A Vote Parliament Lost by Winning
On July 9, 2026, the European Parliament held a vote that, on its face, went against mass message scanning: 314 MEPs voted to reject the Council's position reinstating the ePrivacy derogation known as Chat Control 1.0, versus 276 who voted to keep it alive. Opponents won the room. They lost the law. Under the ordinary legislative procedure set out in Article 294 of the Treaty on the Functioning of the European Union, a second-reading Parliament can only reject a Council position with an absolute majority of the chamber's full membership — 361 votes out of 720 seats, regardless of who shows up. Absent members are not neutral; they function as automatic yes votes for the status quo. Opponents fell roughly 47 votes short, and the derogation survived by default (The Register; The Record).
The result: Regulation (EU) 2021/1232, which lets messaging and webmail providers voluntarily scan for known child sexual abuse material (CSAM) and report it, now runs until April 3, 2028 — a two-year extension the European Commission formally proposed on December 19, 2025 (EUR-Lex, COM(2025)797). The underlying regime dates to August 2021 and has already been extended once before, to April 2026, before lapsing that April when Parliament couldn't agree on renewal terms (EUR-Lex, Regulation 2021/1232).
The Case the EU Isn't Wrong to Make
It's worth stating the strongest version of the case for renewal, because it's not frivolous. The derogation is voluntary, not a mandate: platforms that already run hash-matching and classifier-based CSAM detection — a practice that predates this regulation and generates the referrals that feed NCMEC and EU law enforcement — needed a clear legal basis to keep doing so without falling foul of the ePrivacy Directive's confidentiality-of-communications rules. When the law lapsed in April, providers reportedly kept scanning anyway, but without the legal cover Brussels itself had told them they needed, creating exactly the kind of ambiguity that chills good-faith compliance (The Record). A bridge measure that keeps existing, voluntary detection running while the EU finishes negotiating a permanent CSAM Regulation is a defensible stopgap, not obviously an assault on privacy.
Crucially, this is not the mandatory-scanning, encryption-breaking "Chat Control 2.0" that privacy advocates have spent years fighting. Recital 25 of the original 2021 regulation states plainly that nothing in it should be read as "prohibiting or weakening end-to-end encryption," and reporting on the July 9 vote confirms encrypted services like Signal remain outside its scope (The Record; EUR-Lex). Companies choose whether to scan; users who want unscanned communications can and do choose E2EE platforms instead. That's a meaningfully different proposition than a backdoor mandate.
Where the Real Damage Was Done
What should worry a pro-innovation, pro-speech publication is not primarily the substance of this extension — it's the method. Parliament had already rejected essentially the same extension once, by normal majority vote, in March 2026. Rather than accept that outcome, proponents brought the identical policy back on the eve of summer recess and ran it through a procedural channel where a losing coalition on the floor still wins if enough colleagues are simply absent. Critics, including in a blog post cited by The Record, called the maneuver an "unprecedented" and "highly politicised procedural" tactic, pushed by European Parliament President Roberta Metsola's office to get the measure over the line before the chamber emptied out for the summer (The Record).
That precedent cuts both ways, and that's the problem. A mechanism that can resurrect a policy MEPs voted down by exploiting absenteeism is a mechanism that works regardless of whether the underlying policy is sympathetic. CSAM detection is About as sympathetic a use case as EU tech policy offers — which is exactly why it's a dangerous test case for the tactic. The next use of an absolute-majority override to steamroll a floor majority may not come wrapped in child-protection framing, and the institutional habit, once normalized, doesn't self-limit to good causes.
What to Watch Next
The encryption fight isn't over — it's deferred. The permanent CSAM Regulation, the successor framework this derogation is bridging toward, is still being negotiated in Council and Parliament, and earlier drafts of that proposal have included detection orders that could reach encrypted services. This July vote extended the voluntary, non-encrypted status quo; it did not resolve whether Brussels will eventually mandate scanning that reaches Signal and WhatsApp. Publications and platforms that care about encryption should treat this extension as a procedural warning shot, not a verdict on the bigger fight still to come.
"Highly politicised procedural efforts" — the characterization of the maneuver by critics cited in reporting on the vote.
For now, the operative fact is narrower and more mundane than headlines suggest: a voluntary, encryption-excluded scanning regime got a two-year renewal nobody on the floor actually voted for in the affirmative majority sense — because under EU procedural rules, showing up to abstain and staying home produce the same result.