Back to Blog
Cybersecurity — May 20, 2026
Cybersecurity 6 min readMay 20, 2026

EU Chat Control 2.0 Just Passed: The End of Private Messaging in Europe?

The European Council approved Chat Control 2.0 on May 20, 2026. Every messaging app operating in the EU must now scan messages before encryption — including WhatsApp, Signal, and iMessage. Here's what actually changed and what you can do.

After three years of contested legislative battles, Chat Control 2.0 cleared its final vote in the European Council on May 20, 2026. The regulation — officially titled the "Child Sexual Abuse Regulation" — requires all messaging platforms to implement client-side scanning (CSS) of every message sent over their services, including those protected by end-to-end encryption. Privacy experts, cryptographers, and civil liberties organisations have called it the most significant attack on digital privacy in the EU's history.

What Chat Control 2.0 requires, in plain terms

  • All messaging apps with EU users must scan messages before encryption is applied
  • Scanning uses AI classifiers to detect flagged content categories
  • Flagged messages are automatically reported to a centralised EU database
  • Applies to text, images, video, and audio content
  • No opt-out mechanism for end users — scanning is mandatory for the platform
  • Non-compliant services face fines of up to 6% of global annual revenue and EU market bans

Why Cryptographers Say This Breaks Encryption

End-to-end encryption means only the sender and recipient can read a message — not the platform, not governments, not anyone in between. Chat Control 2.0 does not technically "break" the encryption algorithm. Instead, it mandates scanning before encryption is applied — directly on your device, before the message is sent.

This is called client-side scanning (CSS). Cryptographers from MIT, Cambridge, and the Chaos Computer Club published a joint paper in 2024 explaining why CSS is functionally indistinguishable from a backdoor: it accesses plaintext content on your device, creates a report of that content, and transmits that report to a third party — regardless of whether the underlying transmission is encrypted.

From a practical privacy standpoint, the result is the same: the platform can read your messages before you send them.

Which Apps Are Affected?

Any messaging service with more than 10,000 EU users is subject to the regulation. This includes:

WhatsApp
iMessage (Apple)
Signal
Telegram
Facebook Messenger
Instagram DMs
Viber
Discord

Signal has already stated it will exit the EU market rather than implement CSS. Apple has not confirmed its response. WhatsApp (Meta) has historically complied with regulatory requirements in major markets.

The Broader Privacy Rollback

Chat Control 2.0 does not exist in a vacuum. It's part of a pattern of legislation across major democracies that has systematically eroded the technical foundations of digital privacy over the past three years:

🇬🇧 United KingdomOnline Safety Act

Ofcom can require ISPs to deploy DPI and platforms to scan encrypted content. Enforcement began this week.

🇺🇸 United StatesRESTRICT Act 2.0

Expanded government authority to compel US-based platforms to provide access to user communications in national security investigations.

🇦🇺 AustraliaAssistance and Access Act

Tech companies can be required to build capabilities to access encrypted communications. No public disclosure required.

🇪🇺 European UnionChat Control 2.0

Client-side scanning of all messages including E2E encrypted content. Approved May 20, 2026.

What Can You Actually Do?

Chat Control's client-side scanning happens on your device — a VPN cannot prevent scanning that occurs before data leaves your app. But a layered privacy approach still makes a significant difference to your overall exposure:

01

Use messaging apps not subject to EU jurisdiction

Apps developed outside the EU that don't operate EU-registered entities may exit rather than comply. Monitor Signal's response — they have committed to leaving the EU market rather than implementing CSS.

02

Use a VPN to protect your network traffic

While a VPN can't stop CSS within an app, it encrypts all other network activity — your ISP, DNS queries, browsing, and non-CSS-compliant communications remain private.

03

Route traffic through non-EU VPN servers

A VPN server outside the EU routes your traffic through non-EU infrastructure. Combined with apps that exit the EU market, this reduces your exposure significantly.

04

Audit which apps you actually need

Delete messaging apps you don't use. Each app you remove is one fewer scanning system operating on your device.

Frequently Asked Questions

What is EU Chat Control 2.0?

A regulation requiring all messaging apps operating in the EU to implement client-side scanning of messages — including end-to-end encrypted ones — before sending. Flagged content is reported to a centralised EU database.

Does Chat Control 2.0 break end-to-end encryption?

Technically the encryption itself isn't broken — but client-side scanning accesses message content before encryption is applied, on your device. Security experts argue this is functionally equivalent to a backdoor.

Can a VPN protect me from Chat Control 2.0?

A VPN protects your network traffic but cannot prevent in-app client-side scanning. However, combined with privacy-focused apps outside EU jurisdiction, a VPN significantly improves your overall privacy posture.

Will Signal leave the EU because of Chat Control?

Signal has publicly stated it will exit the EU market rather than implement client-side scanning. As of the time of writing, no final timeline has been confirmed.

Governments are dismantling digital privacy. Layer your defences.

SoloFlight VPN encrypts your network traffic and keeps zero logs — so your browsing, DNS queries, and non-app communications stay private, regardless of what legislation passes.