The European Union has once again pushed back the deadline on its interim "chat control" rules, extending the voluntary scanning framework for child sexual abuse material (CSAM) until April 2028. The move, reported by Euronews, keeps in place a legal gray zone that has defined the EU's fight over online privacy for years: platforms can choose to scan private messages for illegal content, but they are not yet required to.
This latest EU chat control extension 2028 deadline is not a new law. It is a continuation of a temporary derogation first introduced years ago, one that was supposed to be replaced by a permanent, mandatory regulation. Instead, lawmakers have repeatedly kicked the can down the road, unable to agree on whether scanning should stay optional or become compulsory, and whether encrypted messaging apps should be forced to comply at all.
What the EU Just Extended, and Until When
Under the extension, messaging and email providers operating in the EU retain the legal ability to voluntarily scan user content for CSAM through April 2028. This is the same interim regime that has been in effect since it was first carved out as an exception to the EU's ePrivacy rules. Without it, platforms that already scan for abusive material would technically be breaking privacy law by doing so.
The extension buys negotiators more time to hash out a permanent framework, often referred to as "Chat Control 2.0," which has stalled repeatedly amid disagreements over mandatory scanning obligations and their impact on encrypted communications. For now, the interim rules simply continue, giving companies breathing room without settling the bigger question of whether scanning should eventually become a legal requirement rather than a choice.
Voluntary Scanning vs. Mandatory Scanning: Why the Distinction Matters
The difference between voluntary and mandatory scanning is the crux of the entire debate. Under the current, extended rules, a messaging provider can opt to scan messages, photos, or links for known CSAM using detection tools, but nothing in EU law forces them to do so. Providers that choose not to scan face no penalty under this specific regulation.
A mandatory scanning regime, by contrast, would require every in-scope platform, including those offering end-to-end encrypted messaging, to build in detection capabilities regardless of user preference. Civil liberties groups, security researchers, and several EU member states have warned that this would amount to a form of mass surveillance, since it would require scanning the private communications of every user, not just those suspected of wrongdoing. That fundamental disagreement is why the EU has settled for extension after extension rather than passing a permanent law. Readers can get a fuller sense of how divided public opinion is on this point in the EU Chat Control Sparks Debate: Euronews Launches Reader Poll, which captured reader reaction to the earlier stages of this fight.
How Chat Control Interacts With End-to-End Encryption
The technical sticking point is encryption. End-to-end encrypted apps are designed so that only the sender and recipient can read a message, not even the platform operator. Any scanning system capable of inspecting message content for illegal material would need some way to access that content before, or instead of, encryption doing its job.
This is why critics argue that mandatory scanning proposals are functionally incompatible with strong encryption, even when lawmakers insist encryption itself would remain intact. The mechanics of how scanning could work without undermining encrypted protections is a genuinely complex technical question, one that EU Chat Control: Encryption Determines What Gets Scanned breaks down in more detail. Because the current extension only preserves voluntary scanning, encrypted apps that choose not to scan remain unaffected for now, but the underlying tension has not been resolved, only postponed to 2028.
What This Means For You
If you use messaging apps within the EU, nothing changes immediately. Voluntary scanning was already legal before this extension, and it remains legal now. No new mandatory scanning obligation has been imposed on encrypted apps. What has changed is the timeline: EU lawmakers now have until April 2028 to negotiate a permanent solution, and that negotiation will determine whether stronger, compulsory scanning requirements eventually apply to the apps you use every day.
In the meantime, it is worth understanding which apps you use actually offer end-to-end encryption by default, and which platforms have opted into voluntary scanning programs. Public sentiment on this issue remains sharply divided, as reflected in the EU Chat Control Debate Resurfaces in Euronews Poll, so staying informed as the 2028 deadline approaches is worthwhile.
Key Takeaways
The EU chat control extension 2028 deadline is a pause, not a resolution. Voluntary scanning remains legal, mandatory scanning is still undecided, and the encryption debate is far from settled. Between now and 2028, consider reviewing the privacy settings and encryption standards of the messaging apps you rely on, follow how the permanent legislation develops, and choose services that are transparent about whether and how they scan content. The fight over chat control is not over, it has simply been given a new deadline.




