primary Sources<\/h3>\n<ul>\n<li><a href=\"https:\/\/eur-lex.europa.eu\/legal-content\/EN\/TXT\/HTML\/?uri=CELEX:32026R1881\" rel=\"nofollow noopener\" target=\"_blank\">Regulation (EU) 2026\/1881<\/a> \u2014 full text, Official Journal<\/li>\n<li><a href=\"https:\/\/eur-lex.europa.eu\/legal-content\/EN\/TXT\/HTML\/?uri=CELEX:52026AG0009(02)\" rel=\"nofollow noopener\" target=\"_blank\">Council statement of reasons<\/a> \u2014 the procedural paper trail<\/li>\n<li><a href=\"https:\/\/www.euronews.com\/next\/2026\/07\/10\/chat-control-10-passed-the-european-parliament-through-the-back-door\" rel=\"nofollow noopener\" target=\"_blank\">euronews<\/a> \u2014 &#8220;through the back door&#8221; vote analysis<\/li>\n<li><a href=\"https:\/\/www.patrick-breyer.de\/en\/eu-governments-adopt-return-of-chat-control-1-0-breyer-the-true-losers-are-our-children\/\" rel=\"nofollow noopener\" target=\"_blank\">Patrick Breyer<\/a> \u2014 Council adoption statement<\/li>\n<li><a href=\"https:\/\/www.eff.org\/deeplinks\/2026\/04\/eu-parliament-blocks-mass-scanning-our-chats-whats-next\" rel=\"nofollow noopener\" target=\"_blank\">EFF Deeplinks<\/a> \u2014 April win and what comes next<\/li>\n<li><a href=\"https:\/\/www.politico.eu\/article\/president-vs-parliament-roberta-metsola-overrides-meps-bid-force-child-abuse-law\/\" rel=\"nofollow noopener\" target=\"_blank\">Politico<\/a> \u2014 Metsola vs. Parliament<\/li>\n<\/ul>\n<p><script type=\"application\/ld+json\">\n{\n \"@context\": \"https:\/\/schema.org\",\n \"@type\": \"FAQPage\",\n \"mainEntity\": [\n  {\n   \"@type\": \"Question\",\n   \"name\": \"What is Chat Control 1.0?\",\n   \"acceptedAnswer\": {\n    \"@type\": \"Answer\",\n    \"text\": \"Chat Control 1.0 is the revived interim EU regulation (Regulation (EU) 2026\/1881) that permits providers of messaging and email services to voluntarily scan private communications for child sexual abuse material. It entered into force July 31, 2026 and applies until April 3, 2028. No provider is mandated to scan.\"\n   }\n  },\n  {\n   \"@type\": \"Question\",\n   \"name\": \"Does EU Chat Control scan encrypted messages like WhatsApp or Signal?\",\n   \"acceptedAnswer\": {\n    \"@type\": \"Answer\",\n    \"text\": \"No. Article 1(3) of Regulation (EU) 2026\/1881 states the regulation does not apply to communications to which end-to-end encryption is, has been, or will be applied. Audio communications are also excluded.\"\n   }\n  },\n  {\n   \"@type\": \"Question\",\n   \"name\": \"When does the revived EU chat control law expire?\",\n   \"acceptedAnswer\": {\n    \"@type\": \"Answer\",\n    \"text\": \"Regulation (EU) 2026\/1881 applies until April 3, 2028. It entered into force on July 31, 2026, three days after its July 28, 2026 publication in the Official Journal.\"\n   }\n  },\n  {\n   \"@type\": \"Question\",\n   \"name\": \"Does the EU law require client-side scanning?\",\n   \"acceptedAnswer\": {\n    \"@type\": \"Answer\",\n    \"text\": \"No. The phrase client-side scanning appears zero times in the regulation. Client-side scanning remains part of the separate, permanent CSAR proposal (Chat Control 2.0), where EU institutions have provisionally agreed to exclude encrypted content from scope.\"\n   }\n  },\n  {\n   \"@type\": \"Question\",\n   \"name\": \"What is Chat Control 2.0 and when do negotiations resume?\",\n   \"acceptedAnswer\": {\n    \"@type\": \"Answer\",\n    \"text\": \"Chat Control 2.0 is the permanent CSAR regulation, in trilogue since December 2025. The key open disputes are whether age verification is compulsory or optional for messaging services, and detection-order design. Negotiations resume in September 2026.\"\n   }\n  }\n ]\n}\n<\/script><\/p>\n<p>Views: 4<\/p>","protected":false},"excerpt":{"rendered":"<p>On July 9, 2026, 314 members of the European Parliament voted to kill mass chat scanning. That was more than the opposition \u2014 276 MEPs voted to keep it. The rejection won. And the law passed anyway. Here&#8217;s the sentence that should make every builder&#8217;s blood run cold, then boil: a majority of voting MEPs&hellip; <a class=\"more-link\" href=\"https:\/\/thethriftydev.com\/blog\/eu-chat-control-back-door\/\">Continue reading <span class=\"screen-reader-text\">Chat Control 1.0 Passed Through the Back Door (EU, 2026)<\/span><\/a><\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[38,34,93],"tags":[82,116,113,111,117],"class_list":["post-853","post","type-post","status-publish","format-standard","hentry","category-digital-rights","category-privacy","category-sovereign-builder","tag-age-verification","tag-csar","tag-eu-chat-control","tag-sovereign-builder","tag-surveillance","entry"],"_links":{"self":[{"href":"https:\/\/thethriftydev.com\/blog\/wp-json\/wp\/v2\/posts\/853","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/thethriftydev.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/thethriftydev.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/thethriftydev.com\/blog\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/thethriftydev.com\/blog\/wp-json\/wp\/v2\/comments?post=853"}],"version-history":[{"count":2,"href":"https:\/\/thethriftydev.com\/blog\/wp-json\/wp\/v2\/posts\/853\/revisions"}],"predecessor-version":[{"id":862,"href":"https:\/\/thethriftydev.com\/blog\/wp-json\/wp\/v2\/posts\/853\/revisions\/862"}],"wp:attachment":[{"href":"https:\/\/thethriftydev.com\/blog\/wp-json\/wp\/v2\/media?parent=853"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/thethriftydev.com\/blog\/wp-json\/wp\/v2\/categories?post=853"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/thethriftydev.com\/blog\/wp-json\/wp\/v2\/tags?post=853"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}