Chat Control: The Majority Voted No — and Lost Anyway
314 MEPs voted against Chat Control, 276 for it — the law is in force anyway. The Council kept Parliament's encryption carve-out.
Status: 30 August 2026. The interim derogation is back: Regulation (EU) 2026/1881 has been in force since 31 July 2026 and runs until 3 April 2028. The Council accepted Parliament’s encryption carve-out. The permanent CSA Regulation is still open.
The majority voted no. It lost anyway.
On 9 July, the European Parliament voted at second reading on the return of the “temporary” ePrivacy derogation — the rule that lets communications services “voluntarily” run automated, suspicionless scans of private messages for child sexual abuse material and grooming. The motion to reject the Council’s position outright received 314 votes in favour against 276 opposed, with 17 abstentions.
A clear majority of the members voting wanted to stop the law. It wasn’t enough. At this stage of the procedure, rejection requires an absolute majority of all 720 MEPs — 361 votes. It fell 47 short. A surveillance law survived against the majority of votes cast, because absent members effectively count as yes. If you ever wondered why the cypherpunks never took government assurances about private communications on faith: this is the exhibit.
The timing was no accident either. The file, which had expired in April, was revived at short notice in late June and fast-tracked into the start of the summer recess — a window in which absolute majorities are notoriously hard to assemble.
The one real win: encryption stays out
Parliament did not simply wave the Council’s position through — it amended it. The key amendment: communications to which end-to-end encryption is, has been, or will be applied are excluded from scanning. No breaking it open, no reading before encryption, no backdoor through the side door.
That is not a detail; it is the defensive line. End-to-end encryption is mathematics, and mathematics has no “good guys only” exception: either only the recipient can read the message, or the promise is broken — for everyone, forever. Cryptographers have been putting exactly this into open letters to lawmakers for years.
The Council accepted those amendments on 23 July. The carve-out is now in the operative text: the regulation does not apply to interpersonal communications to which end-to-end encryption is, has been, or will be applied.
What is now in force
The interim derogation that expired in April 2026 is back in force — as a self-standing regulation, not as an extension of the old one. After the 9 July vote the amended text sat with the Council, which had three months. It moved faster: on 23 July it accepted all of Parliament’s amendments by written procedure. The regulation was published in the Official Journal on 28 July and entered into force three days later. It applies until 3 April 2028, or until a permanent CSA Regulation replaces it. There is no retroactive effect for the gap between April and late July.
The European Parliament’s press release of 9 July 2026 records the vote. The Council’s decision is in its press release of 23 July 2026. The binding text is on EUR-Lex.
Why “voluntary” should reassure no one
Protecting children and prosecuting abuse material are vital public responsibilities — nothing here relativises that. The question is not the goal but the tool: “voluntary” scanning means, in practice, that large platforms run private communications through classifiers at scale, with no suspicion required. That inverts a basic principle — suspicion no longer triggers the search; the search goes looking for suspicion. False positives arrive at law enforcement as private photos and family chats, and every scanning infrastructure, once built, invites the next purpose.
Eric Hughes put it plainly in the 1993 Cypherpunk’s Manifesto: “Privacy is necessary for an open society in the electronic age.” Privacy is not about hiding; it is the freedom to decide who gets to read along. The confidentiality of correspondence was never a concession to criminals — it is a precondition of open societies.
Chat Control 2.0 is already waiting
The current fight was only the opening act. In parallel, the permanent CSA Regulation (“Chat Control 2.0”) is still being negotiated. Parliament wants detection orders limited to specific suspects and subject to judicial authorisation; the Council favours “voluntary” suspicionless detection plus risk-mitigation duties that can amount to the same thing. The supposedly final negotiating round on 29 June 2026 collapsed on precisely this point. Under the Irish Council presidency, the next political trilogue is set for 29 September. Whether end-to-end encrypted services could still be pulled in via client-side scanning — searching messages on the device, before encryption takes effect — has narrowed in the trilogue papers. When it adopted the interim rules, though, the Council expressly reserved that the encryption carve-out there does not prejudice its mandate for the permanent law. Former MEP Patrick Breyer maintains a running chronicle.
What remains in your own hands
The cypherpunks did not answer the first round of the Crypto Wars in the nineties with petitions, but with a principle: “Cypherpunks write code.” Laws change with majorities and procedural manoeuvres — well-implemented encryption does not. In practice that means: end-to-end encrypted messengers as the default, treating email as a non-confidential channel where confidentiality matters, and infrastructure where the keys stay with you rather than with a platform that might “voluntarily” scan tomorrow. Set up your communications and data that way, and you are no longer negotiating over who gets to read along.
I am following the talks on the permanent CSA Regulation and will update this article once that file is decided.