
EU Chat Control: If Privacy Is Outlawed, only Outlaws Have Privacy

- Client-side scanning proposals shift private communication from targeted investigation to broad pre-emptive monitoring.
- The technical burden lands on everyone, while determined offenders can still adapt by changing channels or adding encryption layers.
- Once scanning infrastructure exists, expanding it to new policy categories becomes easier than reversing it.
I have spent my career looking for the ways a system breaks, and it is not a habit I can leave at work. Once you spend your days finding where things fail before anyone has to depend on them, you start doing it to everything — a new app, the card reader at the kiosk, Copenhagen’s driverless metro. So when the European Union put forward its “Chat Control” proposal, I turned the same habit on it without really meaning to. The closer I look, the more it worries me — not because of its goal, but because of what the tool would have to do to reach it.
We all want children to be safe. That instinct is right, and I share it. But the proposal would place scanning software on every phone in Europe, checking your private messages against a model before they are sent. That is not targeted investigation of a suspect; it is pre-emptive monitoring of everyone, where each of us is treated as worth checking until the software clears us. The stated aim is compassion, and the architecture is built on suspicion. It has to be tested: whether it is legitimate, effective, and safe at the scale of a continent, and on all three the answer is not yet convincingly yes.
How the Scanning Would Work
The idea is straightforward: “detect abuse material and grooming early”. The implementation, however, is anything but simple. Chat apps today use end-to-end encryption, which means that the phone of the sender encrypts the message, and only the recipient’s phone can decrypt it. While the message is in transit or stored on servers, no one else can read it, not even the internet provider or app developer. This is a powerful privacy guarantee that protects not only criminals but also journalists, activists, domestic-violence survivors, and ordinary people.
If chat apps are to continue to use end-to-end encryption, scanning must happen on the phone before encryption, i.e. just as the message is being sent. The proposal allows “detection orders” for known images (hash matching), “new/similar” images (perceptual matching), and grooming text. The model that decides what to flag will not be public. You will not see the rules. You will only encounter the system if a classifier is confident enough to escalate your case to the authorities.
Proposal for a Regulation of the European Parliament and of the Council laying down rules to prevent and combat child sexual abuse — The official text of the Chat Control proposal, COM(2022)209, setting out the detection orders and obligations discussed throughout this brief.
Once device-level scanning is normalised, the relationship between citizen and state shifts, and so does your attack surface.
Two Uncomfortable Facts
Most politicians are not experts in cryptography, cybersecurity or artificial intelligence. That is not a failing; it is not their job. It does mean they have to rely on those who are, and to act on what they hear even when the answer is unwelcome. Look at what this proposal would actually require, and two uncomfortable facts stand out.
First, circumvention is relatively easy. If scanning happens before encryption, determined offenders can encrypt a second time before the scanner ever sees the message, or move to hardened, self-hosted infrastructure. Nothing sophisticated is needed: the scanner reads what is on the screen on its way out, so anything the sender and recipient have already agreed to disguise between themselves passes straight through. The system will scan the easy targets, catch the careless, and miss those who are most intent on avoiding detection. This is a point noted by both regulators and the Internet Society. Second, the attack surface increases: mandated on-device classifiers, their update channels, indicator feeds and escalation paths become attractive targets for criminals and hostile states.
Infrastructure Outlives Its Purpose
Surveillance infrastructure, once established, tends to expand in scope. Once device-level scanning is normalised and implemented, adding new categories, such as terrorism, extremism, “disinformation”, tax or copyright, becomes a configuration change, not a new public debate. The technical capability is already present; only political will is required to broaden its use.
Many surveillance mechanisms introduced with narrow initial justification have expanded over time. RIPA in the UK, introduced for investigating serious crime, was later used by councils to monitor dog-fouling and school catchment fraud. The question to ask about any surveillance infrastructure is not only “what will it be used for today?” but “what could it be used for in ten years, under a different government, with different political priorities?”
Who the Scanning Would Actually Reach
Chat Control focuses on mainstream platforms like WhatsApp, Messenger, Signal and Telegram. Competent offenders are unlikely to remain on mainstream channels once on-device scanning is enabled; they will move to other platforms or add encryption layers. The result is that the lawful majority are scanned, while those intent on evading detection are likely to succeed.
This is not the most effective way to catch high-value offenders. Signal’s technical analysis also discussed the re-branding of Client-Side Scanning as “upload moderation” to downplay the surveillance aspect. They noted that this does not solve the core problem: if it happens before encryption, the end-to-end guarantee is broken. End-to-end encryption exists to guarantee that only the intended recipients can read the messages, and introducing scanning on the sender’s device compromises this guarantee.
If privacy is outlawed, only outlaws will have privacy.
Philip Zimmermann, the creator of PGP, wrote this decades ago, when the fight was over export controls on encryption software.
Client-Side Scanning: What It Is and Why It Threatens Trustworthy, Private Communication — Internet Society did an independent technical analysis concluding that circumvention is easy and that scanning primarily catches the careless while missing determined offenders.
New Branding, Same Scanning: “Upload Moderation” Undermines End-to-End Encryption — Signal’s response to the rebranding of client-side scanning as “upload moderation”, arguing the end-to-end guarantee is broken regardless of the terminology used.
A Small Error Rate, a Vast Population
Grant the premise of pre-emptive scanning for a moment, and the arithmetic is still unforgiving. A tiny error rate becomes an enormous number when applied across billions of messages and photos. Every time the system produces a false positive, someone at the police station must investigate, diverting resources from real cases. Each false report consumes investigator hours and can drag innocent families into processes they never deserved while real victims may wait longer for help.
At the same time, context is lost when a model sees only pixels, not relationships: pool photos, bath-time pictures to grandparents, dermatology images for a paediatric consult, screenshots from parenting forums. The artificial intelligence cannot understand who the people in these images are or who you are sending them to. Nor is there a point at which you get to explain: the first you hear of it is when someone else has already decided what the picture shows.
Who Gets Exempted
Then there is the question of who does not get scanned at all. A leaked version of the proposal included exemptions for certain professions and roles, citing professional secrecy as justification: ministers, commissioners, generals and party leaders may be excluded from scanning, but not doctors or journalists. The rationale is that some communications require confidentiality for the public good, but the argumentation is inconsistent. If professional secrecy is what earns an exemption, a doctor’s consultations and a journalist’s sources have a stronger claim to it than a party leader’s messages, and neither made the list.
Leak: EU interior ministers want to exempt themselves from chat control bulk scanning of private messages — Former MEP and prominent Chat Control opponent Patrick Breyer, reproducing the leaked Council negotiating text, in which interior ministers sought to exempt the professional accounts of intelligence, police and military staff, and others bound by professional secrecy, from the scanning that would still apply to ordinary citizens.
If the technology is truly safe and necessary, why should any group be exempt at all? Professional secrecy is important, but so too is the privacy of ordinary citizens, including families, support workers, and vulnerable individuals. Exemptions risk creating a two-tier system, where privacy is protected for some but not for others.
Encryption Is Load-Bearing
End-to-end encryption supports the security of banking, healthcare, domestic-violence shelters, journalism, elections and the private lives of ordinary people. Mandated server backdoors and client-side scanners both weaken this chain. It is not possible to have “strong” end-to-end encryption and device-level surveillance at the same time.
In 2021, Apple announced plans to scan iCloud Photos on-device for CSAM before upload. After significant pushback from security researchers, privacy advocates, and civil liberties organisations, Apple abandoned the plan, opting instead for narrower, opt-in child safety features.
Apple had full control over its hardware, operating system, and infrastructure and still could not make client-side scanning trustworthy enough to ship. The EU’s proposal would apply the same approach across hundreds of device manufacturers and operating systems.
What Actually Moves Outcomes
If the goal is fewer victims and more convictions, efforts should focus where harm and profit concentrate, rather than treating the entire population as suspects. Target distribution networks and repeat offenders, freeze hosting infrastructure and trace payments, improve reporting pipelines so investigators receive fewer, higher-quality tips with context, and run targeted, warrant-backed operations that stand up in court.
The Unanswered Questions
Before any of this becomes law, a few questions deserve clear answers in public. On legitimacy: what legal precedent justifies pre-emptive scanning of private correspondence at all? On effectiveness: what measured increase in arrests and convictions is expected from endpoint scanning over targeted warrants and infrastructure take-downs, and where are the peer-reviewed evaluations? On safety: what are the audited false-positive and false-negative rates per category of content at continental scale, and how will automated tips be kept from overwhelming frontline units? On security: what is the threat model for the mandated scanner itself, its update channels and indicator feeds, and how will hostile reuse of those hooks be prevented? None of these are rhetorical. If they cannot be answered cleanly, the mechanism is not ready.
Europe’s Choice
Europe does not have to choose between protecting children and protecting private correspondence. It can go after the places where abuse actually concentrates — distribution networks, hosting, payments — with warrants, resourced investigators, and operations that stand up in court. Or it can put a scanner on every phone, accept the false positives that will land on frontline officers, and widen the attack surface for everyone. The first path is harder and slower. The second is easier to pass and far harder to undo.
I keep coming back to the same test. If the mechanism were truly safe and accurate, it would be safe enough to apply to everyone, ministers included, without a single exemption. That the proposal reaches instead for exemptions is the clearest signal we have of how far its own authors trust it. The wish to keep children safe is real and shared. The harder question is the one those exemptions dodge: whether each of us would accept, with no exemption of our own, the tool we mean to place on everyone.
- Removed the paragraph citing individual cases of politicians in the exemption section; the argument does not depend on specific cases.
The views and perspectives expressed here are the author's own and do not represent any employer or affiliated organisation. The writing draws on public sources and the author's own experience, never on confidential information. Artificial intelligence is used on some posts to identify sources, draft structure, and assist with quality assurance; the final article is always the author's own work. The AI assists, but never authors.
Niclas Hedam
PhD, Computer Science
Niclas Hedam holds a PhD in Computer Science from the IT University of Copenhagen. He is passionate about educating others on the importance of safeguarding personal information online.

