A Law That Passed By Losing
On July 23, 2026, the Council of the EU formally adopted PE-CONS 14/26, reinstating the voluntary CSAM-detection derogation from the ePrivacy Directive that had lapsed on April 3, 2026. The Council approved it by written procedure, 25 member states in favor, one against, one abstention. It followed an unusual sequence in Parliament two weeks earlier: on July 9, a majority of MEPs present — reported at 314 to 276 — actually voted to reject the extension. But second-reading rules require an absolute majority of the full 720-seat chamber, 361 votes, to block a Council position, and every absent or abstaining MEP effectively counts as a tacit yes. The rejection fell 47 votes short. The derogation survived not because Parliament backed it, but because Parliament couldn't muster the numbers to kill it.
That procedural quirk matters for reading what actually happened here: this is less a fresh mandate for message scanning than the default outcome of a chamber that remains deeply split, re-upped until April 3, 2028.
The Carve-Out Is the Real Story
The substantive change in PE-CONS 14/26 isn't the date — it's the scope. The reinstated text excludes end-to-end encrypted services, including WhatsApp and Signal, from the derogation entirely. Only unencrypted number-independent interpersonal communications — DMs on social and gaming platforms, for instance — fall under the voluntary-detection permission. That carve-out was a Parliament condition attached in the July 9 vote, and the Council accepted it rather than reopen a fight it had no votes to win.
This is a meaningfully narrower regime than the client-side-scanning mandate that dominated the "Chat Control 2.0" debate from 2022 onward. The Commission's original 2022 CSA Regulation proposal would have let authorities order even encrypted providers to scan messages client-side before encryption — breaking the security guarantee of end-to-end encryption by design. That mandate is currently dead in the Council's own negotiating position: on November 26, 2025, the Council adopted a "general approach" that dropped mandatory detection orders altogether, after Denmark abandoned the push for mandatory scanning and Germany signaled it would block it. What survives, in both the temporary derogation and the Council's permanent-regulation mandate, is voluntary scanning confined to unencrypted channels.
Steelmanning the Case for Scanning
The strongest argument for reinstating the derogation isn't abstract. Hash-matching against known CSAM, plus some grooming-pattern classifiers, is how the bulk of detection actually happens on the platforms that run it, and providers lost clear legal cover to run those tools for over three months this year. Europol's leadership was blunt that keeping detection running is "vital for the protection of children," and it's a fair point that any compliance gap translates into real abuse material circulating undetected on services that were previously scanning for it. Child-safety advocates also aren't wrong that a derogation extended piecemeal since the original 2021 regulation makes it harder for platforms to invest seriously in better detection tooling.
Why the Encryption Line Still Has to Hold
But a case for voluntary scanning of unencrypted channels is not a case for scanning encrypted ones, and the two get conflated constantly in this debate. The EDPB and EDPS warned as far back as their 2022 joint opinion on the Commission's original proposal that mandatory detection risked making "the interference with confidentiality of communications... the rule rather than remain the exception." That's not a fringe objection — inside the Council, the German government and the German Bar Association raised the same concern formally enough to help sink the mandatory-scanning mandate in November 2025. A scanning layer built into encrypted endpoints is infrastructure whose keys, error rates, and false-positive lists become a target in their own right — and "voluntary" framing today doesn't prevent a future regulation from making it mandatory tomorrow.
What to Watch
The permanent CSA Regulation — meant to replace this patchwork of temporary derogations for good — remains unresolved nearly three years after Parliament first staked out its position in November 2023. Trilogue talks stalled without agreement in mid-2026 and are expected to resume under the incoming Council presidency this autumn. The Council's November 2025 general approach dropped mandatory scanning, but its "risk mitigation" obligations remain broad enough that critics warn they could still pressure encrypted providers to weaken their own security without ever being formally ordered to scan.
That's the fight worth watching, not this one. PE-CONS 14/26 is a two-year bridge, not a settlement. The right outcome in the permanent regulation is the one the Council has now twice backed away from mandating: voluntary, targeted detection of unencrypted material — with end-to-end encryption left structurally intact, rather than "excluded" by a clause a future Council could simply delete.