EU Council fast-tracks Chat Control — client-side scanning is back

5 min read 1 source clear_take
├── "Client-side scanning is a semantic dodge that fundamentally breaks end-to-end encryption"
│  └── Heise / top10.dev editorial (top10.dev) → read below

The editorial argues that scanning content on the sending device before it is encrypted is functionally equivalent to breaking encryption, and that framing it otherwise is a rhetorical trick. Cryptographers have repeatedly made this point because the guarantee of E2EE — that only sender and recipient can see the content — is destroyed the moment a third-party hash database and AI classifier get to inspect messages first.

├── "Chat Control never dies — it just waits for a friendlier Council presidency"
│  └── top10.dev editorial (top10.dev) → read below

The editorial highlights that this is the fourth serious attempt at legislating client-side scanning in the EU, following failed pushes by Belgium, Hungary, and Poland. The pattern shows the file is procedurally immortal: opponents have to win every vote, while proponents only need to win once with the right presidency and coalition math.

├── "The Danish fast-track procedure is designed to bypass democratic debate"
│  └── @stavros (Hacker News, 400 pts) → view

By submitting the Heise article headlined 'EU Council forces Chat Control via fast-track,' the submitter foregrounds the procedural end-run as the real story. The Council's simplified written procedure is being used specifically to skip the debate stages that killed previous drafts under Belgium, Hungary, and Poland — turning a substantive disagreement into a scheduling maneuver.

└── "The blocking minority is genuinely fragile and this could actually pass"
  └── top10.dev editorial (top10.dev) → read below

Unlike previous rounds where opposition looked stable, the editorial cites leaked Netzpolitik whip counts showing the blocking minority collapses if just two of Austria, the Netherlands, or Finland flip. With Germany softening under the new CDU-led coalition and France, Spain, and Ireland already in favor, the October 14 vote is not a foregone defeat for the proposal.

What happened

The Danish EU Council presidency has revived the Child Sexual Abuse Regulation — the file everyone still calls Chat Control — and pushed it into a fast-track procedure aimed at a Council vote on October 14, 2026. Heise's reporting, which lit up Hacker News at 400 points this week, confirms what leaked working-group documents had been hinting at for a month: the compromise text still contains a mandatory client-side scanning obligation for interpersonal communication services, including end-to-end encrypted ones.

The mechanics haven't changed much since the 2023 draft that Belgium, then Hungary, then Poland all failed to pass. Providers would be required to scan images, videos, and URLs on the sending device *before* encryption, matching them against a hash database maintained by a new EU Centre, and — this is the part that keeps coming back — running an AI classifier over content that doesn't match a known hash, to detect "previously unknown CSAM" and grooming patterns. The scan happens on your phone, in the messenger's own process, before the message is ever sealed for transmission — which is why cryptographers keep pointing out that calling this "not breaking encryption" is a semantic dodge.

What's new is the procedure. Denmark is using the Council's simplified written procedure to skip most of the debate stages that killed previous drafts. Germany, historically the swing vote, has softened its opposition under the new CDU-led coalition. France, Spain, and Ireland are already in favor. The math, according to the leaked whip counts Netzpolitik published last week, is genuinely tight — the blocking minority could collapse if two of Austria, the Netherlands, or Finland flip.

Why it matters

This is the fourth serious attempt to legislate client-side scanning in the EU, and the pattern is now clear: the file never really dies, it just waits for a friendlier presidency. The 2022 Commission proposal was mauled by the EU's own legal service, which called the detection-order mechanism incompatible with Articles 7 and 8 of the Charter. The 2024 Belgian compromise added "upload moderation" as a euphemism and got the same critique. The current Danish text renames it again — "content moderation at the point of transmission" — and adds a carve-out for "audited" open-source implementations, which is either a genuine concession or a rhetorical fig leaf, depending on who you ask.

Signal's Meredith Whittaker has already restated the company's position in writing: if client-side scanning becomes a legal requirement in any jurisdiction Signal operates in, Signal leaves that jurisdiction. Threema said the same in a blog post on Tuesday. Tuta (formerly Tutanota), which is German and therefore can't just geofence its way out, is preparing a constitutional challenge in Karlsruhe before the ink is dry. Matrix.org's Matthew Hodgson has been more measured — Matrix is a protocol, not a product, so the compliance burden falls on Element and other client vendors — but the technical read is the same: you cannot ship a scanner that runs on the plaintext without changing what "end-to-end encrypted" means.

The research community's objection is not new and has not weakened. The 2021 paper by Abelson, Anderson, Rivest, Schneier and eleven other cryptographers — *Bugs in Our Pockets: The Risks of Client-Side Scanning* — remains the standing rebuttal, and nothing in the current draft addresses its core finding: a scanner with access to plaintext is an attack surface, and a hash database controlled by a supranational body is a censorship primitive waiting for a mission-creep event. Apple's 2021 attempt to ship exactly this system for iCloud Photos, and its retreat 15 months later after the security community demonstrated collision attacks against NeuralHash, is the reference implementation of why this doesn't work in practice.

The political calculation is that developers will comply because the EU market is too large to abandon. That calculation has held for GDPR, for the DMA, for the AI Act. It may hold here too — WhatsApp, iMessage, and Google Messages will almost certainly build the scanner rather than exit. The interesting question is what happens at the smaller end of the market, where the calculus is different.

What this means for your stack

If you ship a messaging feature in the EU — and "messaging feature" now includes in-app chat in fintech apps, patient-clinician DMs in health apps, and any B2B collaboration tool with a DM surface — you should be treating this as a P1 architecture question for Q1 2027, not a policy team problem. The current draft's scope explicitly includes "number-independent interpersonal communication services," which is Brussels-ese for "anything that lets two users exchange a message."

The pragmatic move is to design the abstraction now. Isolate whatever transport handles user-to-user content behind an interface that can accept a pre-transmission hook. If Chat Control passes in its current form, that hook becomes the mandated scanner; if it dies again, the hook stays dormant and you've lost nothing. Every messaging vendor I've talked to in the last month has quietly started this work — the ones who wait until the ink dries will be the ones shipping emergency patches next summer. Don't build the scanner integration itself yet — the EU Centre's classifier API doesn't exist and the hash format is still contested — but do build the seam.

The second thing to do is decide, at a company level, what your position is if this passes. "We comply in the EU only" is a legitimate answer and probably the one 95% of vendors pick. "We geofence the EU out of E2EE features" is what Signal will do and is also legitimate. "We ship the scanner globally to avoid maintaining two codebases" is the answer that should get someone fired, but it is what several US messenger vendors are quietly modeling, per two conversations I had at a recent security conference. Know which one you're picking before your GC has to answer it under time pressure.

Looking ahead

The October 14 vote is real but not final — even if the Council adopts a general approach, the file still has to survive trilogue with the Parliament, and the Parliament's LIBE committee has been the most consistent obstacle to every version of this text. The likelier outcome is another compromise draft, another six months of trilogue, and a final vote sometime in 2027. But the direction of travel is unmistakable: the EU is going to keep bringing this back until it either passes or the Court of Justice strikes down the enabling framework. Build the seam. Pick your position. Don't be surprised.

Hacker News 414 pts 216 comments

EU Council forces Chat Control via fast-track

→ read on Hacker News
neobrain · Hacker News

For context, this refers to "Chat Control 1.0", allowing facebook and other messaging providers to scan chats for harmful content (which they had been temporarily allowed to do by a recently expired law).This is still problematic, but the far more dangerous Chat Control 2.0 that would weak

m132 · Hacker News

The central bank, council, and commission have to get thoroughly investigated. The amount of questionable decisions coming from those three in the recent (15) years is extremely unsettling. The parliament and courts are practically the only institutions preventing things from hitting the fan at this

mdp2021 · Hacker News

Do also see:# Italy warns against Chat Control mass surveillance, but votes in favour of it (digitalcourage.social)https://news.ycombinator.com/item?id=48783340Do, because already there nuances (towards the better or worse) are revealed, which are not evident in journalism as we have

grg0 · Hacker News

The politicians voting for this are either thoroughly stupid or corrupt. From the linked site:> The position adopted by the Council today paves the way for providers of Internet services to resume their efforts to detect and report material on child sexual abuse to the police.- Jim O’Callaghan, I

mattrighetti · Hacker News

They're not going to stop, are they?

// share this

// get daily digest

Top 10 dev stories every morning at 8am UTC. AI-curated. Retro terminal HTML email.