A Familiar Debate Reaches Another Milestone
On July 9, the European Parliament voted to extend the regulatory regime that permits technology companies to scan users' private messages in search of child sexual abuse material (CSAM). The vote, reported by Pravda EU, has reignited a debate that has simmered in Brussels for years: how far should platforms go in scanning private communications, and what does that mean for the confidentiality of everyday conversations?
It's important to separate this vote from the more sweeping proposal that has repeatedly stalled in negotiations. The European Union has been wrestling with two distinct versions of chat control policy. One is a voluntary scanning framework that lets companies like Meta continue detecting CSAM using existing tools, a practice that has technically existed in a legal gray area pending formal extension. The other is a far more contentious mandatory scanning mandate, often called "chat control 2.0," which would require platforms to build in detection systems capable of scanning encrypted messages before they're sent, something privacy advocates and encrypted messaging providers have fought hard against.
What Actually Changed on July 9
The July 9 vote extended the current voluntary scanning exemption, essentially the legal permission structure that has allowed companies to keep scanning for CSAM without running afoul of EU privacy law. This is consistent with a pattern the Parliament has followed before. As covered in our earlier report on how the EU Parliament limited chat control scanning until 2027, lawmakers have opted for temporary extensions rather than permanent, sweeping legislation, giving themselves room to keep negotiating the more controversial mandatory provisions.
That's a meaningfully different outcome than a mandatory scanning law that would apply to encrypted messaging by default. Readers who followed the back-and-forth in Brussels will recall that a broader push toward mandatory client-side scanning was rejected outright in an earlier session, a decision we detailed in EU Chat Control Rejected Again: What's at Stake. More recently, the Parliament formally adopted what's being described as "chat control 1.0," the voluntary framework, in a vote we broke down in EU Parliament Passes Chat Control 1.0: July 2026 Vote. The July 9 extension reported by Pravda EU appears to build directly on that outcome, keeping the voluntary scanning permission structure alive rather than introducing new mandatory obligations.
Why the Confusion Persists
Part of what makes this topic difficult for the average reader to follow is the naming itself. "Chat control" has become shorthand for multiple, legally distinct proposals: a voluntary scanning exemption that already exists, and a mandatory scanning mandate that keeps getting proposed, revised, and voted down. Headlines describing chat control as "legalized" can easily be read as confirmation that private messages are now open to blanket surveillance, when the more accurate read is that an existing voluntary practice has been given continued legal cover.
That said, the fact that this framework keeps needing extension, rather than being resolved once and for all, tells its own story. Every renewal keeps the door open for future amendments that could expand scanning obligations, and privacy advocates have consistently warned that voluntary frameworks can serve as a stepping stone toward mandatory ones. Our earlier coverage of the moment the EU Parliament rejected mandatory chat control outright shows just how contested this issue remains, and how quickly the political winds can shift.
What This Means For You
For most users, this extension does not change how mainstream messaging apps function today. Companies that already scan for CSAM under the voluntary regime will continue to do so under the renewed legal framework. If you use end-to-end encrypted messaging services that have resisted scanning mandates, your day-to-day privacy protections haven't changed as a direct result of this specific vote.
What has changed is the political runway. Each extension buys time for further negotiation on the more expansive mandatory scanning proposal, meaning this is not the final chapter. Users who value private communication should treat this as a signal to stay informed rather than an immediate call to action. It's also worth remembering that unrelated privacy risks, like the recent WhatsApp credential dump exposing user data, are a reminder that message content scanning is only one piece of a much broader privacy picture.
Staying Ahead of Chat Control Developments
The chat control debate is far from settled. The EU has shown a consistent pattern of extending, rejecting, and revising these proposals rather than delivering a single definitive law, and that pattern is likely to continue as mandatory scanning provisions resurface in future sessions.
If you want to protect your communications regardless of how this legislation evolves, consider using messaging platforms that publish transparent encryption practices, review privacy policies before assuming a service is private, and follow ongoing legislative developments so you're not caught off guard by future amendments. Chat control, in whatever form it takes next, is a policy area worth watching closely.




