In July 2026 the European Union reinstated a temporary measure allowing online communication providers to detect, report and remove CSAM in private messages. It is a derogation, which means it permits providers to scan voluntarily. It does not require anyone to scan. It excludes interpersonal communications protected by end-to-end encryption from its scope. It runs until 3 April 2028.
Two details are commonly misreported. The first is that the measure survived a challenge. It did not. Parliament declined to prolong the previous derogation in March. It expired on 3 April 2026. The Council adopted a position reinstating it on 2 July.
The second concerns what Parliament voted on. At second reading it does not vote to approve a text. It votes on whether to reject or amend the Council’s position. Either requires an absolute majority of its component members. Two rejection motions were tabled. The first drew 314 votes in favour, 276 against and 17 abstentions. A second, taken after the amendments, drew 276 in favour, 286 against and 30 abstentions. Neither reached the majority required. Parliament did not reject the Council’s position. It adopted amendments instead. The Council accepted those on 23 July.
Both instruments are often called Chat Control, which is campaign shorthand rather than a legal term. It covers this temporary derogation and the permanent CSA Regulation still under negotiation, which are different instruments carrying different obligations.
So the measure in force today is voluntary, time-limited and excludes encrypted communication. The Council also removed mandatory detection obligations from its negotiating mandate on the permanent regulation in November 2025.
This article is therefore not about a rule that now exists. It is about an architecture that has been proposed, designed and shelved, and that is currently mandated nowhere in the Union. Apple built a version in 2021 and withdrew it. The Commission’s 2022 proposal required detection inside encrypted services without naming a method.
We take no position on whether such a system should be built. That argument belongs to people whose job it is. Our question is narrower. If detection and reporting run on every handset, what changes for someone who is already being targeted by name?
What the mechanism would be
Client-side scanning describes a family of proposed architectures. Rather than inspecting content on a server after it arrives, the device inspects content before it is encrypted and sent, or after it is received and decrypted. If the device finds a match against targeting material, it flags that finding.
Most proposals use one of two detection families. Perceptual hashing produces a short fingerprint for an image that survives resizing and re-encoding, and compares it against fingerprints of known material. Machine-learning classifiers are trained on examples and can flag content the system has never seen. Both need access to unencrypted content. Both produce false positives at some rate.
Beyond that, designs diverge. The differences are not details. What gets scanned varies. Where the targeting material comes from varies. Apple’s 2021 proposal required a match against lists supplied by child-safety organisations in two separate jurisdictions, set a threshold of thirty matches before anything surfaced, ran a second check server-side and put a human reviewer in the path before any report. Other proposals specify none of that.
A detection event is therefore not the same thing as a report to law enforcement. Nor does it establish possession or intent, which is why human review sits in the serious designs at all.
One of the most comprehensive technical assessments is “Bugs in our pockets: the risks of client-side scanning”, published in the Journal of Cybersecurity in 2024. Its fourteen authors include Ross Anderson, Whitfield Diffie, Ronald Rivest, Bruce Schneier, Susan Landau and Carmela Troncoso. It is open access, and the reference point for what follows.
Its central structural claim: moving detection from the server to the device moves it across the boundary between what a person shares and what a person keeps. Server-side scanning reaches content that was uploaded. Device-side scanning can reach content that was never sent to anyone.
There is also a reason the technique keeps returning. It explains why the encryption exclusion is the provision that matters. Content can only be inspected where the plaintext exists. In an end-to-end encrypted system that means an endpoint. The paper’s authors put this plainly about the 2022 proposal. Its requirements could not be met without either client-side scanning or changing the encryption model. It was silent on which.
So the exclusion currently keeps encrypted messaging outside the scanning regime. It does not resolve the question. It postpones it.
The attack surface moves onto the device
Cybersecurity calls the set of points where a system can be attacked its attack surface. Criminologists arrived at the same model decades earlier under a different name. We have written separately about the fifty years of research showing exposure is the operative variable.
Client-side scanning enlarges that surface. Detection code on the device is code an adversary can study. The device must receive scanning logic, or take part in a matching protocol that depends on targeting material supplied from outside. Either way a delivery channel exists and can be interfered with. An escalation path has to exist, which is itself a path to abuse. Attacks previously possible only against a provider’s servers become possible against a far larger and less defensible population of consumer handsets.
The paper groups the resulting threats into three classes. Authorised parties who expand the targeting material beyond its stated purpose. Unauthorised parties, meaning corrupt insiders, foreign services or criminals who compromise part of the chain. And local adversaries, by which the authors mean a partner, an ex-partner or a family member.
That third class is where this stops being an abstract policy question.
The framing attack
One passage matters for anyone responsible for a person at elevated risk.
The authors observe that an adversary can send a target content which appears innocuous but which will trigger detection. They note this is not hypothetical. Journalists have already been harassed by people who send them CSAM and then report them to the authorities. Their conclusion is careful. The hedge is theirs. Automated reporting might provide a means to scale up such attacks.
An attack of that shape has to pass four gates. Naming them makes the claim testable rather than rhetorical.
The adversary needs a route to the target, which means a phone number, an email address or a messaging handle. The material has to land somewhere the scanner actually looks. It has to produce a match. And the match has to survive whatever threshold, second check or human review the design puts in its way.
Every gate after the first is set by the architecture, long before anyone is targeted. In a design with a high match threshold and human review, a framing attempt is unlikely to clear the fourth. In a design without them, what previously required a person to compile a complaint and persuade an authority to act becomes a by-product of sending a message.
One finding compounds the risk at the third gate. The detection methods can be induced to produce false positives. Research cited in the paper shows innocuous content can be constructed to collide with a target fingerprint, and that classifiers can be induced to misclassify. We are deliberately not describing how. The property exists and is documented in peer-reviewed work.
The second gate is weaker than it looks. Delivery may not require deliberate cooperation, where unsolicited media is stored automatically or the device is compromised. The paper notes some messaging applications save received images to the device photo library by default.
That leaves the first gate, which is the one we work on every week. It is also the one routinely for sale. We have written on the several different kinds of database that put a working number or address in a stranger’s hands. None of them require the target to have done anything careless.
The first gate is the only one a person controls. Where someone already attracts adversarial attention, what a stranger can reach is the thing to measure first.
Protect a targeted personWho would actually be exposed
The architectural risk here is population-wide. What is concentrated is the incentive to frame a particular person. That sits with people who already attract adversarial attention: executives in contested transactions, journalists, people in litigation, public officials and individuals with a determined private antagonist.
That overlaps with the target set doxxing campaigns work from. Doxxing supplies the identity and contact routes a framing attempt uses at the first gate.
This inverts the usual pattern. We have argued before that in most incidents nobody selects the victim and exposure does the selecting. A framing attack is different. It is deliberate, aimed at one named person, by an attacker willing to spend something to reach them.
The local-adversary class is where our own advice helps least. The paper’s authors raise someone planning to leave a controlling partner, and observe that standard security guidance performs badly when the adversary knows the answers to the security questions. That line between attention and surveillance has a working test. We have set out the Fixated, Obsessive, Unwanted and Repeated rubric that investigators and courts use to draw it. Exposure reduction is weakest exactly here, where the adversary already holds physical, account or trusted-channel access.
An argument that outlasts the legislation
One point in the paper holds regardless of what any legislature decides.
Democratic systems have protected people by prohibiting some surveillance and by making the rest expensive. The authors cite the average cost of a United States wiretap in 2020 at roughly $119,000. A court-authorised wiretap is not the same thing as provider scanning. The comparison is inexact but the narrower point holds. Cost and procedure constrain how widely a capability gets used. Anything that makes search cheap removes that constraint without repealing anything.
This is the same logic exposure reduction runs on, pointed the other way. We reduce a person’s reachable footprint because it raises what an adversary has to spend to assemble a usable picture.
What exposure reduction does and does not do
Reducing what is reachable closes routes at the first gate. Fewer places hold a current phone number, email address or messaging handle. Fewer strangers can then reach the target at all. Separating public identifiers from private ones means an old breach record or a broker listing does not yield a live channel. Knowing what is published is the precondition for any of it, because a surface you have not measured is one you cannot reduce.
What it does not touch needs stating just as plainly. It does nothing about a compromised update mechanism, manipulated targeting material, or anyone with authorised access to the detection chain. It does nothing about malware that places material on a device. It does nothing about an adversary with physical or household access, or delivery through a channel the target already trusts.
Those are architectural risks. They are decided by how a system is built and governed, not by how careful an individual is. No exposure practice changes them.
Reachability reduction is therefore a real but partial control against the attack described here, closing one gate of four. It is also the control that works against the doxxing campaign, the pretext call and the opportunistic case. It keeps working whichever way the legislation settles.
What we are not saying
We do not predict what the permanent regulation will contain. As of this writing the Council’s mandate does not include mandatory detection obligations. The measure in force is voluntary and excludes encrypted communication.
We do not reach an independent proportionality conclusion. The European Data Protection Board and the European Data Protection Supervisor did, in a joint opinion on the Commission’s 2022 proposal rather than on the measure reinstated this July, finding that detection of previously unknown material and of grooming goes beyond what is necessary and proportionate. We point to it rather than restate it. Where the question is what the law permits, we have set out separately how European, United Kingdom and United States law currently treat the publication of personal data.
We also claim no novelty for the observation that a stated purpose and a delivered effect can diverge. We looked at that directly in the case of Europe’s facial recognition rules, where the strictest text in any major jurisdiction sits alongside enforcement that has not matched it.
What we are saying is narrow. A device-side detection system that can escalate matches off-device creates a reporting path on every device that runs it. A reporting path can be aimed. The people most exposed to that are those already targeted. They are reachable through exactly the identifiers exposure work exists to reduce.
That conclusion does not depend on any vote. It follows from the design, which is why it should be settled before the design is chosen rather than after.
Sources
- Abelson, H., Anderson, R., Bellovin, S. M., Benaloh, J., Blaze, M., Callas, J., Diffie, W., Landau, S., Neumann, P. G., Rivest, R. L., Schiller, J. I., Schneier, B., Teague, V., Troncoso, C. “Bugs in our pockets: the risks of client-side scanning.” Journal of Cybersecurity, Volume 10, Issue 1, 2024. Open access. doi:10.1093/cybsec/tyad020.
- Jain, S., Creţu, A.-M., de Montjoye, Y.-A. “Adversarial Detection Avoidance Attacks.” 31st USENIX Security Symposium, 2022. On evading perceptual hashing in client-side scanning. USENIX.
- European Parliament. Minutes and results of roll-call votes, sitting of 9 July 2026, item 9.4. Document C10-0178/2026, procedure 2025/0429(COD). europarl.europa.eu.
- Council of the European Union. Press release on the reinstatement of the interim CSA measure, 23 July 2026. consilium.europa.eu.
- Council of the European Union. Negotiating mandate on the CSA Regulation, November 2025.
- European Data Protection Board and European Data Protection Supervisor. Joint Opinion 04/2022 on the Commission’s 2022 CSA Regulation proposal. edpb.europa.eu.
- Administrative Office of the United States Courts. “Wiretap Report 2020”, Table 5. uscourts.gov.