you are on the clearnet. the addresses listed here only open inside the tor network - download the tor browser here »
AlphaBay.Market
last update: 0 min ago 255 onions tracked
home / news / tor network
03 September 2026 tor network 4 min read

EU reinstates Chat Control 1.0: message scanning returns despite a majority voting no

On July 9, 2026, a majority of the members of the European Parliament who cast a ballot voted to stop the return of the EU's temporary message-scanning regime. It came back into force anyway. The episode - critics call it Chat Control 1.0 passing through the back door - matters well beyond Brussels, because the same logic behind scanning private messages for illegal content is the logic used to justify attacking anonymity networks like Tor.

A vote lost, a law won

Of the 607 MEPs who voted on the proposal to reject the Council's position, 314 supported rejection while 276 opposed it, with 17 abstentions. Under second-reading rules, however, rejecting a Council position requires an absolute majority of all 720 seats - 361 votes - regardless of how many lawmakers show up. The rejection fell 47 votes short, so the reinstatement passed by default. Digital rights campaigner and former MEP Patrick Breyer called the outcome a farce that damages democracy, noting that the vote was forced through an urgent procedure on the last day before the summer recess, when absences were highest. The Council gave its final approval on July 23, and the regime entered into force at the end of the month as Regulation (EU) 2026/1881.

The legal gap the regime filled

The temporary derogation from the ePrivacy Directive had originally allowed communications providers to voluntarily detect, report and remove child sexual abuse material without violating confidentiality rules. Parliament had declined to extend it earlier in 2026, and the instrument lapsed on April 3, leaving a several-month legal gap during which voluntary scanning had no explicit basis. The Commission and Council argued the gap endangered children; opponents argued that a lapse proved scanning was never indispensable. Rather than restart the process, Parliament's president reopened the file and routed it to a second reading where blocking required the near-impossible absolute majority - a procedural path live trackers of the file describe as designed to exhaust opposition through repetition.

What the revived regime actually covers

Chat Control 1.0 remains formally voluntary and technically applies to unencrypted or server-side accessible communications. An amendment adopted alongside the vote explicitly excludes end-to-end encrypted services from scope. In practice, according to Breyer's post-vote analysis, the platforms affected are largely US-based services such as webmail, legacy Messenger archives, and platforms that removed encryption from their DMs. That carve-out sounds reassuring, but privacy analysts writing explainers like overviews of the Chat Control framework point out that the boundary between encrypted and unencrypted is a policy choice that can be redrawn - which is precisely what the permanent regulation would do.

CSAR: September is the decision point

The real prize is the Child Sexual Abuse Regulation (CSAR), nicknamed Chat Control 2.0, which in its most contested form would mandate detection orders against providers - including end-to-end encrypted ones, via client-side scanning on user devices. Five trilogue rounds between Parliament, Council and Commission have ended without agreement; the fifth, on June 29, 2026, collapsed specifically over suspicionless scanning of encrypted traffic. Negotiations resume in September 2026 under the incoming presidency, and both sides know the clock is running: the temporary regime expires April 3, 2028, or when the permanent law lands, whichever comes first. Encrypted providers like Proton face a stark scenario - either EU law forces client-side scanning that breaks their cryptography, or they must consider geo-blocking or withdrawal. Advocates warn that reviving the voluntary regime removed much of the Council's incentive to compromise, since unencrypted-platform scanning already proceeds in the meantime.

Why this matters for the Tor audience

It is tempting to file Chat Control under messaging-app politics and move on. That would be a mistake. Scanning regimes and censorship regimes share infrastructure and share rhetoric: once a legal duty to inspect private traffic exists for one category of content, the machinery - hashing databases, classification models, reporting pipelines - exists for every category that follows. Client-side scanning is functionally indistinguishable from the state-sponsored malware that de-anonymization efforts have long warned about, except it would be installed by the app store rather than a hacker. And the same majorities that tolerate suspicionless message scanning rarely hesitate when asked to block or fingerprint anonymity infrastructure itself; we have documented how national blocking patterns evolve from targeted lists into broad protocol-level filtering. The lesson from July 9 is uncomfortable but useful: procedural thresholds, empty chambers and urgent procedures can override expressed majorities, so privacy-preserving defaults cannot depend on politics alone. Users who need anonymity should not wait for legislation to settle before configuring bridges and fallback transports - see our guide to getting bridges in censored regions - because the window for choosing your tools is always open longer than the window for keeping them. The scanning regime now runs until spring 2028. The September trilogue will decide whether the temporary version was the ceiling or merely the floor.

more notes

all news ›