The European Parliament voted in early July 2026 to extend controversial legislation allowing technology companies to scan online communications for child sexual abuse material, under different voting rules that made approval easier following a political move by the European People's Party. The legislation, dubbed chat control by critics due to privacy implications particularly on end-to-end encrypted communications, extends a temporary derogation from the ePrivacy Directive that was due to expire on 3 April 2026. The extension is intended to provide a bridge while negotiators continue work on a permanent legal framework that has been deadlocked over whether scanning requirements can apply to encrypted messaging.
Temporary derogations that expire and require repeated extensions signal the structural challenge of requiring blanket platform-level scanning as a regulatory solution. Detection deployed at the level of individual user accounts—monitoring a specific child's direct messages in real time with parental or institutional consent—addresses the underlying harm without imposing the privacy trade-offs that have deadlocked the permanent European framework. Where mandatory scanning of encrypted communications for all users raises fundamental rights questions that prevent legislative consensus, targeted monitoring authorised by a parent or school closes the protection gap for the child at risk, enabling grooming, sextortion and child sexual abuse material to be intercepted and escalated to the correct authority without requiring platforms to undermine encryption for their entire user base.