Leaked EU documents point to a new route for chat control: rather than writing an explicit mandate for scanning private messages into law, member states may be aiming for the same outcome through administrative orders. According to heise online, the documents surfaced ahead of the crucial trilogue negotiations between the Parliament, the Council and the Commission. The issue of chat control administrative orders mass scanning now sits at the center of a debate about whether encrypted messaging can be weakened without anyone ever passing a law that says so.
The source article is brief, and we rely only on what it reports. Where details are not available, we say so.
What the Leaked Documents Reveal
According to heise online, the leaked EU documents reveal plans to enforce mass scanning of private messages through administrative orders. The reporting frames this as an indirect way for EU states to legalize comprehensive scanning, rather than a plain legal requirement written into the regulation text.
The timing matters. The documents appeared just before the trilogue, the closed-door phase where negotiators from the three EU institutions try to reconcile their positions. Positions taken in that room tend to shape the final text, and leaks at this stage give the public a rare view of what governments are actually weighing.
This is also not the first time the proposal has been reshaped. Our earlier coverage of EU Chat Control being rejected again described a pattern of the idea being blocked, revised and reintroduced. The leaked plans look like another revision in that cycle, with the mechanism changing rather than the goal.
How Administrative Orders Could Replace an Explicit Scanning Mandate
An explicit mandate is easy to see and easy to challenge. Lawmakers vote on it, journalists quote it, and courts can review it against fundamental rights. An administrative order works differently. It is issued by an authority under a broader legal framework, often case by case or platform by platform, and it can be harder for the public to follow.
Based on the heise online summary, the concern is that the law itself might avoid the words "mandatory scanning" while still giving authorities the power to require it in practice. If that is the design, the politically sensitive decision moves from the legislature to the administrative level.
That shift has several consequences that critics are likely to raise:
- Less visibility: orders may not get the same scrutiny as a parliamentary vote.
- Scope creep: a framework that allows orders can be applied more widely over time.
- Legal ambiguity: officials can say the law contains no scanning mandate, even if orders achieve the same result.
We should be careful here. The article does not specify the exact legal wording or which states are pushing it, so these points describe the structural risks of the approach, not confirmed details of the leaked text.
It also sits alongside the interim framework. EU governments have already agreed to extend the interim chat control rules until April 2028, which gives platforms legal cover to voluntarily scan. Moving from voluntary scanning to orders would be a significant change in character.
What This Means for End-to-End Encryption
End-to-end encryption means only the sender and recipient can read a message. A service cannot scan content it cannot see, so any order to scan private messages raises a technical question: how do you do it without breaking that protection?
The usual answer discussed in this debate is scanning on the user's device before a message is encrypted, often called client-side scanning. Whether the leaked plans specify such a method is not stated in the heise online summary. But the logic is worth understanding: if an order requires a provider to detect certain content, the provider either has to weaken encryption or inspect messages before encryption applies. Either way, the privacy guarantee changes.
This is why the administrative route matters for encryption. A formal "chat control" law would be openly debated as a threat to secure messaging. An order-based system could undermine the same protection while avoiding that label. The Parliament's own actions show how contested this ground is; see our report on the July 9, 2026 vote on what critics call Chat Control 2.0.
What to Watch as the Trilogue Talks Begin
A few questions will show where this heads:
- Does the final text mention orders explicitly? Watch for language on who can issue them and on what grounds.
- Are there safeguards? Judicial authorization, transparency requirements and limits on scope would all change the picture.
- How does the Parliament respond? Its position on scanning has differed from that of the Council before.
- How do the interim rules interact with the permanent proposal? The two are often confused, and the distinction matters.
The debate has also spilled beyond policy circles. We previously covered how a hacker leaked data of 24 French politicians over Chat Control. That is a reminder of how heated the issue has become, though such tactics are illegal and not a substitute for legitimate debate.
What This Means For You
Nothing changes for your messaging apps today. The leaked documents describe plans, not adopted law, and the trilogue outcome is not yet known. But the direction of travel is worth understanding: the question is shifting from whether the EU will pass a chat control law to whether similar effects can be achieved without one.
For everyday users, that means keeping an eye on whether the apps you rely on keep end-to-end encryption by default, and on how providers respond if orders are introduced. A VPN does not solve this problem, since scanning would happen at the app or device level, not on your network connection.
Actionable Takeaways
- Follow the trilogue process and look for the final text, not just headlines about a "chat control" law.
- Read the wording on administrative orders closely when it is published.
- Understand the history: our coverage of the interim rules extension and the recent votes explains how the proposal got here.
- Keep your messaging apps updated and check their statements on encryption.
- Contact your MEPs if you want your view on scanning heard.
The story of chat control administrative orders mass scanning is still developing. Until the trilogue concludes, the most useful step is staying informed about what the final text really allows.




