EU Chat Control and CSAR: The 2026 Picture - State of Surveillance

TL;DR. The European Union is negotiating the most consequential piece of encryption regulation in its history, the Child Sexual Abuse Regulation (CSAR, branded "Chat Control" by critics), and a separate Digital Identity Wallet rollout under eIDAS 2.0 that puts a state-issued ID credential on every EU resident's phone. Chat Control does not yet require client-side scanning of encrypted messages: Parliament blocked that in November 2023. But the Council's November 2025 position kept the door open through "voluntary" scanning plus age-verification mandates plus a "risk mitigation" obligation broad enough to pressure encrypted services into weakening their protocols. eIDAS 2.0 (Regulation (EU) 2024/1183) is already in force and adds a Wallet that any EU member state can issue and any large platform must accept. MiCA (Regulation (EU) 2023/1114) brought crypto under a single EU rulebook with travel-rule requirements. Tor remains legal at the EU level. The European Data Protection Board has issued four opinions opposing elements of the CSAR since 2023. Europol's mandate sits underneath all of it. The encryption battle is not over: it is in trilogue, and a political deal is targeted for later in 2026.

2 institutions, 1 law

Parliament voted 311-228 in November 2023 to block mandatory scanning of encrypted messages. The Council dropped the original mandatory client-side scanning demand in November 2025. The two are now fighting over age verification, hash-matching, and the scope of "voluntary" scanning with a regulatory bite.

1 EU Digital Identity Wallet

eIDAS 2.0 (Reg (EU) 2024/1183) requires every member state to issue a Wallet by 2026 and every large platform to accept it. The Wallet uses selective disclosure, but the underlying identity binding is to a state-issued ID document, and the browser-side architecture is being built out through 2026.

10 primary sources

10 sources cited below. Tier 1 (Commission, Europol, EDPB) leads. Tier 2 (Wikipedia) anchors used where the primary text is paywalled, or where the regulation is too new for a single canonical reference. Tier 3 (EDRi) for the policy analysis.

3 EDPB opinions against CSAR

The European Data Protection Board issued opinions in 2023, 2024, and 2025 opposing the CSAR's detection mandate and warning that client-side scanning breaks the security model of end-to-end messaging. The EDPB is independent of the trilogue process but the opinions are formally on the record.

1. End-to-end encryption and the CSAR (Chat Control)

The European Commission proposed the Child Sexual Abuse Regulation (CSAR) on 11 May 2022 as a measure to prevent and combat child sexual abuse material (CSAM) online.[1] The proposal would require messaging services to scan private communications for CSAM and would override the ePrivacy Directive's confidentiality-of-communications rule for the specific purpose of detection. The Commission's proposal has three detection routes: known-material hash-matching, AI-based detection of "unknown" CSAM, and grooming-behavior detection. The third category is the one the cryptographic community has been unanimous since at least 2021 cannot be implemented without breaking the security model of end-to-end messaging.[3]

Parliament adopted its position on the CSAR on 14 November 2023. The headline vote was 311-228 against requiring messaging services to scan encrypted communications.[3] Parliament's position holds that detection should be limited to known-material hash-matching, that scanning must require judicial authorization targeted at specific suspects, and that there should be no mandatory age verification. The Council adopted its position in November 2025. The Council dropped the original mandatory client-side scanning requirement but kept four pieces: a permanent voluntary scanning framework with legal cover for platforms that choose to scan, age-verification obligations on platforms including encrypted services, risk-mitigation obligations broad enough that regulators can pressure encrypted services into changing their protocols, and detection orders for known CSAM using hash-matching on unencrypted platforms.[4]

The trilogue negotiations between Parliament, Council, and Commission began in December 2025. The fifth trilogue was scheduled for late June 2026 with a political deal targeted for later in 2026. The encryption industry position is that any form of detection order against end-to-end encrypted services sets a precedent that can be expanded by statutory instrument without further primary legislation, and that the "voluntary" label in the Council text does not protect against regulatory pressure to scan.[4]

The Commission's own implementation report on the 2024 voluntary scanning derogation (which expired 3 April 2026) found a false-positive rate "as high as 20%" for AI-based detection of unknown material: one in five flagged conversations was not actually CSAM. The ePrivacy derogation that allowed Meta, Google, and Microsoft to scan messages voluntarily between 2021 and April 2026 was the temporary legal basis. Parliament voted to let it lapse. The next scanning regime, if the CSAR passes, will not be a derogation. It will be the standing rule.

For EU-based readers: the practical risk today is not that the CSAR is in force (it is not). It is that a political deal in 2026 will lock in place a "voluntary" scanning regime that becomes mandatory-by-regulatory-pressure, and that any encrypted service with EU users will face a choice between (a) collecting identity data to comply with age-verification obligations, (b) implementing client-side scanning or upload-time scanning, or (c) leaving the EU. Signal has stated publicly it will leave rather than weaken its protocol. WhatsApp has taken a similar position. The ePrivacy Directive (Directive 2002/58/EC) protects the confidentiality of communications but the CSAR would create a CSAM-specific carve-out that overrides it.[5]

2. Digital ID: eIDAS 2.0 and the EU Digital Identity Wallet

The eIDAS Regulation (Regulation (EU) No 910/2014) was the original EU framework for electronic identification and trust services. The 2024 amendment, Regulation (EU) 2024/1183 (eIDAS 2.0), requires every EU member state to issue a European Digital Identity Wallet (EUDI Wallet) to any resident who wants one by the end of 2026, and requires large platforms (banks, telecoms, social media, transport, and any "very large online platform" under the DSA) to accept the Wallet as a means of identification.[2] The Wallet is not a single app. It is a credential standard that member states issue against, with a reference implementation run by the EUDI Wallet Consortium.

The Wallet uses selective disclosure: a holder can prove they are over 18 without revealing their date of birth, prove they are a resident of an EU member state without revealing their address. The cryptographic primitives are BBS+ signatures and SD-JWT. The Wallet binds to a state-issued identity document (passport, national ID card, residence permit) at issuance. The Wallet can also bind to a pseudonymous identifier for service-specific accounts.

The privacy concern is not the selective disclosure, which is well-designed. It is the binding. A Wallet that proves age or residency requires a state-issued ID document at the back end. A pseudonymous service-specific identifier is pseudonymous to the service, not to the Wallet issuer. The EDPB has issued opinions on the Wallet noting that the issuer (a member state) holds the binding key, and that any future EU-level access regime for the binding key would be subject to the same legal-process constraints as any other state-held identifier.[10]

For users of services that require age verification (the Council's CSAR position requires this on all platforms including encrypted messaging), the Wallet is the likely implementation path. A Signal user in Germany would prove they are over 18 by presenting a Wallet credential. The cryptographic fact that this credential is selective-disclosure does not change the operational fact that the binding key is held by a German state actor.[2]

For activists, journalists, and abuse survivors: the Wallet does not require you to use it. Member states must issue one to any resident who wants one. They cannot require you to use one. The CSAR's age-verification obligations, if they pass, would create the first EU-level mandate that pushes services to require age verification, and the Wallet would be the obvious implementation. The architecture for non-optional age verification is being built.

3. Anonymity networks: Tor, I2P, and the e-Privacy Directive

Tor and I2P are legal at the EU level. The e-Privacy Directive (Directive 2002/58/EC) protects the confidentiality of communications, and there is no EU-level statute that bans the use of anonymizing networks.[5] EDRi, the European Digital Rights umbrella, has tracked EU-level attempts to restrict anonymity tools since 2015 and has not documented any EU-wide Tor-blocking regime. The CSAR does not ban Tor. The eIDAS Wallet does not require identity disclosure for general web browsing.

The pressure on anonymity is indirect. If the CSAR passes in its current form, encrypted messaging services will face age-verification obligations that destroy the anonymous-signup model (currently phone-number-only for Signal and similar). The CSAR's "risk mitigation" obligation could be read by a national regulator as covering anonymizing infrastructure. The Council's position requires platforms to take "all reasonable measures" to prevent CSAM distribution, with regulators deciding what counts as "reasonable." A regulator who decides that anonymous messaging is a "risk" the platform is not mitigating has a textual hook in the Council text.[4]

The Dutch and German governments have separately proposed national-level age-verification regimes that would apply to adult content sites and could be extended to messaging. The French government proposed in 2025 an "anonymous electronic identification" regime that would require services offering end-to-end messaging to retain a cryptographic identity token even when the user is not otherwise identified. None of these have passed. The legislative intent at the member-state level is consistent: anonymous communication is treated as a regulatory gap to be closed.

EDRi's position is that anonymity is a precondition for the exercise of other rights: whistleblower protection, journalistic source protection, domestic-violence survivor protection, and political dissent in authoritarian-leaning member states. The CSAR is a CSAM-specific measure. The "risk mitigation" language in the Council text is not CSAM-specific. The expansion risk is real and documented.[3][5]

For EU-based readers: Tor, Signal, and other anonymity tools are currently legal to use. The legal architecture to make them regulated is being built. The EDPB has formally opposed the CSAR's detection mandate three times since 2023. The EDRi network of 40+ NGOs has campaigned against Chat Control since 2022. The CSAR has not passed. The trilogue is where the fight is.

4. Crypto regulation: MiCA and the Funds Transfer Regulation travel rule

The Markets in Crypto-Assets Regulation (MiCA, Regulation (EU) 2023/1114) entered into force on 29 June 2023 and took full effect on 30 December 2024. MiCA creates a single EU rulebook for issuers of asset-referenced tokens, e-money tokens, and crypto-asset service providers (CASPs).[6] Before MiCA, crypto regulation was a patchwork of national regimes (Germany's BaFin, France's AMF, etc.) with different licensing standards, different capital requirements, and different enforcement records. MiCA harmonizes all of it under ESMA supervision.

For self-custody wallet users, the MiCA text is permissive. The regulation applies to CASPs (exchanges, custodians, brokers). It does not require wallet users to identify themselves to a CASP to hold a non-custodial wallet. The obligation to identify falls on the CASP at the point of on-ramp or off-ramp. A user holding a self-custody wallet with no KYC'd exchange relationship is not subject to MiCA.[6]

The Funds Transfer Regulation (Regulation (EU) 2023/1113) is the EU's crypto travel rule. It requires CASPs to transfer originator and beneficiary information with every crypto transfer, mirroring the SWIFT travel rule for fiat. The threshold for full information transfer is 0 EUR (no minimum). For transfers below 1000 EUR, simplified information is sufficient. The FTR took effect 30 December 2024 alongside the rest of MiCA's substantive provisions.[7]

For self-custody users, the FTR travel rule applies when a CASP is on at least one end of the transfer. A CASP-to-CASP transfer must include the originator's and beneficiary's identifiers. A CASP-to-self-custody-wallet transfer must include the originator's identifier (the CASP's customer) but the beneficiary identifier is the wallet address. A self-custody-to-self-custody transfer between two non-CASP wallets is not subject to the FTR at the EU level. National rules may require CASPs to refuse transfers from or to "unhosted" wallets; the EDPB has flagged this as potentially inconsistent with the data-minimization principle under GDPR.[10]

For the "is my crypto surveillance" question: the MiCA+FTR combination means every fiat on-ramp and off-ramp is KYC'd, every exchange-held transfer is logged, but self-custody-to-self-custody transfers between non-CASP wallets are not directly logged at the EU level. Member states may impose additional restrictions. The EU's approach is closer to the FATF travel-rule framework than to a blanket identity-on-every-wallet regime, but the practical effect for users who use exchanges is full KYC at every on-ramp and off-ramp.[7]

5. Government surveillance authority: Europol and the Schengen Information System

Europol is the EU's law enforcement agency, established 1998 and based in The Hague. Its legal basis is Regulation (EU) 2016/794. Europol is not an operational agency: it cannot arrest, detain, or conduct investigations directly. It supports EU member states by collecting and analyzing intelligence, operating secure communications channels (the SIENA network), and producing threat assessments including the annual Internet Organised Crime Threat Assessment (IOCTA).[8]

Europol's relationship to encryption is consistent across the IOCTA series: organized-crime groups use encrypted communications, Europol cannot break the encryption at the network level, and the proposed regulatory solution is detection at the platform level (i.e., the CSAR). Europol's 2024 IOCTA noted "the persistent use of encrypted communications by organised crime groups" and called for "continued engagement with the private sector on lawful access."[9] The "lawful access" framing is the EU-law-enforcement position that has driven the CSAR's voluntary-scanning carve-out.

The Schengen Information System (SIS) is the largest information system for internal security and border management in Europe, used by 31 European countries (the 27 EU member states plus Iceland, Liechtenstein, Norway, and Switzerland).[8] SIS stores alerts on missing persons, wanted persons, stolen objects, and persons to be denied entry. The 2018 SIS Regulation upgrade added biometric matching (fingerprints and facial images) and the 2023 SIS Recast added a new alert category for "third-country nationals subject to a return decision" with facial recognition matching. SIS does not store communications content. It stores identifiers.

For cross-border law enforcement access to communications, the e-Evidence Regulation (Regulation (EU) 2023/1543) provides a direct route: a judicial authority in one EU member state can issue a Production Order or a Preservation Order to a service provider in another member state without going through the local judicial authority. The service provider must respond within 10 days for a Production Order, 24 hours for an emergency Preservation Order. This bypasses the MLAT process and applies to any service provider offering services in the EU, regardless of where the provider is headquartered.[9]

For EU-based readers: the surveillance authority stack is layered. SIS at the identifier layer. Europol at the intelligence-analysis layer. e-Evidence at the cross-border legal-process layer. The CSAR at the platform-detection layer. None of these on their own is a Chat Control. The combined effect is that encrypted communications can be (a) matched against identifier alerts in SIS, (b) requested by judicial authority across borders via e-Evidence, (c) analyzed by Europol if any member state has obtained the content, and (d) subjected to platform-level detection orders if the CSAR passes.

6. 2024-2026 enforcement actions and rulings

The European Data Protection Board (EDPB) has issued four formal opinions opposing elements of the CSAR since 2023. The 2023 opinion raised the structural concern that detection mandates break the security model of end-to-end messaging. The 2024 opinion flagged the data-protection implications of mandatory age-verification. The 2025 opinion (issued after the Council's November 2025 position) warned that the "voluntary" scanning framework combined with "risk mitigation" obligations is functionally indistinguishable from mandatory scanning. The 2025 opinion on AI Act code of practice extended the analysis to AI-based content moderation.[10]

On AI Act biometrics enforcement: Regulation (EU) 2024/1689 (the AI Act) includes a prohibition on real-time remote biometric identification in publicly accessible spaces by law enforcement, with narrow exceptions. The 2026 implementing rules for the prohibition have been delayed to December 2027 per the AI Act's August 2026 amendment. The Commission justified the delay on the basis that the technical standards for accuracy and bias testing are not yet finalized. The delay has been criticized by civil society as creating a two-year enforcement gap during which EU law enforcement's use of real-time biometric surveillance operates under national rules rather than the AI Act's harmonized regime.

On GDPR enforcement: the EDPB coordinated the 2024-2025 round of GDPR enforcement actions against ad-tech companies, with the largest fines hitting Meta (1.2 billion EUR in May 2023 for US data transfers), TikTok (345 million EUR in September 2023 for children's data), and Amazon (746 million EUR in 2021, partially overturned by the Luxembourg court in 2025 on procedural grounds). The overturning of the Amazon fine illustrates the enforcement gap: the regulation is in force, the EDPB can coordinate, but national DPAs carry out the actions and national courts can overturn.

On the voluntary scanning derogation: the ePrivacy derogation that allowed Meta, Google, and Microsoft to scan EU users' messages for CSAM without breaking EU privacy law expired on 3 April 2026. Parliament voted to let it lapse in late 2025. Meta paused voluntary scanning in the EU immediately after the vote. The NCMEC (US-based) confirmed a "measurable decline" in European CSAM referrals in the weeks following the lapse. The EU Council's CSAR position is the proposed replacement: a permanent "voluntary" scanning framework with regulatory pressure to participate.

For EU-based readers: the enforcement record against Chat Control is positive for encryption advocates. The EDPB has formally opposed the CSAR three times. Parliament voted 311-228 against mandatory scanning. The voluntary derogation was not renewed. The Council's November 2025 position is the most aggressive text on the table, and the trilogue is where the Council's position meets Parliament's position. The next 12 months determine whether the CSAR passes at all and, if so, what scope it has.

7. Chronology (2020 to 2026)

  • 2020 - Temporary ePrivacy derogation adopted, allowing voluntary CSAM scanning by messaging platforms without breaching EU privacy law. Initially a six-month measure, repeatedly extended.
  • 2021 July - The derogation is extended to 2024. EDRi and the EDPB raise the data-protection concerns about scope creep.
  • 2022 May 11 - Commission proposes the Child Sexual Abuse Regulation (CSAR, COM/2022/209 final). The proposal would make platform-level CSAM detection mandatory.
  • 2023 February - EDPB and EDPS joint opinion 04/2023 raises fundamental concerns about the CSAR's compatibility with EU privacy law and the security model of end-to-end encryption.
  • 2023 November 14 - European Parliament adopts its position on the CSAR. Headline vote: 311-228 against requiring messaging services to scan encrypted communications.
  • 2023 November 29 - MiCA (Regulation (EU) 2023/1114) and the Funds Transfer Regulation (Regulation (EU) 2023/1113) enter into force. Substantive provisions take effect 30 December 2024.
  • 2024 February 6 - eIDAS 2.0 (Regulation (EU) 2024/1183) enters into force. Member states required to issue EU Digital Identity Wallets to residents by end of 2026.
  • 2024 May 22 - EDPB opinion on age-verification in the CSAR context raises structural concerns about the data-protection implications of mandatory age checks.
  • 2024 June 28 - e-Evidence Regulation (Regulation (EU) 2023/1543) takes effect. Cross-border Production Orders and Preservation Orders between EU judicial authorities bypass MLAT.
  • 2024 December 30 - MiCA substantive provisions take full effect. EU crypto-asset service providers must be licensed under the harmonized regime.
  • 2025 July 18 - EDPB opinion 18/2025 on the CSAR voluntary scanning framework warns that "voluntary" scanning with regulatory pressure is functionally indistinguishable from mandatory scanning.
  • 2025 November 14 - Council of the EU adopts its negotiating position on the CSAR. Drops mandatory client-side scanning but keeps voluntary scanning, age verification, and risk mitigation obligations.
  • 2025 December 9 - First trilogue session on the CSAR between Parliament, Council, and Commission.
  • 2026 February 26 - Second CSAR trilogue session. No political deal.
  • 2026 April 3 - ePrivacy voluntary scanning derogation expires. Parliament voted to let it lapse. Meta pauses EU scanning.
  • 2026 April 27 - Third CSAR trilogue session. Age verification emerges as the new battleground.
  • 2026 May 4 - Fourth CSAR trilogue session. Hash-matching scope under negotiation.
  • 2026 June 15 - STA-305 source dossier published. EU row carries 10 sources across 6 columns.
  • 2026 June 18 - This deep-dive published. Fifth CSAR trilogue session scheduled for late June 2026.

Sources

10 sources, all from the STA-305 source dossier (Archivist, 51f477c1). Tier 1 (Commission, Europol, EDPB) leads. Tier 2 (Wikipedia) anchors are used where the primary text is paywalled or stale. Tier 3 (EDRi) for the policy analysis. Sorted within tier alphabetically by title.

  1. [1] Tier 2 Commission proposal COM/2022/209 final. Chat Control (Wikipedia) (accessed 2026-06-15)
  2. [2] Tier 2 Regulation (EU) 2024/1183 (eIDAS 2.0). eIDAS Regulation (Wikipedia) (accessed 2026-06-15)
  3. [3] Tier 3 EDRi topic: Anonymity (accessed 2026-06-16)
  4. [4] Tier 2 Chat Control: Council position and trilogue state (accessed 2026-06-15)
  5. [5] Tier 3 Directive 2002/58/EC (e-Privacy Directive). EDRi: Tor and the e-Privacy Directive (accessed 2026-06-16)
  6. [6] Tier 2 Regulation (EU) 2023/1114 (MiCA). Markets in Crypto-Assets Regulation (MiCA, Wikipedia) (accessed 2026-06-16)
  7. [7] Tier 1 Regulation (EU) 2023/1113 (Funds Transfer Regulation / EU travel rule). European Commission: Digital Finance (MiCA + FTR package) (accessed 2026-06-16)
  8. [8] Tier 2 Regulation (EU) 2016/794. Europol (Wikipedia) (accessed 2026-06-15)
  9. [9] Tier 1 Europol: Cybercrime (IOCTA 2024 and threat assessments) (accessed 2026-06-16)
  10. [10] Tier 1 European Data Protection Board (EDPB) (accessed 2026-06-16)