Leaked proposal: the European Union plans to release a draft law this week that requires tech companies to scan for CSAM and threatens end-to-end encryption
Brussels is bracing for one of its biggest and most emotional tech fights yet as companies face stringent new rules to clamp down on sexual abuse material.
Politico
Context & Ripple Effects
The proposal follows the EU’s earlier temporary permission for platforms to scan for child sexual-abuse material without violating privacy rules, but would move the issue from a time-limited allowance toward a more stringent regulatory fight. Related coverage also records expert objections that mandatory messaging scans threaten democratic values, making encryption the central fault line rather than a technical detail.
First-order effects
Tech companies would have to prepare for CSAM-detection obligations under an EU draft law, while providers of end-to-end encrypted services face pressure to reconcile scanning requirements with their existing privacy design.
Brussels would turn child-safety enforcement into a direct compliance issue for the platforms operating in the EU, intensifying an already emotional policy dispute.
Second-order effects
Messaging providers and privacy advocates are positioned to contest requirements that reach encrypted communications, as reflected in expert criticism of mandatory messaging scans.
The proposal shifts the competitive and policy burden toward companies able to demonstrate detection and reporting systems, while making encryption architecture a focal point of EU regulatory scrutiny.
Third-order effects
If the proposal becomes a durable model, EU platform governance will increasingly treat access to private communications as an enforcement surface, with child-safety mandates setting constraints on privacy-preserving product design.
The later parliamentary effort’s exemption for end-to-end encrypted services shows that the lasting structure of such rules will hinge on whether lawmakers separate encrypted communications from broader platform-scanning duties.
The trend: The EU is moving from temporary platform-scanning permissions toward a lasting access-control regime in which child-safety enforcement and end-to-end encryption are regulated together.
Speaking of actual free speech issues, the EU is proposing a regulation that could mandate scanning of encrypted messages for CSAM material. This is Apple all over again. https://www.euractiv.com/...
This document is the most terrifying thing I've ever seen. It is proposing a new mass surveillance system that will read private text messages, not to detect CSAM, but to detect “grooming”. Read for yourself. https://twitter.com/...
Leak: The EU's proposal to force tech platforms to detect, report and remove child sexual abuse material online (for pros), ahead of the European Commission unveiling tomorrow. https://pro.politico.eu/...
EC presents a proposal meant to protect children. Providers must “take reasonable mitigation measures” to manage the identified risks. They will be obliged to install government-issued software(?). Offending content must be blocked. Age-verification? https://ec.europa.eu/... http…
Let me be clear what that means: to detect “grooming” is not simply searching for known CSAM. It isn't using AI to detect new CSAM, which is also on the table. It's running algorithms reading your actual text messages to figure out what you're saying, at scale.
If you play out the EU's regulations on a long enough time horizon, what Orwell presaged will come to pass. Like, what is the 10-20 year vision here? How does this not end up with a splinternet of various non-interoperable internet futures? https://twitter.com/...
...amongst many of the reasons for “NO” was simply: where and how do you distribute the list of “bad people” in a secrecy-preserving manner? It's not like you can/should check the list of phone numbers of FBI's Most Wanted, into the codebase and/or app configuration infra.
If you want a vision of the future, imagine an endless line of do-nothing, jobsworth, bureaucrats demanding you use ever less secure forms of communication - forever.
Sigh. If they want to allow end-to-end encryption, as they claim, then providers *can't* access the content. That's how end-to-end encryption works. If they can, it's not end-to-end (and it's inherently more complex and less secure). https://twitter.com/...
By legally mandating the construction of these surveillance systems in Europe, the European government will ultimately make these capabilities available to every government.
Looks like the EU is about to get its very own version of the EARN IT Act, where end-to-end encryption will be effectively banned. https://www.politico.eu/...
If you want to say “We think the Internet should be even less secure than it currently is”, go ahead and say that, but be prepared for people to, um, disagree. And that's what they're saying here.
I am so tired. It seems like every time people rally to fight off one bad surveillance proposal, an even more powerful organization pops up to devise a more invasive one. Is there no constituency out there for “just let me be, and don't spy on my private communications”?
This is utterly exhausting. We keep having the same conversation over and over, and they keep hoping the basic science will magically change. Child sexual abuse material is *bad*. Everyone agrees on that. But that doesn't mean magic solutions can be made to exist.
This current proposal is EU-specific. But variations on this same non-workable idea keep getting shopped around internationally. There's a reason nothing has actually been adopted.
It is potentially going to do this on encrypted messages that should be private. It won't be good, and it won't be smart, and it will make mistakes. But what's terrifying is that once you open up “machines reading your text messages” for any purpose, there are no limits.
Securing communication and data on the Internet is *hard*. That's why there are so many criminal data breaches and other spectacular security failures. End-to-end encryption is one of the few tools we have that actually works well. Please don't take it away.
I do believe the leaked proposal has a degree of trust in technical possibilities that does not match the actual capabilities that people building the affected services have. It brings back memories of the “nerd harder” quote. https://twitter.com/...
Now I'm out on vacation for the rest of the week, so that leaked EU CSAM draft regulation will just have to wait. But I'm sure it'll reinforce my current mood that US/EU exceptionalism ("by definition we're always the good guys, so total surveillance is fine") is a mortal danger
I am always going to set fire to your legislative proposal to: 1. Backdoor encryption. 2. Legalize hacking back. 3. Require the use of real names online.
This is the problem with the EU: it doesn't want to be the jurisdiction that deploys new technology, it just wants to deploy it. But without few native technology providers of its own, it's unable to even understand what its asking for technologically.
My stance remains the same. Child sexual exploitation material on tech platforms is a huge problem. Governments and those seeking power will use this very real crime to violate digital privacy rights. In a world without digital privacy, no child or survivor is safe. https://twitt…
@alexhern ... So: When building Facebook Messenger Secret Conversations, as I've explained before I was asked whether it would be able to be “backdoored” in order to fight “Organised Crime”; the proposal being that <various narcos> would NOT REALLY be using E2EE. The answer was n…