SOUL IA Animated LogoSOUL IA
← BlogCurrent affairs

Chat Control: the EU wants an AI to read your messages

Jorge Marín Pérez·Jul 8, 2026·8 min
Chat Control: the EU wants an AI to read your messages

A few days ago, like half the country, I got a forwarded message that started with «URGENT» and warned that tomorrow Brussels would pass the most censorious law in memory: access to ALL your conversations, von der Leyen and the globalists wiping out privacy in one stroke, an unprecedented maneuver.

Almost everyone who sent it to me had the same question: is this true?

And here is the mess. The answer is not yes or no. That message mixes real, serious things with exaggerations and some flatly false claims. And when you mix the two, the worst happens: anyone who knows the topic tears it apart in two sentences, and the genuinely important issue ends up taken seriously by no one.

We put AI inside companies for a living. We know what a model can and cannot do when you set it to read millions of messages. So here is what is actually going on, with the sources in front of you, and why someone who does this for a living is paying close attention.

What Chat Control is (and why there are two)

«Chat Control» is not the official name of anything. It is what critics call a European Commission proposal from May 2022, the Regulation to prevent and combat child sexual abuse, known in Brussels as the CSAR or CSA Regulation.

The underlying goal is good and no one disputes it: going after child sexual abuse material circulating online. The problem is the HOW. In its original version, the regulation would force messaging platforms to scan everyone's private messages looking for that material. Including end-to-end encrypted ones, the messages only you and the person you write to are supposed to be able to read.

And here is the first thing to be clear about, because it is exactly where the hoax gets tangled. There are TWO Chat Controls:

  • Chat Control 1.0. A temporary rule in place since 2021. It forces no one: it only allows platforms like Meta or Google to voluntarily scan for that material and report it. It is a permission, not an obligation.
  • Chat Control 2.0. The new regulation, the one being fought over since 2022. This one could FORCE scanning. And it is still under negotiation, not approved.

Almost all the viral panic confuses the two. When you read «tomorrow it passes and they will read everything», they are usually mixing a move on the voluntary version with the fear of the mandatory one.

What has really happened, in order

Here is the timeline with the real dates, the best vaccine against the hoax:

  • May 2022. The European Commission proposes the CSAR regulation.
  • July 2022. The EU's two data protection supervisors (EDPB and EDPS) publish a scathing joint opinion: they call for removing «grooming» detection, warn that forcing decryption is disproportionate, and that giving general access to message content touches the very essence of fundamental rights.
  • November 2023. The European Parliament sets its position and REJECTS mass scanning of private and encrypted communications. In committee it passes with 51 votes in favour, 2 against and 1 abstention.
  • 2024 and 2025. The Council of the EU (the governments) gets stuck again and again. Presidency after presidency tries and fails to reach a majority.
  • November 2025. The Council finally agrees a negotiating position. But to get there it had to REMOVE the obligation to scan: in that version detection is voluntary again. That kicks off the three-way negotiations in December 2025.
  • March 2026. Parliament votes AGAINST extending the voluntary version (Chat Control 1.0) again. That temporary permission expires on 3 April 2026.
  • 2 July 2026. The Council moves to reinstate that expired temporary voluntary measure, proposing to extend it until April 2028.
Chat Control timeline 2022-2026: Commission proposal, data protection supervisors joint opinion against it, Parliament rejecting mass scanning, Council stalling, position without mandatory scanning, voluntary regime expiring and the Council move of 2 July 2026
A four-year standoff: every time mandatory scanning advances, someone pulls its teeth

That is the real picture today. There is no law that «tomorrow» plants a spy in your WhatsApp. There is a long, very much alive fight, in which mandatory scanning keeps being negotiated and keeps getting its teeth pulled, but keeps coming back.

The hoax, point by point

«Brussels passes it tomorrow.» False. Mandatory scanning is still under negotiation. What is moving these days is the voluntary version, which is another thing.

«They will have access to ALL our conversations.» Exaggerated. Not even the toughest version taps your phone like in the movies: it would be an automated system looking for matches with illegal material, not an official reading your voice notes. Still extremely serious for privacy, but not «they read everything».

«Von der Leyen and the globalists.» Distorted. The 2026 push did not come from von der Leyen or the Commission, but from Roberta Metsola, President of the Parliament, who reopened the process through an urgent procedure right before the summer break. That part is real, and some diplomat called it «unprecedented». But it is a parliamentary move, not a movie-villain plot.

The European Parliament hemicycle in Strasbourg during a plenary session
The Strasbourg hemicycle, where Parliament stopped mass scanning in 2023 (photo: Diliff, Wikimedia Commons, CC BY-SA 3.0)

«It was already voted down by MEPs.» Half true. Parliament did reject extending the voluntary version in March 2026. What the hoax does is glue that real fact to the fear of the mandatory version, as if they were the same.

Now the part that really is scary (and it is about AI)

To scan the messages of hundreds of millions of people you need AI. And AI, for this, is not magic. It works in two ways, and both have holes.

Two people look up at a wall covered in dozens of surveillance cameras
To watch everything you need a machine that looks at everything. And machines get it wrong (photo: Matthew Henry, CC0)

Matching against known material (perceptual hashing). A kind of fingerprint is taken from each image and compared against a list of fingerprints of already-flagged illegal material. Sounds clean, until you see what happened in 2021: Apple built such a system, NeuralHash, and within days several researchers showed you could craft innocent images that produced the same fingerprint as an illegal one. You could make someone trigger a false alarm with a normal photo. Apple ended up burying the project.

Detecting new material and «grooming» with AI classifiers. This is even more slippery, because the model does not compare against a list: it JUDGES. It decides whether a photo or a conversation «looks» suspicious. And that is where the numbers become a problem.

More than 500 cryptographers and scientists signed a letter in 2025 warning that this detection is technically unfeasible at this scale. An example from that letter: even with a false positive rate of 0.1% (far better than any real detector achieves today), and even scanning just 1% of WhatsApp messages, that would be 1.4 million false alarms a day.

Funnel from the 500 scientists letter: 140 billion daily WhatsApp messages, only 1% scanned is 1.4 billion, with a 0.1% false positive rate that is 1.4 million false alarms a day
The math from the scientists letter: even with a detector better than any real one, 1.4 million innocent people flagged every day

A million and a half ordinary people, every day, flagged as suspects by an algorithm. A beach photo of your kids sent to grandma, a conversation with your partner, a joke. The system does not understand context. It only scores.

And for that scanning to happen, something has to break. End-to-end encryption works precisely because NO ONE in the middle can read the message. To scan it before encrypting it (client-side scanning) you have to put an eye inside your own phone, before the lock closes. And a lock with a hole for the good guys is a lock with a hole: others can find it.

Signal, the encrypted messaging app, said it bluntly through its president, Meredith Whittaker: if they are forced to build a surveillance system into Signal, they will leave the European market.

«In the UK they arrest thousands over a message», is it true?

The figure is real. The Times revealed in 2025 that in 2023 there were 12,183 arrests in the UK over offensive online messages, under laws like the Communications Act. That is about 33 a day. And in a July 2025 House of Lords debate they spoke of more than 30 arrests a day, a 121% increase since 2017. The data part is true and if anything an underestimate.

Yearly UK arrests over online messages: about 5,500 in 2017 versus 12,183 in 2023, a 121% increase, about 33 a day
The hoax stat that is actually real: 12,183 arrests in 2023, as revealed by The Times

Now the honesty from the other side: the viral message ended by saying they arrest over messages while «turning a blind eye to foreign murderers or rapists». That is no longer data, it is a political opinion shoehorned in. That the UK arrests many people over what they write is a real free-speech debate. Mixing it with immigration is another matter, and it does not come from the data.

What is worth keeping: when you give a State the power to police what people write, it gets used. Not in theory, in practice, and by the thousand.

Two London Metropolitan Police officers watch a protest camp
Metropolitan Police officers in London: over 12,000 arrests a year for online messages (photo: James Mitchell, CC BY-SA 2.0)

Why people who build AI are telling you this

It might seem odd that someone who installs AI for a living warns you about the dangers of AI. I see it the other way: precisely because I am inside, I know where the seams are.

When we build a system for a client, we spend days fighting the false positives of ONE specific, narrow task. And they still slip through. Now imagine that same thing, but judging the privacy of 450 million Europeans, with no context and no one reviewing case by case. It is not that it is hard: it is that the technology, today, is not good enough to do it right.

AI is a brutal tool when you set it on a specific problem and watch it closely. It is a terrible idea when you let it loose to watch everyone at once and decide who is suspicious. And the precedent is what matters: if scanning messages is accepted today for this, tomorrow the same pipe serves the next thing.

The goal, protecting children, is sacred and no serious person disputes it. The question is whether the way to get there is turning everyone's phone into a listening post. And to that question, as someone who knows what AI can and cannot do, my answer is no. Not because we do not want to protect anyone, but because this protects no one and breaks something that belongs to everyone.

Sources

Verified primary sources, no middlemen:

Council of the EU: reinstating the interim measure (2 Jul 2026)

Council of the EU: negotiating position (26 Nov 2025)

European Parliament: effective measures, no mass surveillance (2023)

EDPB-EDPS Joint Opinion 04/2022

Open letter from 500+ scientists (2025)

Signal: Meredith Whittaker's letter (2025)

Fact-check in Spanish (Maldita.es)

Written by

Jorge Marín Pérez · Founder of Soul IA

I help SMEs automate their customer service and processes with AI, from Málaga. What I write here comes from what we build every week for real businesses.

About Soul IA →LinkedIn →

Want to know what you could automate in your business?

Talk to Soul IA