If you send a message on Signal or WhatsApp today, EU law does not apply to it for now. If you send the same photo through an unencrypted app, it may already be checked by an automated system before anyone reads it. This distinction, rather than a broad claim that “the EU reads your DMs,” reflects the core issue in the ongoing debate over Chat Control and the detection of child sexual abuse material (CSAM) online.
A revived temporary regulation, in force until 2028, allows platforms to voluntarily scan private messages, photos, and videos for CSAM. This does not apply to end-to-end encrypted services like WhatsApp or Signal in the same way it applies to other platforms. A separate permanent proposal, “Chat Control 2.0”, is still being negotiated. Whether it eventually reaches encrypted chats remains the central unresolved question.
How the system decides what to flag
Detection tools work in two main ways. The first is hash matching: an image or video is converted into a cryptographic fingerprint and compared against a database of material confirmed as illegal. It is fast and precise for exact or near-identical copies but easy to defeat with a small edit. The second is machine-learning classification, used for new or altered content and, more controversially, for scanning text for language patterns associated with grooming.








