Signal President Meredith Whittaker warns the EU's recent “upload moderation” proposal to detect CSAM “fundamentally undermines encryption” of messaging apps
A controversial European Union legislative proposal to scan the private messages of citizens in a bid …
TechCrunchNatasha Lomas
Context & Ripple Effects
The proposal sits in a continuing European debate over whether child-safety obligations can coexist with private-message encryption. Earlier experts had already characterized an EU scanning plan as a threat to democratic values in the prior expert critique of mandatory message scanning.
Whittaker’s intervention gives that technical objection a prominent messenger-service voice. It also arrives as Council consideration of an amendment that could have required Signal and WhatsApp to scan images and links was taken off the voting agenda, underscoring that the policy remains contested rather than settled.
First-order effects
Signal publicly frames the proposed detection requirement as incompatible with end-to-end encryption, sharpening the company’s opposition to the EU approach.
EU policymakers face a clearer conflict between a CSAM-detection mandate and the privacy architecture used by encrypted messaging services.
Second-order effects
Other encrypted messaging providers gain a high-profile basis to challenge or seek changes to scanning obligations, as Apple, WhatsApp, and Signal had done in the UK encryption debate.
The dispute shifts implementation scrutiny toward whether any upload-scanning design can be deployed without creating a new inspection point for private communications.
Third-order effects
If lawmakers continue to attach detection duties to messaging services, encryption may become a recurring regulatory boundary: providers will be pressed to demonstrate compliance while preserving their core security claims.
The broader policy outcome remains uncertain, but repeated fights over scanning could make privacy-preserving design a central constraint on digital-safety regulation rather than a product-level feature.
The trend: Child-safety regulation is increasingly testing whether governments can impose detection mandates without weakening the encryption that private messaging services rely on.
“We ask that those playing these word games please stop and recognize what the expert community has repeatedly made clear. Either end-to-end encryption protects everyone, and enshrines security and privacy, or it's broken for everyone. And breaking end-to-end encryption, partic…
📣Official statement: the new EU chat controls proposal for mass scanning is the same old surveillance with new branding. Whether you call it a backdoor, a front door, or “upload moderation” it undermines encryption & creates significant vulnerabilities https://signal.org/... [ima…
New branding, same scanning. Good to see @signalapp pushing back on this embarrassingly naïve effort. When you build a system to mass scan private communications, you irreversibly undermine security and privacy. No matter where the scanning happens.
False positives for CSAM reported to German police from US appears to be increasing alarmingly according to @derspiegel - seems to undermine some of the justification behind proposals within EU to require monitoring of E2EE messages. https://www.spiegel.de/...
Insanity is trying the same stupid thing over and over again and expecting a different outcome. Unfortunately, this works in politics unless there is pushback. Good to see @signalapp continue to take a clear stand 🙏
Excellent and clear statement from @chaosupdates, who are holding the line as ever on encryption and fundamental rights in the EU and everywhere❤️🙏 https://www.ccc.de/... [image]
@mer__edith We still have one day to stop this #ChatControl mass surveillance madness, especially if you're from IT, FI, CZ, SE, SV, EST, GR, PT. Act NOW: https://www.patrick-breyer.de/ ...
Very clear statement by Signal's @mer_edith exposing the cynical game of the Belgian presidency to keep rebranding chatcontrol/client side scanning as “upload moderation with consent”, claiming that this would not break end-to-end encryption. 1/3