The EU’s Child-Protection Vote, Message Scanning, and What It Means for Everyone Using AI

On 9 July 2026, the European Parliament voted on a rule that lets platforms scan people’s messages to find child sexual abuse material. A majority of the MEPs in the room voted against it. It passed anyway.

That is not a contradiction in the reporting. Because of the procedure used, MEPs who were not present were counted as “yes.” So more of the lawmakers actually in the room opposed the measure than backed it, and it survived on the strength of the absent. Suspicionless scanning of unencrypted messages is now law in the EU again, running to April 2028.

I want to walk through this carefully, because it is not really a story about one vote. It is a preview of how the EU intends to govern AI that touches ordinary life — and it lands on far more than compliance officers.

The goal nobody disputes

Start with what everyone agrees on: protecting children online is urgent and real. The rules under debate — often called “Chat Control” — exist to detect and remove child sexual abuse material. Days before the July vote, a Commission special panel on child safety online handed its final report to Commission President Ursula von der Leyen, recommending that platforms should have to prove their services are safe before making them available to children. The Commission plans to build legislation on it after the summer.

So this is not going away. If anything, the child-safety agenda is accelerating. The hard question was never whether to protect children. It is which method actually does, and what that method costs everyone else.

Chat Control 1.0 vs 2.0, in plain words

Keep the two versions apart:

  • Chat Control 1.0 — the temporary rule extended on 9 July. It permits voluntary scanning of unencrypted messages, and — importantly — it exempts end-to-end encrypted services like WhatsApp and Signal. This is the one now in force until 2028. The new pressure point on this track is age verification.
  • Chat Control 2.0 — the permanent CSA Regulation. Still deadlocked after five rounds of talks, the last collapsing on 29 June 2026, resuming in September. The unresolved fight: blanket scanning at platforms’ discretion, or targeted detection ordered by a judge against actual suspects.

The encryption carve-out matters. It means the worst version — forcing every app to break its own encryption — did not happen this round. That is a genuine limit worth noting honestly, not a total defeat for privacy.

What it means for security

Here is where it stops being a niche privacy story and becomes a security story for everyone.

The Council of European Professional Informatics Societies (CEPIS) warned that weakening encryption — or bypassing it through tools like client-side scanning — has consequences far beyond privacy. As one digital-rights expert put it, any requirement that forces a service to bypass its own encryption “fundamentally destroys the security guarantee of end-to-end encryption.” You cannot build a scanning door that only the good guys walk through. A mechanism that reads everyone’s messages to catch a few is, by design, a mechanism that can be turned to other ends.

And the counter-intuitive part: the UN’s human-rights office has argued that mass surveillance can make children less safe — because it weakens security for everyone and diverts resources away from the targeted investigations that actually catch abusers. In other words, the method most likely to feel like “doing something” may be the one that does least, at the highest cost to the whole population’s security.

That is the real tension — and it is not “privacy vs children.” It is “surveillance-by-default vs security-for-everyone, children included.”

The regulation paradox

The EU is often described as over-regulating technology, and in AI it clearly regulates hard — the AI Act bans some practices outright and puts duties on many more. Yet here it is expanding a form of mass scanning that its own security experts say is dangerous and may not even work. More rules, pointed in opposite directions.

That is the paradox worth sitting with. Regulation is not automatically protection. A stack of laws can still leave you less safe if the method inside them is wrong. Deregulation is not automatically freedom either. The useful question is not “more rules or fewer,” but “do these specific rules make people safer, or just more surveilled?”

Where this touches the AI Act — and everyone using AI

Now the connection I cannot stop thinking about.

The EU already has an AI law in force: Article 4 of the AI Act, the AI literacy obligation, live since 2 February 2025. It requires anyone deploying AI to ensure their people have “a sufficient level of AI literacy.”

We usually read that as “learn to use ChatGPT properly.” But literacy cuts both ways. It is also understanding the AI being used on you — the scanner reading your messages, the model deciding what counts as suspicious, the system you never opted into and cannot inspect.

So society is being asked to do two things at once: become literate about the AI it uses, while accepting AI it is not allowed to see operating on its most private communications. This is how AI surveillance gets normalised — not with a dramatic announcement, but through a child-protection vote most people never hear about. The precedent set here — scan everyone by default, trust the system you can’t audit — is the precedent that will shape how AI is used on citizens far beyond messaging.

That affects everyone with a phone, not just businesses. The chilling effect is real: people communicate differently when they suspect they are being read. Trust in the tools erodes. And the same public we are telling to “get AI literate” is being handed the least transparent AI of all.

What it means for a small business

If you run a company of ten to two hundred people, the practical takeaway is not “pick a side on surveillance.” It is this: the EU is regulating AI on several tracks at once, and the one that already binds you is Article 4.

Everyone is watching 2 August 2026, when the AI Act’s Article 50 transparency rules begin to apply. But Article 4 has been law since February 2025. If your team uses AI at work and you have run no structured training, no policy, no record, you already have a live compliance gap — and, not coincidentally, you lack exactly the AI literacy that would let your people reason clearly about news like this vote.

The question I would leave you with

Is scanning private messages by default a price worth paying to protect children — even if security experts say it weakens safety for everyone and may miss the abusers it targets? Or does “AI literacy” mean very little when the most powerful AI in our lives is the one we are forbidden to inspect?

I have a view. What I would rather do is open the debate — because the people and businesses that think clearly about this are the ones who will handle their own AI obligations with their eyes open, instead of sprinting at a deadline.

Start with the free two-minute self-check → it tells you exactly which AI Act obligations apply to your business, then points you to the plain-language Handbook (€35) if you want the full walkthrough. Link: linktr.ee/frelih


This article was written by me and edited with AI — fittingly, the kind of disclosure Article 50 is about. It is general information on the EU AI Act, not legal advice.

Leave a comment