EU encryption policy

The EU Revived Mass Chat-Scanning Powers Using a Rule That Counts Absent Lawmakers as Yes Votes

MEPs voted 314-276 against renewing CSAM message-scanning powers, but an absolute-majority threshold pushed the measure through anyway.

How 314 No Votes Still Lost People of Internet Research · EU 314 MEPs voted against revival More MEPs opposed reviving the sca… 361 Absolute majority needed to block Absent MEPs count as implicit yes … Apr 2028 New derogation expiry Regulation 2021/1232 is extended f… 2021 Original derogation enacted Regulation (EU) 2021/1232 first cr… peopleofinternet.com
How 314 No Votes Still Lost People of Internet Research · EU 314 MEPs voted against revival 361 Absolute majority needed to block Apr 2028 New derogation expiry 2021 Original derogation enact… peopleofinternet.com

Key Takeaways

On July 9, 2026, the European Parliament brought back a rule letting tech companies voluntarily scan private messages for child sexual abuse material (CSAM) — even though more MEPs present voted to kill it (314) than to keep it (276). The measure survived because the procedure used to reject it required an absolute majority of all 720 members, 361 votes, and Parliament's rules count every absent member as an implicit yes. Opponents needed 361 present-and-voting no votes to stop the extension; they got 314. The scanning derogation, first created by Regulation (EU) 2021/1232, is now valid until April 3, 2028.

How Parliament un-rejected its own rejection

The outcome inverts what Parliament did four months earlier. On March 26, 2026, MEPs rejected the Council's position on extending the same derogation under ordinary second-reading rules — a simple majority of votes cast was enough, and the measure failed. The derogation lapsed on April 3, 2026. Some platforms, including Google, Microsoft and Meta, kept scanning anyway, without clear legal cover, while EU officials warned that doing so exposed them to ePrivacy and GDPR liability (The Record).

Rather than accept that outcome, Parliament President Roberta Metsola's EPP group invoked Rule 170 — an urgency mechanism designed for first-reading files — to force a fresh vote on a second-reading matter, skipping committee scrutiny, on the last sitting day before summer recess when attendance is thinnest (Patrick Breyer). The urgency motion itself passed narrowly, 331-304. That set up the second-reading rejection vote, where the absolute-majority quirk did the rest: 314 against, 276 for, 17 abstaining, 47 votes short of the threshold (The Register).

Even the bill's own rapporteur, Birgit Sippel, called the maneuver "an unfair trick" that risks poisoning ongoing negotiations over the permanent CSAM regulation, Chat Control 2.0. ALDE Party President Svenja Hahn was blunter, calling the result "a disgrace" that "opens the door for mass surveillance of all private communication of our European citizens instead of the targeted fight against child sexual abuse" (Euronews).

The steelman: platforms needed legal certainty, fast

The underlying child-safety problem is real and the case for some legal basis is not manufactured. Providers who voluntarily scan for previously-hashed CSAM generate the overwhelming majority of referrals that feed law-enforcement investigations globally, and Regulation 2021/1232 has been the only lawful basis for that scanning in the EU since 2021. When it lapsed in April, platforms faced an ugly choice: stop scanning and lose detection capability entirely, or continue without a clear legal shield and risk regulatory exposure. From that angle, restoring a voluntary, non-encrypted-messaging derogation — the scanning still does not apply to end-to-end encrypted platforms like Signal, per Parliament's own March 2026 position that any extension "should not apply to end-to-end encrypted communications" (European Parliament press release) — is a narrower, more defensible outcome than either extreme.

Why the process still matters more than the outcome here

But a defensible outcome reached by an indefensible process sets a bad precedent, and that's the real story. Parliament had already ruled on this exact text in March under its normal rules and rejected it. Reopening the file four months later via an urgency procedure written for a different stage of the legislative process, timed to exploit low summer-recess attendance, is not "Parliament changed its mind" — it's Parliament's leadership using a majority-counting quirk to overturn Parliament's own decision without a majority actually voting to overturn it. That distinction should worry anyone who cares about regulatory legitimacy, not just privacy advocates. Rules that are hard to comply with are one thing; rules whose legal basis depends on a procedural inversion nobody voted for are a worse foundation for an industry that needs predictability to invest in EU-facing products.

The encryption carve-out is a genuine win worth banking, and it should not be swept aside for the sake of criticizing the vote. But Chat Control 2.0 — the permanent regulation this derogation is meant to bridge toward — is still under negotiation, and earlier drafts of that permanent regime included mandatory, not voluntary, client-side scanning obligations that would reach into encrypted apps directly. If the EU institutions are willing to use a majority-counting mechanism to push through the low-stakes, voluntary, unencrypted version of this policy, the more consequential fight over mandatory scanning of encrypted platforms deserves a legislative process that can't be won by simply outlasting a quorum.

Sources & Citations

  1. Regulation (EU) 2021/1232 (EUR-Lex)
  2. European Parliament press release, March 2026
  3. The Record: Europe revives law allowing big tech to scan for CSAM
  4. The Register: MEPs fail to prevent Chat Control revival
  5. Euronews: Chat Control 1.0 passed through the back door
  6. Patrick Breyer: Procedural trick pushes Parliament towards capitulation