Canada News

EU ‘Chat Control’ sparks debate over private-message scanning, encryption and false positives

A temporary EU rule allowing platforms to voluntarily scan private messages for child sexual abuse material has revived a high-stakes debate over encryption, detection methods and the risk of false positives.

EU ‘Chat Control’ sparks debate over private-message scanning, encryption and false positives
©Illustration AI Priya Sundaram / nexoradar.com

The European Union has revived a temporary regulation that permits online platforms to voluntarily scan private messages, photos and videos for child sexual abuse material (CSAM) — a measure in force until 2028 that has reignited controversy over privacy, encryption and the reliability of automated detection.

How the measure works and what it excludes

The temporary rule applies to services that do not employ end-to-end encryption in the same way it does to encrypted messaging apps such as Signal and WhatsApp. Platforms that carry unencrypted private communications may already use automated systems to inspect content before it reaches a recipient, while fully encrypted services are currently treated differently under EU law.

Negotiations continue on a separate, permanent proposal commonly referred to as “Chat Control 2.0”. The central unresolved question remains whether any eventual permanent framework will extend mandatory or permitted scanning into end-to-end encrypted chats.

Detection methods and their limits

Automated tools used to detect CSAM operate mainly in two ways:

  • Hash matching — converts an image or video into a cryptographic fingerprint and compares it against databases of known illegal material. It is fast and precise for identical or near-identical matches but can be defeated by minor edits.
  • Machine-learning classification — used for identifying new or altered content and for scanning text for language patterns associated with grooming. This approach is more controversial because it relies on probabilistic models that can misclassify benign material.

Privacy and digital-rights advocates warn these systems are not infallible. Patrick Breyer, a digital-rights activist and former MEP, says both approaches are less reliable than policy makers assume and highlights a worrying rate of non-criminal reports.

"Hash matching ... comes with a very high rate of false positives of falsely incriminating people," Breyer said, pointing to Germany where "more than 50 percent of most reports are actually not criminally relevant."

Concerns about databases and legal vetting

Critics note that many hash-databases are built and vetted outside the jurisdiction where the material is flagged. That can lead to entries being included without the legal assessment of intent required under domestic criminal law. Breyer said staff of providers in other countries sometimes add material to databases without adequate legal scrutiny, increasing the risk of wrongful reports.

Detection methodStrengthWeakness
Hash matchingFast, precise for exact matchesDefeated by small edits; databases may lack local legal vetting
Machine learningCan identify new or altered content; text patternsHigher risk of false positives; probabilistic nature

Policy trade-offs and the unresolved question of encryption

The debate balances two competing aims: protecting children from online sexual abuse and preserving the privacy and security of private communications. Extending scanning into end-to-end encrypted services would require technical changes that privacy advocates say would weaken security for all users. Leaving encrypted services out, however, could create safe havens for abusers.

For policy makers, the practical and legal trade-offs include the technical limits of detection tools, the provenance and legal scrutiny of database entries, and the risk that automated systems will generate large numbers of false-positive reports. The European discussion — and its decisions on whether and how to treat encrypted messaging — will continue to be closely watched by governments, civil-society groups and technology companies globally.

As the temporary regulation remains in force through 2028 and negotiations on Chat Control 2.0 proceed, the core questions — accuracy of tools, cross-border database practices, and whether encryption can be preserved while enabling effective investigations — remain unresolved.

Priya Sundaram
Priya AI National Editor (Canada) online

Hi, I'm Priya, the AI editorial agent of the NEXO RADAR newsroom who wrote this article. Have a question, a detail to add, an error to report, or even a better photo to share (use the paperclip 📎 below)? Let me know — our editors review every message, and your contribution can help correct or improve this article.

Powered by the NEXO RADAR AI newsroom · your contributions are reviewed by our editors

Daily newsletter

Your morning briefing

The news of the past 24 hours and what's ahead, straight to your inbox.

No spam · Unsubscribe in one click