The European Union has revived the interim “Chat Control 1.0” framework, preserving a legal basis for online services to voluntarily scan private communications for child sexual abuse material and grooming activity. After a European Parliament vote failed to secure the absolute majority needed to block the measure, Regulation (EU) 2021/1232 remained in force, allowing participating email, chat, gaming, and social networking platforms to detect, report, and remove suspected abuse-related content without a separate warrant for each account. The renewed regime is set to remain valid until 2028 or until a permanent successor, widely referred to as Chat Control 2.0, is adopted.
The move has reignited a broader fight over end-to-end encryption and lawful access, as researchers and security experts warn that many government proposals to limit encrypted services misunderstand how encryption is deployed in practice. A newly highlighted academic paper argues that end-to-end encryption is not confined to messaging apps but is embedded throughout modern infrastructure, including TLS, SSH, VPNs, and Zero Trust architectures, and says broad restrictions would carry significant consequences for cybersecurity, commerce, and government operations. While the current EU framework does not extend to end-to-end encrypted services such as Signal, critics say it normalizes surveillance of private communications and could strengthen pressure for wider access mandates.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
2 events from the most recent confirmed update back to the earliest known activity.
A newly summarized academic paper argued that government proposals to limit end-to-end encryption often misunderstand how E2EE works in practice and identified five distinct technical scenarios with different lawful-access implications. It also warned that broad restrictions on effective encryption would harm cybersecurity, commerce, and government operations.
On 2026-07-09, efforts in the European Parliament to block the interim Chat Control 1.0 framework failed because opponents did not reach the required absolute majority. As a result, Regulation (EU) 2021/1232 remained in force, preserving a legal basis for companies to voluntarily scan private communications for CSAM and grooming activity.
2 references tracked. Mallory keeps watching after this page renders.
schneier.com
Open sourcecysecurity.news
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.