KontorBund
The Library

Chat Control (CSAM Regulation): where the file stands after the 29 September 2026 trilogue

Last checked4 October 2026
KeeperOpen — keeper wanted
StatusProposal — not law

The short version

The CSA Regulation — universally known as "Chat Control" — is a Commission proposal of 11 May 2022 (COM(2022) 209 final, procedure 2022/0155(COD)). It would let authorities order communication and hosting providers to search their users' content for child sexual abuse material. It is not law. At the sixth trilogue on 29 September 2026 the negotiators agreed the tasks of the new EU Centre and, on press reports, detection orders for publicly accessible content — but not the one question that has blocked the file for years: whether private messages may be scanned at all. What is in force meanwhile is the voluntary regime, now Regulation (EU) 2026/1881, which applies until 3 April 2028 and leaves end-to-end encrypted communication alone.

What the proposal would require

The Commission adopted the draft on 11 May 2022. Its full title is a Regulation laying down rules to prevent and combat child sexual abuse; it carries the document number COM(2022) 209 final and the procedure number 2022/0155(COD), and it has been with the Parliament and the Council ever since. Nothing below is in force — it is the text as the Commission proposed it and as the two co-legislators are still amending it.

In the Commission's own summary, the draft would oblige providers of hosting services and interpersonal communication services to assess the risk that their service is misused and to propose mitigation measures. Where a national authority finds that a significant risk remains, a court or an independent national authority could issue a detection order: a limited period and a specific type of content on a specific service. Providers could use only detection indicators verified and supplied by the future EU Centre, had to pick the least privacy-intrusive technology available and to minimise false positives, and would have to report what they found to the Centre. National authorities would also be able to issue removal orders and, for material that cannot be taken down, access-blocking orders. App stores would have to stop children from downloading apps that carry a high risk of grooming. The Commission's 2022 text also required age verification for communication services; Tech Times reports that the negotiators provisionally dropped age verification as a mandatory requirement at the fifth trilogue in June 2026.

On the comparison table that the campaigning former MEP Patrick Breyer maintains from the three institutions' texts, the reach of the proposal is wide: services normally provided for remuneration, ad-funded services included, with no size or user-number threshold; communication services covering telephony, e-mail, messenger, chats — including chats that are part of games — and videoconferencing; hosting covering web hosting, social media, video streaming, file hosting and cloud services, including personal storage that is not shared, such as Apple's iCloud; and providers established outside the EU as well. One carve-out is common to all three institutions: non-commercial services that are not ad-funded, which covers many open-source projects.

What is in force today

A weaker, earlier instrument is live and is usually called "Chat Control 1.0". It is a temporary derogation from the ePrivacy Directive that permits — it does not require — providers of number-independent interpersonal communications services such as webmail and messaging to scan for child sexual abuse material and report it. It is not the proposal above, and it is not run by the EU Centre; it is the reason some providers have scanned voluntarily for years.

The instrument now in force
Regulation (EU) 2026/1881 of 24 July 2026. Article 11: it applies until 3 April 2028. The first derogation, Regulation (EU) 2021/1232, had been extended once, to 3 April 2026, and lapsed when the co-legislators failed to agree a further extension before that date; the Parliament had rejected one extension in March 2026, and the file was brought back and adopted in July.
What it leaves out
Article 1(2) excludes audio communications. Article 1(3) excludes interpersonal communications to which end-to-end encryption is, has been or will be applied. Recital 32 adds that nothing in the Regulation should be read as prohibiting or weakening end-to-end encryption.
Who actually scans
On Breyer's dossier, only unencrypted US services have used the regime: Gmail, Facebook and Instagram Messenger, Skype, Snapchat, iCloud Mail and Xbox. European messaging and mail providers have not.

The extension in July 2026 was procedurally contested. As Euronews and Tech Times both report, the Parliament first voted to reject the amended text by 314 to 276, with 17 abstentions; but rejecting a second-reading position requires an absolute majority of all MEPs, which the opponents did not reach, so the extension went through. The Parliament's handling of the file is disputed by the campaigners who say a majority of those voting was against it.

The sixth trilogue, 29 September 2026

Interinstitutional negotiations opened on 9 December 2025, and five rounds — 9 December 2025, 26 February, 16 April, 11 May and 29 June 2026 — passed without settling the central question. The sixth round was held on Tuesday 29 September 2026 under the Irish Council presidency, which took the chair on 1 July 2026 and holds it until 31 December 2026, and it was billed by the presidency as the round for general political agreement.

What was agreed: the tasks of the future EU Centre for the Protection of Children from Child Sexual Abuse. The Parliament's rapporteur Javier Zarzalejos (EPP, Spain) confirmed it in a statement on 30 September: the Centre will receive providers' reports, check that they are not unfounded and pass them to the authorities, maintain a database of indicators of known material, and proactively search publicly accessible content for known and new material — with a fundamental-rights officer monitoring it and a Victims' Consultative Forum. Commission selection of the Centre's seat can now start.

Beyond that, the record is thinner than headlines suggest. Agence Europe and MLex, as relayed by the Brussels Record tracker, report an agreement in principle on detection orders for public content, conditional on a deal on the whole law; netzpolitik.org reports agreement only on the Centre, with some points on public content settled; the Parliament's own statement does not mention detection orders at all; and the Council published no outcome.

What was not agreed is the substance: whether, when and how authorities may order the scanning of non-public communications. On Breyer's account of the round, the Parliament's negotiators stood firm and refused the Council's "search plans", so the deal fell.

The Council's "search plans"

The mechanism at issue is the Council's "search plans" — in German Suchpläne. The term is new to the trilogues, and on netzpolitik.org's reporting it is not even clear that the member states knew what their own presidency meant by it: in a document of 23 September the German negotiators on the Council side said they did not know what lay behind the term and had rejected the plans beforehand.

From what has leaked, a search plan is a document a service would submit describing the technology it would use to detect abuse material and the safeguards it would put in place to limit errors. The Council's disputed point was scope: its presidency note of 18 September 2026 (document 13158/26, marked LIMITE and published by Breyer) records the compromise of bringing "specific parts of an online service or, if possible, individual users" into view, with the Council pressing that the number of items detected should not fall below what the voluntary regime achieves today. Civil-liberties campaigners read "parts of a service" as meaning, in practice, everybody, since every user belongs to some part.

Breyer's reading of the Council position is that providers could file a search plan and begin scanning private chats and content automatically unless an authority actively vetoed it — a "silent approval" — that scanning need not be limited to individual suspects and could cover large parts of a service, that detection orders over non-public content would be issued by administrative authorities rather than courts, and that "voluntary" scanning could be folded into enforceable risk-mitigation duties, so that a platform scans to avoid fines.

Two readings of the Council do not match. netzpolitik.org, which has seen the presidency papers, reports that the Council wants to remove detection orders from the law and favours voluntary scanning. The account Breyer published the day before the trilogue assigns administrative detection orders a central role. Both describe non-public drafts; the Council has published no outcome, and we cannot reconcile them from outside.

Beyond known images

The Commission's 2022 text covered not only known material, matched against fingerprints supplied by the EU Centre, but also new material and grooming — detected by machine-learning systems. The Council's framework keeps that reach: as Tech Times describes it, a search plan would cover hash-matching against known material, machine detection of new material, and machine detection of the "solicitation of children". Breyer's rendering is the same in plainer words: AI-powered image and text analysis for "suspected content", with the risk of false positives on innocent conversations.

The error rate is the weak point. The Parliament's own research service, in a complementary impact assessment of April 2023 quoted by Tech Times, concluded that there are currently no technological solutions that detect child sexual abuse material without a high error rate. The figures the campaigners use are police data: on Breyer's numbers, over half of the investigations triggered by automated reports in Germany targeted minors themselves, mostly consensual image-sharing between teenagers, and about 75% of flagged communications were not actionable. Tech Times adds the Irish figure: of 4,192 referrals to the Gardaí from NCMEC in 2020, 471 were confirmed by police not to be abuse material at all.

Parliament's red lines

The Parliament's negotiating mandate was adopted in the LIBE committee on 14 November 2023 and confirmed by plenary on 22 November 2023, and it has not fundamentally moved. Its position, on the sources above:

  • Scanning of private communications only under judicial authorisation and only where it is targeted at specific persons or groups with reasonable grounds linking them to child sexual abuse.
  • No client-side scanning, and end-to-end encrypted services excluded from scope — the Parliament's mandate says so explicitly, and it has repeated the point since.
  • Proactive "web cleaning": the EU Centre searching publicly accessible content instead.
  • Services that search on their own initiative limited to known material already in the EU Centre's database, which they would have to connect to.
  • Prevention as the other half: safety-by-design defaults and on-device, user-controlled warnings before sensitive content is shared.

One crack appeared in June 2026: according to internal cables reported by netzpolitik.org and summarised by Tech Times, the Parliament's team signalled for the first time a willingness to examine voluntary detection, having previously rejected it outright — while insisting that end-to-end encryption stay entirely outside the regulation and that no general surveillance duty be created. Whether that can be squared with the Council's search plans is exactly what the autumn talks are testing.

The Council's own lawyers

The Council is pushing the search-plan compromise against advice from its own Legal Service. The opinion, document 8787/23 of 2023, was leaked and published by Breyer. Its warning: scanning an entire service or distinct parts of it is "highly probable" to be judged "general and indiscriminate" — and therefore unlawful under the Charter — by the Court of Justice of the EU, which has struck down generalised regimes before. Breyer points to paragraphs 47 and 79 of the opinion; Tech Times puts the same warning in the context of the Court's case law on data retention.

The Legal Service is not alone. The EDPB and EDPS said the same in their joint opinion of 28 July 2022, and both the Parliament's research service and the Council's internal reflections are on record doubting that orders below the level of an individual judicial order can survive review. Breyer's argument is political as well as legal: a law built this way will not protect children, because it will be struck down.

October, November, and the 1.0 fallback

Technical level first. The political trilogue is only half the file. From 30 September, experts continued to negotiate the rules on non-public detection through October; earlier rounds had already provisionally settled removal and blocking orders, national authorities, risk assessments and reporting. Breyer expects the next political trilogue in November — a final attempt at a deal. No date has been confirmed, according to Agence Europe and netzpolitik.org, and the Brussels Record tracker says the same as of 4 October.

The fallback. The Council's position keeps the voluntary "Chat Control 1.0" regime in reserve. Leaked document 13158/26 sketches the option of excluding non-public content from the new Regulation altogether and simply leaving the temporary regime — legal until 3 April 2028 — in place, as a parallel, effectively permanent regime. Breyer calls that a trap: the Parliament must not accept a permanent law that fails to replace the temporary one, because the temporary one has no end date beyond 2028 and no judicial warrant.

What adoption would still take. Even a political agreement in November would need legal scrubbing by all three institutions and formal adoption by the Parliament and the Council before it applied. The Irish presidency ends on 31 December 2026; if nothing is agreed by then, the file passes to the Lithuanian presidency in January 2027.

What it would mean for you

Read this as conditional. Which of the following applies depends on a text that does not exist yet, and the current answer for most services is nothing yet.

Encrypted messengers
The Commission's 2022 proposal covered end-to-end encrypted services and would in effect have required client-side scanning — checking a message on the user's device before it is encrypted. The Parliament excludes end-to-end encrypted services from scope, and netzpolitik.org reports the Council also rejects client-side scanning of encrypted content; but Breyer's comparison of the negotiating texts still marks the Council's draft mandate as following the Commission here, with no exclusion. Treat the exemption as the Parliament's position, not as settled.
A small or self-hosted service
There is no small-enterprise exemption to rely on. The proposal reaches services "normally provided for remuneration" whatever their size, and on Breyer's reading of the Council position even detection orders for public content could hit any hosting provider, however small. A non-commercial, non-ad-funded service — the typical self-hoster or hobby instance — is outside scope in all three texts, but the moment it charges or carries ads, that changes.
Chat in a game
Chat that is part of a game sits inside the communication services the 2022 proposal listed, and on Breyer's comparison of the negotiating texts the Parliament's position keeps e-mail, messenger, chat and videoconferencing while dropping telephony. A game with a chat function is therefore in a different position from one without. Nothing has been agreed.
An open-source project
Outside scope while it is non-commercial and not ad-funded — the single carve-out the Commission, the Parliament and the Council have in common. A commercially run or ad-funded fork is not covered by that exemption, and a project that is itself a hosting provider is a hosting provider.

The one thing to keep straight

None of the scanning duties described here is law. What is law, today and until 3 April 2028, is a voluntary regime for unencrypted communication, and nothing in it requires a provider to weaken encryption. The rest is a proposal under negotiation. This note is not legal advice.

What we could not establish

Whether the Council still wants mandatory orders
netzpolitik.org and Breyer describe the Council's position in opposite directions — voluntary scanning only, or administrative detection orders. The presidency documents are LIMITE; we have one leaked copy that is an image scan with no extractable text.
The exact contents of a "search plan"
Technology and safeguards are described in secondary reporting; the underlying note is not public. The scope wording — "specific parts of a service or, if possible, individual users" — we have only from netzpolitik.org's reading of document 13158/26.
Whether end-to-end encryption ends up excluded
Parliament says yes. The Commission's original text says no. The Council is described both ways. This is the single clause that decides the file.
Numbers in the Council
The Brussels Record tracker counts nine governments on record against mandatory scanning of private messages, about two points short of a blocking minority, with Germany, Belgium or Portugal able to close the gap. We have not verified that arithmetic.

Sources

The Commission's proposal and press release, and the two regulations, are official. Everything about the negotiations is attributed to whoever reported it, because the negotiating documents are not public. Where a source is secondary, we say so.

  1. EUR-Lex — COM(2022) 209 final, proposal for a Regulation laying down rules to prevent and combat child sexual abuse (11 May 2022) The authentic proposal, procedure 2022/0155(COD). Source for the document and procedure numbers and the date. We read the EUR-Lex record and the Commission's summary of the scheme, not every article of the draft
  2. European Commission — press release IP/22/2976, "Commission proposes new EU legislation to prevent and combat child sexual abuse online" 11 May 2022. Source for what the draft would require — risk assessment and mitigation, detection orders, EU Centre indicators, reporting, removal and blocking orders, app-store duty, oversight and redress. Read in full for this page
  3. EUR-Lex — Regulation (EU) 2026/1881 of 24 July 2026, temporary derogation for voluntary detection "Chat Control 1.0" as in force. Source for the date, for Article 1(2) on audio communications, Article 1(3) excluding end-to-end encrypted communications, Article 11 (applies until 3 April 2028) and Recital 32 on encryption. Read for those provisions
  4. European Parliament — Legislative Train, "Combating child sexual abuse online" (updated 20 September 2026) Source for the history: interim act of 14 July 2021, in force 2 August 2021, extended and expired 3 April 2026, approved again and in force since 1 August 2026; the LIBE mandate of 14 November 2023, confirmed in plenary on 22 November 2023; the six trilogues through 29 September 2026
  5. European Parliament — "Combating child sexual abuse: rapporteur hails deal on new EU agency's tasks" (30 September 2026) Rapporteur Javier Zarzalejos on the agreed tasks of the EU Centre. The only official confirmation of what came out of the sixth trilogue; note that it does not mention detection orders. Read in full for this page
  6. EDPB and EDPS — joint opinion on the proposal, 28 July 2022 The data-protection authorities' formal objections to a detection-order framework below the level of an individual judicial order
  7. netzpolitik.org — "Chatkontrolle: Verhandlungen — EU-Staaten und Parlament weiter uneins" (German, 1 October 2026) Secondary, but closest to the documents. Source for the outcome of 29 September, the technical negotiations, the "Suchpläne" concept and the technology-and-safeguards description, the 23 September objection by German negotiators, the scope wording in Council document 13158/26, the Council's preference for voluntary scanning, and the absence of a date for the next trilogue
  8. Patrick Breyer — "Chat Control 2.0 trilogue update: no mass scanning deal for now" (30 September 2026) Campaigning source, written by the Parliament's former negotiator. Source for the claim that the Parliament refused the search plans, for the outcome on public content, for the October technical talks and the November trilogue expectation, and for the warning about the 1.0 fallback. Attributed, not adopted
  9. Patrick Breyer — "Governments push 'Search Plans'…" (28 September 2026) Breyer's reading of the Council's trilogue position — silent approval, scope beyond suspects, administrative orders, risk-mitigation duty — and the links to the leaked Council documents. Attributed
  10. Patrick Breyer — Chat Control dossier and its German version The three-institution comparison table used for scope, service types, size threshold, the open-source carve-out and the age-verification question; timeline of trilogues; the German page carries the term Suchplan. Campaigning source, quoted as such
  11. Tech Times — "EU Council pushes Chat Control mass-scanning plan own lawyers warned unlawful: round six" (29 September 2026) Secondary. Source for the "parts of a service" mechanism and the Council presidency note, the legal opinion of 2023, the chronology of the five earlier trilogues, the Irish presidency's end date and the Lithuanian handover, and the Irish and German error figures. Used as reporting
  12. Brussels Record — Chat Control tracker (last checked 4 October 2026) Secondary, but it links each statement to a document. Source for what the Parliament's statement confirms versus what rests on press reports (Agence Europe, MLex), the absence of a confirmed date for the next round, and the count of governments on record against mandatory scanning
  13. Euronews — "Chat Control 1.0 passed the European Parliament — through the back door" (10 July 2026) Secondary. Source for the July 2026 second-reading vote (314 to 276, 17 abstentions), the absolute-majority threshold and the new end date
  14. Council document 13158/26, "Preparation for the trilogue", 18 September 2026 (LIMITE; published by Patrick Breyer) Listed because it is the document behind the search-plan reporting. We could not extract text from the published scan, so we cite it through netzpolitik.org and Breyer, not directly

Tell us what we got wrong

This file will move, possibly within weeks. If you have the Council's published outcome, a presidency note with a register number, or a provider's own account of what it has scanned, bring it in — a source we can open beats ten pages of commentary, and we will correct this page in public if it turns out we have something wrong.