Green digital code streaming down a dark screen, resembling the Matrix
Photo via Unsplash

TL;DR: On April 3, the EU's legal basis for voluntary CSAM scanning expired after Parliament voted it down 311-228. Three days later, Google, Meta, Microsoft, and Snapchat released a joint statement announcing they'd keep scanning private messages in the EU anyway. An EU Commission spokesperson said flatly: "Without a legal basis, companies are no longer allowed to proactively detect child sexual abuse in private communications." The companies called Parliament's vote "irresponsible." A coalition of 247 child rights organizations backed them. Privacy advocates say corporations don't get to override democratic votes. Nobody's been fined yet.

The Democratic Vote That Didn't Matter

On March 26, the European Parliament voted 311-228 to reject extending Chat Control 1.0, the temporary ePrivacy derogation that since 2021 let tech platforms scan unencrypted private messages for child sexual abuse material.

The law expired April 3. We covered it the day it died. We asked: will platforms actually stop, or will they "quietly continue and dare regulators to enforce?"

We got our answer on April 5. Google, Meta, Microsoft, and Snapchat released a joint statement. Not quietly. Loudly.[1]

Their message to the European Parliament: we're not stopping.

What the Joint Statement Says

The statement is remarkable for its tone. Four corporations directly contradicting a democratic body that voted to end their scanning authority:

"Today, because of the expiry of the ePrivacy derogation enabling the use of technology to detect child sexual abuse material (CSAM), Europe risks leaving children across the globe less protected from the most abhorrent harm."

They called Parliament's decision to let the law expire an "irresponsible failure."

Then the actual commitment:

"As EU institutions continue to negotiate an immediate, interim solution and durable framework, signatory companies (Google, Meta, Microsoft, and Snap) reaffirm their continued commitment to protecting children and preserving privacy, and will continue to take voluntary action on our relevant Interpersonal Communication Services."

Translation: We'll keep scanning Gmail, Messenger, Instagram DMs, Outlook, Xbox messages, and Snapchat messages in the EU. Your Parliament voted to end this. We don't care.

They announced a webinar for April 10 "to explain how hash-matching and CSAM detection tools work" (as though the Parliament rejected scanning because they didn't understand it, not because they decided mass surveillance of private communications is incompatible with fundamental rights).[1]

The EU Commission Disagrees

The companies aren't operating in a legal gray area. The European Commission, which actually wanted the scanning to continue, told The Record that the platforms are now breaking EU law.[2]

Commission spokesperson Guillaume Mercier: "Without a legal basis, companies are no longer allowed to proactively detect child sexual abuse in private communications."

Another Commission spokesperson added that "protection of our children should not be subject to autonomous business decisions."

Read that again. Even the institution that fought to extend Chat Control is saying the companies can't do this. The Commission wanted Parliament to vote differently, but when Parliament voted, the Commission accepted the result. The companies didn't.

The Child Safety Shield

The companies aren't acting alone. A coalition of 247 child rights organizations condemned Parliament's vote, calling the regulatory gap "deeply alarming and irresponsible." German Chancellor Friedrich Merz backed maintaining the practice. Europol's Catherine De Bolle warned that law enforcement will be "hobbled" without scanning capabilities.[2]

This is the political cover. Nobody wants to be seen opposing child safety. That's precisely why it's been the weapon of choice for surveillance expansion in Europe for years.

But the numbers behind the scanning system tell a different story than the rhetoric:

  • 13-20% false positive rate on automated image assessment
  • Germany's BKA found nearly 50% of reports were criminally irrelevant
  • Among flagged German suspects, roughly 40% were minors (mostly teenagers sexting)
  • Scanning reports dropped 50% since 2022
  • Only 36% of CSAM reports came from chat scanning at all

And there's the EFF's documentation of false positives at Google specifically: fathers' photographs of their own children flagged by automated scanning, leading to police investigations. The men were cleared, but only after their Google accounts were locked, their photos reviewed by strangers, and their lives upended.[3]

This is the system the companies are fighting to preserve.

When Corporations Override Parliaments

Strip away the child safety framing and look at what actually happened: a democratically elected parliament voted to end a surveillance program. The corporations running that program said no.

This isn't a case of companies reluctantly continuing operations during a regulatory transition. They issued a public statement attacking the Parliament's decision. They organized a webinar to argue their case. They explicitly committed to continued scanning.

The platforms also asked EU regulators for assurances that they wouldn't be penalized for continuing to scan. In other words: they want to break the law and not face consequences.[4]

That's not corporate responsibility. That's corporate sovereignty.

And the precedent is dangerous beyond CSAM. If four tech companies can openly defy an EU parliamentary vote and face no enforcement, what stops the same companies from ignoring other privacy regulations when they find them inconvenient? The ePrivacy Directive doesn't have an exception for "we think this is important." Neither does the GDPR.

The Enforcement Question

So what happens now? In theory, national data protection authorities in each EU member state could investigate and fine the platforms for violating the ePrivacy Directive. The Digital Services Act's general monitoring prohibition adds another legal angle.

In practice? EU enforcement is glacial. Investigations take years. Cross-border cases between DPAs move even slower. Ireland's Data Protection Commission (which oversees Google, Meta, and Microsoft because of their EU headquarters) has a documented history of slow enforcement that's frustrated other EU regulators.

The companies know this. That's why they're not even pretending to comply. The calculation is simple: by the time any enforcement action materializes, either the new CSAR regulation will give them a fresh legal basis, or they'll have demonstrated that scanning is so normalized that no regulator will have the political appetite to stop it.

It's the same playbook Uber used to enter European markets. Break the rules, establish yourself, wait for the law to catch up to your reality.

Why This Matters for CSAR

The companies aren't just preserving the status quo. They're building leverage for the CSAR trilogue negotiations that resume May 4.

CSAR (the Child Sexual Abuse Regulation) is Chat Control's permanent successor. If passed in anything close to the Council's version, it would make scanning mandatory and extend it to encrypted platforms like Signal and WhatsApp.

By continuing to scan during the legal gap, the companies create a fait accompli. They can tell negotiators: "See? We're already doing this. The infrastructure exists. Just give us the legal authority we need." It normalizes the surveillance and makes it politically harder for Parliament to hold its position in trilogue.

The trilogue timeline:

  • May 4, 2026: Third trilogue session
  • June 29, 2026: Fourth trilogue session
  • July 2026: Target date for political deal

Signal has already said it'll leave Europe before implementing client-side scanning. The stakes couldn't be higher.

What You Can Do

Switch to Encrypted Messaging

Gmail, Messenger, Outlook, and Snapchat are actively scanning your messages in the EU, without legal authority. Signal and WhatsApp use end-to-end encryption that prevents this kind of server-side scanning. Our comparison guide helps you pick.

Contact Your MEP Before May 4

The CSAR trilogue resumes in two weeks. Tell your MEPs you support Parliament's position: targeted detection with judicial warrants, not mass scanning. EDRi's campaign page makes it easy.

File DPA Complaints

If you're an EU resident using Gmail, Messenger, Outlook, or Snapchat, you can file a complaint with your national data protection authority. The companies are scanning your messages without a legal basis. That's what DPAs exist to address.

Support Digital Rights Groups

EDRi, CDT Europe, and Patrick Breyer's office are fighting the CSAR battle. They need funding and public pressure behind them.

The Bottom Line

A democratic parliament voted to end mass message scanning. Four corporations said no. The EU Commission says they're breaking the law. Nobody's doing anything about it.

This isn't a story about child safety. It's a story about who gets to decide how surveillance works in a democracy: elected representatives, or the companies that own the infrastructure.

Right now, the companies are winning.

References

  1. The Record: Big tech vows to continue CSAM scanning in Europe despite expiration of law allowing it (April 6, 2026)
  2. Telecompaper: Google, Meta, Microsoft and Snapchat to continue CSAM screening after EU legal loophole expires (April 2026)
  3. EFF: EU Parliament Blocks Mass-Scanning of Our Chats. What's Next? (April 2026)
  4. PPC Land: Google Lost EU Legal Cover to Scan for Child Abuse Images (April 2026)
  5. Patrick Breyer MEP: Chat Control Tracker (comprehensive timeline and false positive data)
  6. CDT Europe: Response to European Parliament Rejection of Chat Control 1.0 Extension

Published: April 20, 2026