How can we protect children from online sexual predators? With this aim in mind, the European Union has revived a proposal that had already been rejected earlier this summer. But what does this proposal involve? (Photo: Shutterstock)

How can we protect children from online sexual predators? With this aim in mind, the European Union has revived a proposal that had already been rejected earlier this summer. But what does this proposal involve? (Photo: Shutterstock)

The European Parliament voted on 9 July to reinstate, under certain conditions, the framework allowing online platforms to voluntarily detect child sexual abuse material. However, it excluded end-to-end encrypted communications. Behind the debate over “Chat Control” lie three very different technologies.

On Thursday, 9 July, the European Parliament did not adopt the final version of the future regulation commonly known as “Chat Control”. Instead, it voted on a temporary measure intended to allow platforms to resume certain voluntary operations aimed at detecting child sexual abuse.

The previous framework expired on 3 April 2026. The Council of the European Union proposed extending it until 3 April 2028. A motion to reject the Council’s position outright received 314 votes to 276, but an absolute majority of 360 MEPs would have been required. Parliament nevertheless adopted several amendments, the most significant of which excludes communications to which end-to-end encryption “is, has been or will be applied”. The text now returns to the Council, which has three months to decide whether to accept these amendments. It is therefore not yet final.

Two texts that are often confused

The term “Chat Control” actually refers to two separate legislative proposals.

The 9 July vote concerns a temporary derogation from EU rules protecting the confidentiality of communications. It would allow providers that choose to do so to detect, report and remove certain child sexual abuse material. The mechanism is entirely voluntary.

A second, permanent regulation has been under negotiation since 2022. The Commission’s original proposal provides for risk assessments and the possibility of imposing targeted detection obligations on certain services. Under this regulation, a platform could be required to search for specific content or behaviour on the basis of an order issued by a competent authority.

This distinction is fundamental. The July vote does not create a general obligation to scan every conversation taking place in Europe. Rather, it determines under what conditions platforms may voluntarily resume analyses that would normally be incompatible with the rules set out in the ePrivacy Directive.

Method 1: recognising a familiar image

First method: recognising an image that is already known

The most reliable technique does not attempt to determine whether a photograph depicts abuse. Instead, it checks whether the photograph matches content that has already been identified.

A system such as PhotoDNA converts an image into a digital fingerprint known as a perceptual hash. This fingerprint remains recognisable even if the photograph has been resized, recompressed or slightly altered. If it matches the fingerprint of a previously verified child sexual abuse image, the file is flagged. PhotoDNA does not identify a person or an object, and its fingerprint cannot be used to reconstruct the original image.

This method is highly accurate, but it can only detect content that has already been catalogued. A completely new image will produce no match.

Second method: asking an AI to evaluate an image

To detect previously unknown content, platforms rely on classifiers based on artificial intelligence (AI). The model analyses an image and assigns it a score – for example, the probability that it contains nudity or belongs to a category of child sexual abuse material. It does not retrieve a previously known file. Instead, it generates an estimate.

The distinction matters. Hashing determines whether a given image matches a file that is already recorded in a database, whereas AI assesses whether an image displays characteristics that appear suspicious. The latter inevitably involves greater uncertainty. A family photograph, a medical image or a work of art may be incorrectly classified. Human review therefore remains essential before any report is sent to the authorities. The European Commission itself distinguishes between known content, new content and grooming as three technically distinct challenges.

Method three: analysing the conversation

Grooming detection aims to identify attempts to sexually manipulate a child. The system may analyse the text itself, the sequence of messages or certain behavioural patterns, such as requests for intimate photographs, the gradual sexualisation of the conversation, repeated moves to different platforms or frequent contact with minors.

Rather than searching for a file, it searches for a conversational pattern. This is the most intrusive method because it requires analysing the meaning or structure of private exchanges. The Council’s text explicitly acknowledges that the technologies involved may scan images, text or traffic data using hashes, classifiers and AI.

Where the scan is carried out makes all the difference

When messages are not protected by end-to-end encryption, a platform can analyse them on its own servers. With WhatsApp, Signal or any other end-to-end encrypted messaging service, however, the server normally receives only unreadable data. Only the sender’s and recipient’s devices hold the keys required to decrypt the messages.

To analyse the message nonetheless, the inspection must take place on one of those devices. This is known as client-side scanning. The encryption used during transmission may technically remain intact. However, the message has already been inspected before it is encrypted, and the software may then transmit a report if necessary. As a result, confidentiality no longer depends solely on encryption. It also depends on what the application is permitted to do on the user’s device.

What Parliament’s amendment would change

By excluding end-to-end encrypted communications, Parliament aims to prevent the temporary derogation from becoming a legal basis for scanning protected messages, including where the analysis would take place on the user’s device.

Platforms would still be able to voluntarily search for content on services where they have access to data in plain text, such as messaging services that do not use end-to-end encryption, certain cloud storage services or publicly accessible files. They could also continue offering local safety features that alert only the user without automatically transmitting the results.

The political line drawn by the vote is therefore more nuanced than the expression “Chat Control” might suggest. The issue is not simply whether child sexual abuse material should be tackled. It is about determining which technology may examine which type of content, where that examination may take place and what consequences it may have for users. Hashing a known image, an AI’s probabilistic assessment of an image and the analysis of an entire conversation do not offer the same level of reliability, nor do they entail the same degree of intrusion.