Skip to content
Deep Analysis12 min read

Chat Control 2026: What Really Changes for Italian Lawyers, Journalists and Executives When Europe Discusses Your Encryption

27 April 2026|AEGIDA Research Team

Chat Control is the name by which specialized press refers to the European regulation proposal CSAR — Child Sexual Abuse Regulation — filed by the European Commission in May 2022 and under negotiation for four years in EU institutions. The original form of the proposal foresaw an obligation for interpersonal communication service providers (Messenger, WhatsApp, Signal, iMessage, Telegram, but also email and cloud storage) to "detect, report, and remove" child sexual abuse material, including the obligation, upon order of competent authority, to scan message content before encryption — the so-called client-side scanning technique, which in practice annuls the promise of end-to-end encryption.

Over the years the proposal has been the subject of harsh confrontation between the European Commission (more ambitious), the Council of the Union (fragmented, with Germany, Austria, and the Netherlands historically opposed and other countries in favor), the European Parliament (more protective, with a majority always demanding exemption of encrypted communications), and a galaxy of civil society, academic cryptographers, encrypted service providers (Signal, Tutanota, Proton), and data protection authorities. The technical debate has been very serious: cryptographers of the caliber of Matthew Green, Bruce Schneier, Susan Landau, and over five hundred academics signing an open letter argued that client-side scanning is incompatible with computer security, because anyone who can scan can also be compromised, manipulated, extended to categories different from those initially declared.

April 2026: The Chronology of What Really Happened

The two weeks between late March and early April 2026 produced three distinct facts that must be kept separate to avoid confusing the reading of the game.

First fact: on March 26, 2026 the European Parliament rejected, by a single vote, the extension of the temporary derogation that since 2021 authorized service providers to voluntarily scan their users' content to detect known child sexual abuse material. This is the so-called "Chat Control 1.0", or technically Regulation (EU) 2021/1232 on temporary derogation from the ePrivacy Directive. The rejection had immediate political value: for the first time a majority, however slim, of the European Parliament refused to extend the legal basis allowing scanning even on a "voluntary" basis.

Second fact: on April 3, 2026 the derogation expired without renewal. From that date, providers operating in the European Union — Meta (WhatsApp, Messenger, Instagram), Google, Microsoft, Apple, and others — can no longer legally scan their European users' messages searching for known child sexual abuse material. The question of what is actually happening in practice is debated: some operators announced suspension of the scanning service, others find themselves in a grey zone because they operate under other legal bases. NCMEC, the US National Center for Missing & Exploited Children that receives most global reports of child sexual abuse material, registered a significant drop in the report flow from the European Union in the first three weeks of April.

Third fact: the negotiation of "Chat Control 2.0", the structural and lasting version of the regulation, has been ongoing for months and officially resumes in trilogue (negotiation between Commission, Council, and Parliament) on May 4, 2026, with the stated goal of the rotating presidency to close an agreement by July 2026. This — not Chat Control 1.0, already archived — is the open game those handling confidential communications must follow.

Distinguish well: Chat Control 1.0 (temporary derogation) died on April 3, 2026. Chat Control 2.0 (permanent regulation) is in active negotiation, with trilogue reopening on May 4 and political agreement expected by July. The March 26 victory is a partial victory of method, not the end of the substantive game.

What Was Removed from the Table (the Good News)

Political and technical pressure accumulated over the years has produced a result that, until 2024, seemed unlikely: the Council of the Union has over the past year modified its negotiating position, eliminating from its mandate the requirement of mandatory client-side scanning on encrypted services. The current Council formulation no longer asks Signal, WhatsApp, iMessage providers to implement local scanning of messages before encryption. The Parliament position, historically more protective, is even clearer on this point: no mandatory scanning on end-to-end encrypted content.

This is, in concrete terms, a victory of civil society and the technical community. It means that, in the trilogue agreement scenario, the cryptographic integrity of Signal, WhatsApp, iMessage, and other E2E services will not be broken by European law. The conversation between your lawyer and you, or between your journalist and his source, will remain end-to-end encrypted without a third governmental eye placed inside the client. It is a non-trivial result and deserves to be recorded as such.

Beware of words however. "Not mandatory" does not mean "forbidden". The text emerging from trilogue could still admit, in some form, "voluntary" scanning by providers wishing it, or mandatory scanning on individual basis by judicial order on individual suspects. The conceptual structure "everyone gets scanned by default" has fallen. The conceptual structure "someone could be scanned under certain conditions" remains under discussion.

What Remains on the Table (and Why It Must Be Followed)

With the muscular version of generalized client-side scanning fallen, the negotiation has shifted to three fronts that must be carefully followed because each has concrete operational implications for those handling confidential correspondence.

Front 1 — Age Verification and Mandatory Digital Identity

The text emerging from the Council introduces an age verification obligation for communication services wishing to avoid exposure to detection procedures. The logic: if you are sure your users are adults, you do not need to scan to protect minors. The technical question however is explosive: how do you verify age online without identifying the person? Available technologies today (document upload, facial recognition, attestation through state digital identity) are all strongly identifying. The risk is replacing one privacy problem (message scanning) with another even more serious privacy problem (real identity tied to every messaging account, with all that entails in case of breach like the French one of April 21).

For Italian journalists receiving communications from anonymous sources, and for lawyers assisting protected witnesses or foreign political dissidents, mandatory age verification would be particularly problematic: the operational value of Signal or a WhatsApp account with secondary SIM lies precisely in the possibility of not linking the source's real identity to the channel's identity. Age verification based on SPID or EUDI Wallet would link every message to a state identity. Defense of in-transit encryption is not enough if upstream and downstream identity is exposed.

Front 2 — Scanning of Non-Encrypted Material (Cloud Storage, Email)

The Council text maintains a scanning obligation for cloud service providers not end-to-end encrypted and for plaintext email operators. This means Google Drive, OneDrive, Dropbox, and Gmail, Outlook, Libero mailboxes not protected by E2E will continue to be scanned for known child sexual abuse material. For the lawyer or journalist archiving sensitive documents on standard commercial cloud, this is already today the implicit model: assume your Google Drive is regularly inspected, also for general security purposes (phishing detection, malware, illicit content). The European regulation does not change the risk, it formalizes it.

For those wanting effective storage confidentiality, the only technical path is client-side encryption before upload — tools like Cryptomator, rclone with encryption, or native E2E platforms like Proton Drive, Tresorit, Tuta. This is a recommendation AEGIDA has been giving for some time, becoming even more pointed in light of regulatory framework stabilization.

Front 3 — Detection Orders on Individual Services and Individual Cases

The mechanism remaining in both positions (Council and Parliament, albeit with different calibrations) is the "detection order" — an order issued by competent authority requiring a specific provider to adopt detection measures for a limited period, in presence of certain requirements. The Parliament version requires judicial approval, high suspicion threshold, and periodic renewal; the Council version is more permissive. Even if the object of the detection order will not be encrypted content scanning (the obligation has fallen), it could include other obligations: account blocks, metadata retention, traffic pattern sharing, cooperation with ongoing investigations.

For providers operating under EU jurisdiction, the arrival of a detection order is a scenario already requiring legal and technical planning today. For end users, the practical consequence is that a provider's posture (European headquarters, US headquarters, Swiss or Icelandic) materially influences the level of pressure to which it can be subjected. An organization custodying high-sensitivity dossiers would do well to diversify: operational communications on one channel, truly secret communications on a separate channel and on a provider with different jurisdictional exposure.

Italy Among the Four Opponents: What It Really Means

Italy, Czech Republic, Netherlands, and Poland today form the bloc of four countries opposing the current Council position. For an Italian citizen this is news to start from but must be properly framed. First: Italian opposition to the Council text does not mean Italy is "against Chat Control" in absolute terms. It means the Italian government assesses that the current version does not offer sufficient guarantees on one or more fronts — communication privacy, age verification, proportionality, technical sustainability for operators. The Italian position may evolve in the next two months.

Second: opposition by four countries is not sufficient on its own to block the procedure. For a qualified majority vote in the Council of the Union, fifteen member states representing at least 65 percent of EU population are required. Four countries representing a significant share of population (Italy, Poland, Netherlands) constitute however a potential blocking minority, especially if Germany or Spain were to shift to a critical position.

Third: the European Parliament has equal role. Given the Parliament position is more protective than the Council's, the final text negotiated in trilogue will have to be a compromise. The structural risk for citizens' rights is that, in seeking compromise, the Parliament accepts a "lightened" version of the Council text in exchange for concessions on other aspects. Civil society pressure, including Italian, in the next two months matters concretely. Those wanting to act can: write to their MEPs, support campaigns like Privacy Network, Hermes Center, European Digital Rights, and follow trilogue evolution week by week.

For Italian professionals interested in close monitoring: the sites euperspectives.eu, edri.org (European Digital Rights), patrick-breyer.de (the German MEP who led the opposition), stateofsurveillance.org publish timely and technically accurate updates. The Italian associations Hermes Center for Transparency and Digital Human Rights and Privacy Network produce analyses dedicated to the Italian audience.

What Concretely Changes in Your Workday

Stripped of legal formulas, the operational picture for an Italian lawyer, journalist, executive in the next six months is the following.

For real-time communications (chat, voice, video) end-to-end encrypted on Signal, WhatsApp, iMessage, Threema: today there is not and likely will not be legal obligation of content scanning. E2E encryption continues to do its job. The dominant attack surface is not the regulator, it is the terminal device: phone compromised by spyware (Pegasus, Predator, Graphite), unencrypted backup, screenshot by interlocutor, malware on desktop. Defense of contents passes through defense of the device.

For email and documents on non-E2E cloud services (Gmail, Outlook, Libero, Google Drive, OneDrive, Dropbox): the regulatory situation confirms the de facto situation. They are scanned, voluntarily today, potentially mandatorily tomorrow. For truly confidential documents client-side encryption before upload is the only technically robust measure. Specific tools: 7-Zip with AES-256 for archives, Cryptomator for cloud folders, OnlyKey or YubiKey for encryption keys, or migration to native E2E providers (Proton, Tuta, Tresorit) for the most sensitive loads.

For messaging account registration and identification: the scenario is evolving. If age verification enters the final text, in twelve to twenty-four months all messaging accounts in the EU could require mandatory identification. Strategically, this is the time to establish — if not already done — backup communication channels with sources, clients, confidential contacts, on platforms with different jurisdictional exposure (Signal continues to be the reference choice for integration with "real" SIMs, but it is worth planning alternatives).

For your device posture: the most important point. A compromised device annuls any cryptographic guarantee of the network. Investing in correctly protected devices, with active verified boot, controlled firmware, rigorous permission model, segmentation between professional and private identity, is today the difference between real defense and cosmetic defense. It is the area in which AEGIDA operates with its Privacy Phone — not as "antidote to Chat Control" (Chat Control does not break encryption, as we have seen) but as foundation of a digital posture that resists real threats against those handling sensitive dossiers: mercenary spyware, hostile forensic access, metadata leaks, sophisticated social engineering.

The Wider Frame: Encryption, Rule of Law, European Resilience

It is instructive to place Chat Control in the wider frame of European policy on encryption. In recent years the Union has moved simultaneously in two apparently contradictory directions. On one hand it has promoted transition to post-quantum cryptography, financed research on resistant algorithms, imposed on member states migration plans for critical infrastructure, recognized in eIDAS 2.0 the centrality of strong electronic signature. On the other hand it has discussed, with Chat Control and other parajuridical initiatives (like the Stockholm declaration of 2024 on "lawful" access by authorities to encrypted data), limits on consumer encryption.

The contradiction is only apparent. What Europe is trying to build, in non-linear fashion and with uncertain outcomes, is a posture in which infrastructural cryptography remains strong (for defense of digital sovereignty, resilience against geopolitical adversaries, industrial competitiveness) but interpersonal communications cryptography has regulated exceptions (for police action on serious crimes, child protection, judicial cooperation). It lies with European democratic maturity to find a balance preserving both needs, and with informed civil society pressure to tip that balance toward rights protection.

For professionals operating in regulated sectors — lawyers with professional secrecy, journalists with source protection obligation, doctors with medical secrecy, engineers with industrial property data — the strategic lesson is not to wait for regulation to decide everything. Building from now a digital posture resisting regulatory evolution in the next five to ten years, regardless of how Chat Control closes in July 2026, is the rational way to protect your professional operation.

Seven Concrete Moves for the Next Eight Weeks

  1. 1.Map your communications by sensitivity class: ordinary correspondence (WhatsApp/standard email is OK), professional correspondence (Signal preferable), truly secret correspondence (Signal on dedicated device, separate identities, no cloud backup).
  2. 2.Verify the posture of your main device: active system updates, screen locked with high-entropy code, biometrics for daily use but fallback to strong passphrase, verified boot where possible.
  3. 3.Migrate truly confidential storage to E2E solutions (Proton Drive, Tresorit, Tuta) or introduce client-side encryption (Cryptomator) over standard cloud storage.
  4. 4.Disable optional scanning where offered in opt-out: Apple iCloud, Google Photos, Microsoft 365 privacy settings include content detection options that can be disabled. Verify regularly.
  5. 5.Review age verification and privacy policy of platforms you already use: some will introduce preventive age verification in coming months. Evaluate implementation quality (zero-knowledge proof? document upload? state identity?) before accepting.
  6. 6.For journalists and lawyers: device separation between administrative identity (bank, tax, state agencies) and professional identity (correspondence with sources or clients). A compromise of the administrative device must not touch the professional one.
  7. 7.Follow the CSAR trilogue in the next eight weeks: edri.org, patrick-breyer.de, hermescenter.org, privacynetwork.it publish detailed updates. To have impact: write to your Italian MEPs, particularly LIBE committee members.

Conclusion: Encryption Stays. The Rest Is Work

The news many gave alarmistically — "Europe will break encryption" — is not what is today on the CSAR trilogue table. End-to-end encryption of Signal, WhatsApp, iMessage will not be broken by the European regulation emerging by July. This is the good news, and it is non-trivial news, fruit of years of technical and political pressure. But stopping at this news would be dangerous. The regulation that will emerge — whatever the exact compromise version — will shape European digital identity, cloud provider obligations, detection procedures on specific suspects, and the regulatory environment in which professionals handling confidential dossiers operate for years to come.

For an Italian lawyer, an investigative journalist, an executive with responsibility over confidential information, the operational conclusion is: encryption continues to be available, the regulatory environment remains substantially compatible with your craft, but the responsibility to build a solid digital posture falls on you. There is no platform that saves you, there is no rule that protects you alone, there is no provider that makes you invulnerable. There is, instead, a set of technical and procedural choices — the device you use, channel separation, client-side encryption for archives, authentication hygiene, continuous training — that, accumulated, determine whether the confidentiality you declare to your clients, your sources, your colleagues is real or cosmetic. The May 4 trilogue does not change this truth. It confirms it.

Primary sources: State of Surveillance — "EU Chat Control: The Plan to Scan Every Private Message" (2026); State of Surveillance — "Chat Control Is Dead. Long Live Chat Control" (April 2026); EFF — "After Years of Controversy, the EU's Chat Control Nears Its Final Hurdle"; Patrick Breyer (MEP); TechRadar — "A disaster waiting to happen"; TechRadar — "Chat Control: Germany, Belgium, Italy, and Sweden shift positions"; EU Perspectives; European Pirates; Tuta Blog (2026); Mozilla Foundation; Tech Policy Press; Wikipedia (en); Euronews. Internal references: AEGIDA Research, "Equalize Italian Database Case" (April 10, 2026), "France Titres ANTS 19M records" (April 27, 2026).