Chat Control 1.0 and 2.0: What’s the Difference?

by David Briguglio Brown

When Council negotiations on the Child Sexual Abuse Regulation (CSAR), more commonly known as ChatControl, intensified in summer 2025, there was an uproar among the general populace in each country against the proposal, as the European Parliament had already done. And as public pressure mounted, the political landscape began to shift, as several Member States revised their positions in the Council. With Germany announcing its opposition in October 2025, negotiations on the proposal appeared to have fallen through. Then, in July 2026, headlines across Europe proclaimed that the European Parliament had passed Chat Control. For many, this came as a surprise. Hadn’t Parliament already rejected the proposal? Hadn’t negotiations collapsed months earlier?

The answer is not quite.

The answer lies in a distinction that many headlines overlooked: there are two different pieces of legislation commonly referred to as “Chat Control”: Chat Control 1.0, a temporary legal framework, and Chat Control 2.0, the permanent Child Sexual Abuse Regulation that remains under negotiation. Confounding the two obscures both what Parliament actually approved and the far more intrusive measure still waiting in the wings.

A Short Background

The story begins in 2021. When new EU privacy rules (the ePrivacy directive) came into force, many online communication providers lost the legal basis that allowed them to voluntarily detect and report Child Sexual Abuse Material (CSAM) within their services. To prevent this work from stopping overnight, the European Union adopted Regulation (EU) 2021/1232, commonly referred to as Chat Control 1.0.

Importantly, this was always intended to be a temporary derogation. It gave providers a legal basis to continue voluntary detection while the European Commission prepared a permanent legislative framework. That permanent framework arrived in May 2022 as the proposed Child Sexual Abuse Regulation (CSAR), better known as Chat Control 2.0. From that point onwards, the European Union has had two simultaneous Chat Control pieces of legislation: one temporary and one permanent. The two proposals have often been confused, despite serving different purposes and following separate legislative paths.

The Permanent Proposal

The Permanent CSAR proposal, or Chat Control 2.0, is intended to create a permanent EU framework for combating child sexual abuse online. This was first proposed in 2022 by Home Affairs Commissioner Ylva Johansson, via a regulation making the detection and reporting of child sexual abuse material a legal requirement for platforms, including a requirement to bypass end-to-end encryption.

This immediately became one of the most controversial digital rights proposals in EU history. In fact, the European Court of Human Rights ruled, in an unrelated case, that requiring degraded end-to-end encryption “cannot be regarded as necessary in a democratic society”. The European Parliament adopted a significantly more privacy-protective negotiating position, as the European Parliament’s Committee on Civil Liberties, Justice, and Home Affairs (LIBE) voted to remove indiscriminate chat control and allow for targeted surveillance, and MEPs voted in favour of the protection of encrypted communications.

The Parliament’s position was remarkably consistent: any scanning of private communications should only occur where there are reasonable grounds for suspicion, should require judicial authorisation, and should not apply to end-to-end encrypted communications. Here, it was argued that indiscriminate scanning of private communications risked violating the fundamental rights to privacy and confidential communications, and instead proposed targeted detection limited to individuals reasonably suspected of involvement in child sexual abuse.

The Council, meanwhile, pursued a different approach. The Danish Presidency in the second half of 2025 made passing this permanent regulation a priority, pushing hard for mandatory scanning of end-to-end encrypted communications (conveniently with exemptions for politicians). This is where the “Fight Chat Control” movement gained much of its prominence – as civil liberties and tech groups across Europe put great pressure on EU Member States to oppose the proposal.

In October 2025, Germany announced it would vote against mandatory suspicionless scanning. The Danish presidency was forced to drop mandatory detection orders and shifted to “voluntary” suspicionless detection and broad risk-mitigation duties, including mandatory age verification. In November, the Council approved the softened Danish compromise, opening trilogue negotiations between the Council, Parliament and Commission. But these would fall through. Despite progress on excluding mandatory age verification, the Council’s request to make suspicionless scanning permanent could not be agreed upon.

Hence, Chat Control 2.0 has not been adopted, and talks continue under the incoming Irish presidency.

The Temporary Framework

The lack of agreement on the permanent proposal created a problem, as there was no existing legislation to protect against CSAM online. To fill the void, the EU proposed a temporary derogation in 2021, known as Chat Control 1.0. This measure did not require providers to scan private communications. Instead, it gave providers a legal basis to voluntarily search messages for the presence of child pornography, enabling the scanning of private communications without prior judicial authorisation.

Although end-to-end encryption was not directly threatened under the new law, providers could deploy “client-side scanning”, software capable of analysing messages, images, videos, or files before they are encrypted and sent, hence undermining many of the privacy guarantees users expect from end-to-end encrypted services.

In 2026, the Council Legal Service would go on to state that the “voluntary” scanning proposal still constitutes generalised scanning of communications and is incompatible with Article 7 of the EU Charter (right to privacy) without reasonable suspicion and prior judicial authorisation. Furthermore, the European Commission’s 2025 evaluation concluded that there was insufficient evidence to fully assess whether the benefits of voluntary scanning were proportionate to its impact on privacy and fundamental rights. This remains one of the central criticisms surrounding the legislation.

The regulation was originally due to expire in 2024 before being extended until April 2026 due to a lack of progress on the permanent proposal. In March 2026, LIBE would surprisingly reject the extension of this framework to 2028. Parliament then voted for a compromise: extend to 2027, but only with targeted and proportionate detection of known content, no end-to-end encrypted communications, and limiting scanning to suspected users or groups identified by the competent judicial authority. Yet the Council refused to budge, and the extension talks collapsed. In response, Parliament rejected the extension together with the proposal of automated assessment of unknown photos and texts, with a one-vote majority.

However, despite the Parliament’s rejection being final, the Council (with no progress on the permanent regulation) proposes a formally new law with identical content via an expedited procedure. This was in part driven by the European People’s Party (EPP) and the President of the European Parliament, Roberta Metsola. It is this resurrection of the Chat Control 1.0 that was the subject of the 9th July vote. Although more MEPs voted in favour of rejecting the proposal, the motion failed because an absolute majority of 361 Members was required to block it. An amendment to restrict scanning to judiciary-identified suspects won 322 votes and missed the absolute majority as well, while an exemption for end-to-end encrypted services passed.

Chat Control 1.0 was adopted and set in force until 2028. Mass scanning will continue, even though a majority of the MEPs who voted wanted it stopped.

Where Do Things Stand Today?

Today, the European Union is simultaneously dealing with two separate legislative frameworks.

Chat Control 1.0 is once again in force as a temporary legal framework, allowing online providers to voluntarily detect and report child sexual abuse material while negotiations on a permanent solution continue. Unless replaced sooner, it will remain in force until 2028. Chat Control 2.0, the proposed permanent Child Sexual Abuse Regulation, remains under negotiation following repeated disagreements between the European Parliament and the Council over issues such as suspicionless scanning, judicial oversight, and end-to-end encryption. No final agreement has yet been reached.

Although they are often discussed interchangeably, the two proposals are fundamentally different. One is a temporary derogation designed to fill a legal gap, while the other seeks to establish a permanent framework for combating child sexual abuse online. Yet both continue to raise difficult questions about privacy, proportionality, judicial oversight, and the future of secure communications in Europe. There is no disagreement that child sexual abuse must be tackled. The real question is how. Europe has a responsibility to protect children, but it also has a responsibility to uphold the fundamental rights that define it as a democratic union.

As negotiations on Chat Control 2.0 continue, the European Union has an opportunity to demonstrate that security and liberty are not competing values. Any permanent solution should be targeted, evidence-based, subject to robust judicial oversight, and respectful of privacy and secure encryption. Europe should strive to show that protecting children and protecting fundamental rights are objectives that can, and must, go hand in hand.

References

‘Chat Control Overview’ (Fight Chat Control) <https://fightchatcontrol.eu/chat-control-overview> accessed 11 July 2026

Politico, ‘President vs Parliament: Roberta Metsola overrides MEPs’ bid to force child abuse law’ (Politico) <https://www.politico.eu/article/president-vs-parliament-roberta-metsola-overrides-meps-bid-force-child-abuse-law/> accessed 11 July 2026

European Digital Rights (EDRi), ‘A beginner’s guide to EU rules on scanning private communications – Part 2’ (EDRi) <https://edri.org/our-work/a-beginners-guide-to-eu-rules-on-scanning-private-communications-part-2/> accessed 11 July 2026

DW, ‘EU to step up fight against child abuse content’ (Deutsche Welle) <https://www.dw.com/en/eu-to-step-up-fight-against-child-abuse-content/a-60370678> accessed 11 July 2026

DW, ‘EU chat control law: Online sexual predators, children, privacy and Big Tech’ (Deutsche Welle) <https://www.dw.com/en/eu-chat-control-law-online-sexual-predators-children-privacy-facebook-google-big-tech-v2/a-74337044> accessed 11 July 2026

Euronews, ‘Chat Control 1.0 passed the European Parliament “through the back door”’ (Euronews, 10 July 2026) <https://www.euronews.com/next/2026/07/10/chat-control-10-passed-the-european-parliament-through-the-back-door> accessed 11 July 2026

GTG Advocates, ‘European Court of Human Rights holds against encryption backdoors’ (GTG Advocates) <https://gtg.com.mt/european-court-of-human-rights-holds-against-encryption-backdoors/> accessed 11 July 2026

European Commission, ‘Report from the Commission to the European Parliament and the Council on the application of Regulation (EU) 2021/1232’ COM (2025) 740 final <https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:52025DC0740> accessed 11 July 2026