A vote that lost still won
On July 9, 2026, the European Parliament held a vote on whether to reject a Commission proposal extending the EU's voluntary CSAM-scanning derogation — the exemption that lets messaging and email providers scan private communications for known child sexual abuse material without falling foul of the ePrivacy Directive. A majority of MEPs who cast a vote wanted to kill the extension: 314 voted to reject it, against 276 who wanted it kept. By ordinary arithmetic, rejection wins.
It didn't. Under the second-reading rules governing this file, blocking a Council position requires an absolute majority of the full Parliament — 360 votes, half of all 720 seats plus one — not a majority of those present. With 112 MEPs absent, the rejection motion fell 46 votes short of that threshold, so the extension passed by procedural default: no substantive vote in favor, just a failure to muster enough votes against (EDRi). The derogation now runs to April 3, 2028, two years beyond its original cutoff (European Commission proposal COM(2025) 797).
The case for the carve-out
Before litigating the process, the substance deserves a fair hearing. This is the second time Parliament has flipped on this question in under four months. On March 26, 2026, MEPs rejected the same kind of extension outright, 311–228 with 92 abstentions, and the prior derogation lapsed on April 3 (European Parliament Legislative Observatory). In the weeks that followed, providers including Meta paused voluntary scanning in the EU, and the U.S. National Center for Missing & Exploited Children recorded a measurable decline in European referrals to its CyberTipline. Known-CSAM scanning is comparatively narrow: it matches file hashes against a database of already-identified abuse images, not open-ended content analysis, and it has a documented record of surfacing real cases. Lawmakers who voted to keep the carve-out alive were not wrong that a lapse has a measurable child-safety cost.
Why the mechanism still matters
That argument justifies the underlying policy of allowing voluntary hash-matching to continue. It does not justify how Parliament got there. Euronews's framing — that the extension "passed through the back door" — is not editorializing so much as a description of the sequence: after the March rejection, Parliament President Roberta Metsola reopened the file and routed it to the Council at the start of the summer recess, when assembling the 360 votes needed to reject it again proved harder, and the July vote proceeded under an urgency procedure that bypassed the usual committee review (Euronews).
"It's the same approach to normalising the erosion of privacy that we've seen before... a sweeping power justified by an urgent-sounding purpose, then quietly normalised." — Lyudmyla Kozlovska, Open Dialogue Foundation
A legislature is entitled to require supermajorities for certain actions — that's a legitimate constitutional design choice found across democracies. What's harder to defend is a design where a numerical majority against a measure fails to stop it, on a question this consequential, decided under an accelerated procedure with over 100 members absent. Whatever one thinks of the underlying scanning policy, the process invites exactly the "back door" reading it's now getting, and that erodes trust in EU tech lawmaking generally — trust the Commission will need for the much bigger fight ahead.
The fight that actually matters starts in September
Chat Control 1.0 is voluntary and narrow. Chat Control 2.0 — the permanent CSA Regulation the Commission first proposed in 2022 — is neither. Its more aggressive drafts would impose mandatory detection duties on providers, including client-side scanning that inspects message content on-device before encryption is applied. Proponents argue this technically preserves end-to-end encryption because the ciphertext itself is never touched. The technical and civil-society consensus, echoed by groups like EFF, is that scanning every message before it's encrypted defeats the purpose of encryption regardless of where the inspection happens: it requires building a permanent, exploitable inspection layer into every private conversation, one that repressive governments and criminals alike would eventually find a way to target.
Trilogue negotiations on that permanent regulation broke down without agreement in late June and resume in September, with Parliament so far holding a floor against suspicionless, mass-scanning duties. That is the fight worth watching. A temporary, voluntary, hash-based carve-out — however clumsily extended — is a defensible bridge measure for known material. A permanent mandate to inspect the content of every private message, encrypted or not, is a different category of law, and the procedural shortcuts used in July are a preview of the pressure Parliament will face to wave it through in September too.
The proportionate path
People of Internet's position is not anti-child-safety; it's pro-precision. Support narrow, auditable, voluntary hash-matching against known CSAM databases, sunset it on a real timeline, and route any expansion through ordinary legislative procedure — not urgency votes timed to recess. Oppose mandatory client-side scanning and open-ended AI content classifiers on private messages, which trade a marginal, unproven detection gain for a permanent surveillance capability applied to everyone. September's trilogue is where that line gets drawn or erased.