A rejection that wasn't enough
On July 9, 2026, the European Parliament reinstated the ePrivacy Directive derogation that lets platforms including Google, Microsoft and Meta voluntarily scan private messages for child sexual abuse material (CSAM) — the scheme critics call Chat Control 1.0. A motion to kill the measure actually won the count: 314 MEPs voted to reject the Council's position, versus 276 who wanted to keep it, with 17 abstentions. But under the second-reading procedure used here, rejecting a Council position requires an absolute majority of the chamber's full membership — 360 votes at Parliament's current composition — not merely a majority of those who show up (European Parliament press release, 9 July 2026). Because absent MEPs are effectively counted as votes to keep the status quo, the rejection fell short and the derogation survived a vote it numerically lost (The Register).
The reinstated rule permits providers to voluntarily detect, report and remove CSAM in private communications through April 2028 (The Record), reviving a scheme first introduced in August 2021 that lapsed on April 3, 2026, when Parliament couldn't agree on renewal terms (The Register). Platforms kept scanning during the three-month gap anyway, but without clear legal cover — an uncomfortable position for providers and users alike, since informal continuation carries none of the reporting obligations a formal derogation at least nominally imposes.
The case for reinstatement
Steelman it first: CSAM circulates overwhelmingly through mainstream messaging and cloud storage services, not just the internet's dark corners, and voluntary hash-matching against known CSAM databases has generated the large majority of the EU's CSAM detection reports since providers began doing this at scale. A legal void doesn't reduce demand for child safety tools; it just strips away the audit trails and proportionality conditions a formal law would otherwise require. Parliament President Roberta Metsola's push to fast-track reinstatement reflected a genuine risk: platforms operating without authorization either over-scan without accountability or stop scanning altogether, and neither outcome protects children.
Why the mechanism should still worry pro-speech observers
That case doesn't make the procedure defensible. Parliament had already rejected this same continuation once, under ordinary conditions, only months earlier — a point critics raised loudly when the leadership brought it back via emergency second-reading procedure on the eve of summer recess (The Record). Reviving a measure through an absolute-majority mechanism that functionally converts absence into consent, timed for a low-attendance session, is a legislative maneuver optimized to produce an outcome the chamber had already declined to endorse on the merits. That is a governance problem independent of whether Chat Control 1.0 is good policy: a rule that can be revived by procedural attrition rather than persuasion invites the same maneuver against any measure a determined minority wants to force through — a precedent that should worry anyone who wants durable, broadly legitimated internet regulation rather than rules that flip with each low-turnout vote.
The substantive scope, at least, stayed bounded. MEPs also adopted language excluding "communications to which end-to-end encryption is, has been or will be applied" from the scanning regime (European Parliament press release, 9 July 2026) — meaning Signal, WhatsApp and similarly encrypted-by-default services stay outside its reach, as they were under the original 2021 rule. What was reinstated, in other words, is authorization to keep scanning services that were never end-to-end encrypted — largely cloud storage, email attachments and unencrypted messaging — not a mandate reaching into encrypted channels.
What this signals for the pending fight
The real fight is still ahead. This derogation is a bridge, not a settlement: it buys time until 2028 while Parliament and Council negotiate the permanent CSAM regulation — "Chat Control 2.0" — where the encryption question remains genuinely contested rather than resolved, and where earlier drafts proposing client-side scanning before messages are encrypted drew sustained opposition from privacy regulators and several member states. The encryption carve-out MEPs insisted on this week is a meaningful marker heading into that fight: it tells the Council that any permanent regulation reaching into encrypted communications will face resistance as determined as the one that killed the extension attempt in March.
Proportionate regulation should mean scanning tools that are narrowly scoped, auditable and subject to judicial oversight — not an indefinite default produced by whichever side manages the parliamentary calendar better. The EU landed closer to that outcome this week, but by accident of absolute-majority math rather than by design. Lawmakers on both sides of this debate should take the lesson that legitimacy earned through persuasion holds up better than legitimacy manufactured through procedure — because the next fight, over the permanent regulation, will be decided on the merits, and neither side should want to win it the way Chat Control 1.0 just survived.