On July 9, 2026, the European Parliament tried to kill the temporary Chat Control rules and failed by a technicality. Not because a majority wanted them to survive: 314 MEPs voted to block the extension, only 276 voted against. The problem is the procedure required 360 votes to succeed. So the extension passed anyway, by default, and now runs until April 3, 2028.
What happened in Strasbourg
Chat Control 1.0 is the nickname for the EU’s interim regulation that lets messaging and email providers voluntarily scan private communications for child sexual abuse material (CSAM). It has been running since 2021 on a series of short-term extensions. This latest vote was Parliament’s chance to let it lapse.
It didn’t work, but not for lack of votes. As The Register reported, the motion to block needed a specific threshold under the applicable procedure, and 314 votes wasn’t enough even though it beat the 276 opposing votes comfortably. Euronews called it a rule that “passed through the back door”, since the extension survives purely because the rejection fell short, not because anyone voted it back in.
The practical result: the voluntary CSAM scanning regime that has existed since 2021 continues unchanged, and it’s now locked in until April 2028.
A quick recap of how we got here
This fight didn’t start on July 9. The European Commission first proposed a permanent, mandatory version of Chat Control back in 2022, and it has been rewritten, delayed, and reintroduced under various council presidencies ever since. Each version has run into the same wall: you cannot require platforms to scan message content, including E2EE content, without either breaking encryption or building a backdoor that anyone, not just child-safety investigators, can eventually find and use.
Parliament has pushed back on the mandatory version repeatedly, which is why the EU has instead leaned on this “temporary” voluntary framework since 2021, extending it every year or two rather than letting it lapse or forcing through the permanent law. July 9 was supposed to be the moment that temporary patchwork finally ended. Instead, it got another 21 months of runway, and the underlying fight simply moved to the next round.
The encryption carve-out, and why it barely matters
There is one real win buried in the vote. MEPs did secure a majority to formally exclude end-to-end encrypted (E2EE) platforms, think WhatsApp, Signal, iMessage, from the scanning provisions in this interim rule.
Sounds significant. In practice it changes almost nothing, because providers were never scanning E2EE message content under the current voluntary framework anyway. You can’t scan what you can’t read, and E2EE by design keeps even the platform locked out of the plaintext. Privacy groups have been fairly blunt that this exemption formalizes an existing technical reality rather than closing an open door. The real fight was never really about the interim rules. It’s about what comes after them.
What’s actually coming in September
The interim extension was always the smaller story. The permanent Chat Control legislation, the one that would replace this voluntary patchwork with a binding EU-wide law, is where the real stakes sit, and negotiations on that resume in September 2026.
Several proposals on the table involve client-side scanning: software installed on your phone or laptop that inspects message content before encryption is ever applied, and flags matches to a database. The pitch from supporters is that this leaves end-to-end encryption “technically intact”, since the message is still encrypted in transit. Critics, including most of the cryptography and security research community, describe that framing as misleading at best. If every message gets inspected on the device before it’s sent, the privacy guarantee that made E2EE worth using is gone in practice, even if the math still checks out on paper.
This is the same fight that has been running since Chat Control first surfaced in 2022, and it connects directly to the EU’s broader surveillance push covered in our piece on Going Dark and ProtectEU. Different legislative vehicle, same underlying goal: build the EU an architecture for reading communications that are supposed to be private.
Want to compare all VPNs side by side? Check our full VPN comparison table with scores across 18 criteria.
Why this matters for VPN users, honestly
Here’s the part we’re not going to oversell. A VPN is genuinely useful privacy tooling, but it does not do what people assume it does here.
A VPN encrypts your traffic between your device and the VPN server, and it hides your IP address and location from your ISP and from the sites and apps you connect to. That’s real protection, and it’s why jurisdiction and no-logs policies matter so much when you’re choosing a provider.
What a VPN cannot do is protect the content of a message from client-side scanning. If scanning happens on the device itself, before your VPN’s encryption ever gets involved, the VPN tunnel is irrelevant to that specific threat. The scan already happened. Your VPN sees encrypted traffic leaving your device either way; it has no visibility into, and no way to prevent, what an app running on that same device inspected before sending. This is a different attack surface than the one a VPN is built for, and no amount of tunnel encryption changes that.
If you want a plain-English gut check: a VPN protects the pipe. Client-side scanning happens before the pipe. Anyone selling a VPN as a fix for that specific problem is selling you something it can’t do.
What to actually watch and do
The interim rules aren’t changing before April 2028, so nothing about your day-to-day messaging changes today. What’s worth tracking is the September 2026 negotiation round on the permanent legislation, since that’s where client-side scanning either gets written into EU law or gets pushed back again, the way mass message scanning was in the original Chat Control push.
For messaging privacy specifically, the meaningful lever is choosing apps that minimize what’s collected and stored, and watching how providers respond if client-side scanning mandates move forward. Signal has already said publicly it would rather leave the EU market than build scanning into its app. For general browsing and connection privacy, a solid no-logs VPN like ProtonVPN, based in privacy-friendly Switzerland and vocal on EU digital rights issues, is still worth having. Just understand what it covers and what it doesn’t.
None of this means encryption and VPNs stop mattering. A VPN still hides which sites and services you connect to from your ISP, still protects you on public Wi-Fi, and still keeps your real location from being visible to every server you touch. Those are separate, real problems that a VPN solves well. Client-side scanning is a separate, real problem it doesn’t solve at all. Keeping both facts straight is the whole point of covering this story honestly instead of turning every EU privacy headline into an affiliate pitch.
Our guide on Five Eyes, Nine Eyes and Fourteen Eyes covers the surveillance-alliance angle if you want the fuller picture of who can legally request what data, and from whom.
This vote is a near miss dressed up as a compromise. The interim rules survive on a technicality, not a mandate, and the encryption exemption Parliament won is mostly symbolic since E2EE apps were never in scope anyway. The number that actually matters is September 2026, when the permanent legislation comes back with client-side scanning proposals on the table. A VPN remains essential for hiding your traffic and location, but be clear-eyed: it is not a defense against scanning that happens on your device before your VPN ever touches the data. Watch this file closely.