TL;DR: On May 4, the EU Parliament, Council, and Commission sit down for the fourth round of trilogue negotiations on the Child Sexual Abuse Regulation (CSAR), the law critics call "Chat Control." The voluntary scanning derogation expired April 3. Parliament voted 311-228 to block mass scanning of private messages. But the Council still wants detection powers, age verification mandates, and hash-matching on unencrypted platforms. A political deal is targeted for July. What comes out of May 4 will shape whether encrypted messaging apps like Signal and WhatsApp can continue operating in Europe without fundamentally changing what they are.
Where Things Stand After April 3
Three weeks ago, the legal foundation for scanning private messages in the EU disappeared. The ePrivacy derogation (the temporary rule that let platforms like Meta, Google, and Microsoft voluntarily scan messages for child sexual abuse material (CSAM) without breaking EU privacy law) expired on April 3, 2026. Parliament voted 311-228 to let it die [1].
Meta confirmed it paused voluntary scanning in the EU immediately after the vote. Child protection organizations warned that CSAM referrals from European platforms would drop. The National Center for Missing & Exploited Children (NCMEC), which processes reports from tech companies, said it expected a "measurable decline" in European referrals [2].
That's the backdrop. The old scanning regime is gone. The question now is what replaces it.
Two Visions of the Same Law
The CSAR has been under negotiation since the European Commission proposed it in May 2022. Four years later, the EU's three institutions still disagree on what it should actually do [3].
What the Council wants
The Council of the EU, representing member state governments, agreed on its negotiating position in November 2025. The headline concession: they dropped the original requirement for mandatory client-side scanning of encrypted messages. That was the provision that caused Signal to threaten to leave the EU entirely [4].
But the Council's text still includes:
- Mandatory age verification on all platforms, including encrypted services like Signal and WhatsApp. Users would need to prove their age before accessing messaging features.
- "Voluntary" scanning codified as a permanent legal framework, not just a temporary derogation. Platforms that choose to scan get legal cover; platforms that don't face regulatory pressure through "risk mitigation" requirements.
- Detection orders for known CSAM using hash-matching technology on unencrypted platforms.
- Vague "risk mitigation" obligations requiring platforms to take "all reasonable measures" to prevent CSAM distribution, with regulators deciding what counts as "reasonable" [3][5].
What Parliament wants
Parliament's position, adopted in November 2023 and reaffirmed this year, draws harder lines [6]:
- No scanning of end-to-end encrypted services. Period.
- Detection limited to known material only: hash-matching against verified CSAM databases. No AI-based detection of "unknown" material or grooming behavior.
- Judicial warrants required for any scanning, targeted at specific suspects.
- No mandatory age verification.
- "Security by design" as the primary framework: platforms build safer defaults (like private profiles for minors) rather than scanning everyone's messages.
The gap between these positions isn't technical. It's philosophical. The Council sees monitoring as a tool that needs calibration. Parliament sees mass monitoring as a threat that needs prohibition.
What's Actually on the Table May 4
The May 4 trilogue is the fourth session since negotiations began December 9, 2025. Previous sessions met February 26 and in early April. A fifth session is scheduled for June 29. The target is a political deal by July [7].
Three specific issues will dominate May 4:
1. Age verification: the new battleground
With mandatory encrypted scanning off the table, age verification has become the Council's fallback. If platforms must verify users' ages before allowing access to messaging or social features, encrypted services face a choice: implement identity verification (destroying anonymous communication) or refuse (and face penalties).
The EFF warned in December 2025 that age verification requirements could "fundamentally alter the privacy-focused design" of encrypted messaging apps. Signal, WhatsApp, and similar services currently allow anonymous signup with just a phone number. Mandatory age verification would require collecting government IDs or biometric data, exactly the kind of data these services are designed not to hold [5].
2. Hash-matching scope
Both sides broadly agree that hash-matching against known CSAM databases is acceptable on unencrypted platforms. The fight is over scope. The Council wants to expand detection to include "unknown" material using AI classifiers. Parliament wants to restrict it to hash-matched, verified material only [6].
The difference matters. Hash-matching compares files against a database of confirmed CSAM: it's targeted and has a relatively low false-positive rate. AI-based detection of "unknown" material is where the EU Commission's own implementation report found a false-positive rate "as high as 20%." One in five flagged conversations was someone who did nothing wrong [8].
3. What "voluntary" actually means
The Council wants to give platforms permanent legal cover for voluntary scanning. That sounds benign. But paired with "risk mitigation" obligations and regulatory pressure, "voluntary" can quickly become "do it or we'll make your life difficult." The EFF calls this model "private mass-scanning of non-encrypted services" wearing a voluntary label [5].
Parliament wants any scanning to require judicial authorization targeting specific individuals. The distance between "voluntary with regulatory pressure" and "court-ordered targeting of suspects" is the distance between mass surveillance and due process.
Why This Still Threatens Encryption
The biggest misconception about the current CSAR negotiations is that encryption won. The Council dropped mandatory client-side scanning. Problem solved.
Not quite. The Council's position creates three indirect paths to undermining encryption:
- Age verification mandates force encrypted services to collect identity data, creating honeypots of sensitive information and destroying the anonymous access model that makes encrypted messaging safe for activists, journalists, and abuse survivors.
- "Risk mitigation" obligations with vague standards let regulators pressure encrypted platforms to weaken their protections. If a regulator decides that encryption itself is a "risk" the platform isn't mitigating, the law provides a mechanism to demand changes.
- Review clauses in compromise proposals would allow scope expansion if "technology improves": a built-in mechanism to reintroduce encrypted scanning later when the political heat dies down [7].
Patrick Breyer, the former Pirate Party MEP who led the parliamentary fight against Chat Control, warned: "The Council's approach puts encryption at risk by maintaining 'voluntary' scanning as a permanent measure and enforcing coercive risk mitigation obligations" [4].
What a Compromise Might Look Like
Drafts circulating in Brussels before the May 4 session suggest a potential landing zone [7]:
- Hash-matching on unencrypted platforms only: limited to known CSAM in verified databases
- No AI-based detection of unknown material in the initial version
- Age verification "encouraged" but not mandatory: platforms would face regulatory incentives rather than legal requirements
- A review clause allowing scope expansion after 3-5 years if detection technology improves
- Encrypted services exempt from detection orders but subject to transparency reporting and "security by design" requirements
If this sounds like a reasonable middle ground, that's because it is, on paper. The devil is in the review clause. A regulation that exempts encryption today but includes a mechanism to revisit that exemption in three years is a regulation that can be turned into a surveillance tool by a future Council that's less interested in compromise.
The Timeline From Here
- May 4, 2026: Fourth trilogue session. Key debates on age verification, hash-matching scope, and the "voluntary" scanning framework.
- June 29, 2026: Fifth trilogue. Likely the final negotiation session before a political deal.
- July 2026 (target): Political agreement between Parliament, Council, and Commission. If they reach one, legal-linguistic review follows.
- Late 2026 / Early 2027: Formal adoption and implementation timeline. The regulation would apply 24 months after entry into force.
If May 4 and June 29 don't produce a deal, the regulation could stall under the next Commission. The political window is narrow.
What You Can Do
- Contact your MEP before May 4. EDRi maintains a CSA Regulation document pool with the full negotiating texts and tools for constituent outreach.
- Use encrypted messaging: Signal, WhatsApp, or any service with end-to-end encryption. If these services have a large, engaged user base when the regulation takes effect, lawmakers face a political cost for weakening them.
- Support the EFF and EDRi: the two organizations doing the most granular work tracking these negotiations.
- Understand what age verification means. If your platform starts asking for a government ID to send a message, that's CSAR in action. You should know why, and what data you're handing over.
The Bottom Line
The EU dropped the most extreme version of Chat Control. No mandatory scanning of encrypted messages. That's real progress. But the Council's replacement strategy (age verification mandates, vague risk obligations, permanent "voluntary" scanning frameworks, and review clauses designed for scope creep) creates a slower path to the same destination.
May 4 is when we find out whether Parliament holds the line. Three years of fighting Chat Control come down to the next two months of closed-door negotiations. If Parliament's privacy protections survive trilogue intact, encrypted messaging in Europe is safe for now. If the Council's age verification and risk mitigation provisions make it through, Signal, WhatsApp, and every encrypted app in Europe will face a choice they shouldn't have to make: verify your users' identities, or leave.
References
- Reclaim The Net: EU Parliament Blocked Mass-Scanning Extension (March 2026)
- The Next Web: EU child safety push stalls as ePrivacy derogation expires (April 24, 2026)
- EFF: After Years of Controversy, the EU's Chat Control Nears Its Final Hurdle (December 2025)
- EU Perspectives: Chat Control faces crunchtime, Breyer warns (December 2025)
- Global Encryption Coalition: Statement on Council Position (January 2026)
- European Parliament: Legislative Train: Combating Child Sexual Abuse Online
- Factually: EU Chat Control Trilogue Status (January 2026)
- EDRi: CSA Regulation Document Pool
Published: April 27, 2026