Interim Rules on Voluntary CSAM Detection Reinstated Until 2028
The EU’s interim rules allowing platforms – on a voluntary basis – to detect child sexual abuse material (CSAM) in private communications have been reinstated by Regulation (EU) 2026/1881 of 24 July 2026. The Regulation was published in the Official Journal on 28 July 2026, entered into force three days later, and will apply until 3 April 2028.
The stopgap regime, introduced in 2021 as a bridge to a long-term solution, allows providers of number-independent interpersonal communications services to derogate from certain confidentiality requirements under the ePrivacy Directive. It thereby enables them to continue using specific technologies for the processing of personal and other data, to the extent strictly necessary to detect and report online child sexual abuse and to remove CSAM from their services. This is also called "chat control 1.0".
The reinstatement follows the temporary legal gap. The previous interim regime expired on 3 April 2026 after the institutions had initially failed to agree on an extension with the European Parliament rejecting the extension on 26 March 2026.
After the expiry of the previous regime, the legislative process resumed. On 23 July 2026, the Council accepted the European Parliament’s amendments and gave green light to Regulation 2026/1881.
A key change concerns encrypted communications. The Regulation expressly provides that it does not apply to interpersonal communications to which end-to-end encryption is, has been, or will be applied. It also states that nothing in the Regulation should be interpreted as prohibiting or weakening end-to-end encryption. The derogation therefore does not authorise measures that would circumvent end-to-end encryption or enable client-side scanning of encrypted communications.
The Regulation nevertheless remains framed as an interference with fundamental rights. Its recitals acknowledge that voluntary detection measures affect the rights to respect for private and family life and to the protection of personal data. It also stresses that the confidentiality of communications is relevant not only for users in general, but also for communications between victims of child sexual abuse and trusted adults, organisations active in the fight against child sexual abuse, and lawyers.
The reinstated interim regime applies against the background of a prolonged and contested legislative process for a long-term solution. In 2022, the Commission proposed establishing a permanent framework, including risk assessments, detection obligations (also called "chat control 2.0"), and the creation of an EU Centre on child sexual abuse to coordinate efforts (→ eucrim 2/2022, 91-92 and →eucrim 3/2023, 246 with further references). The proposal has since faced sustained criticism, particularly regarding its implications for privacy and encrypted communications (→ eucrim 1/2023, 13-14).
Institutional positions have also diverged. The European Parliament called for a more limited and proportionate approach, while the Council, in its 2025 position, moved away from broad detection orders towards a more risk-based system that preserves voluntary detection practices (→eucrim 4/2025, 260-261). Trilogue negotiations between the EP, Council, and Commission on the permanent framework are ongoing.
The reinstated interim Regulation closes the immediate legal gap, but the central tension remains unresolved: how to ensure effective detection of child sexual abuse online without undermining the confidentiality of private communications, data protection, and other fundamental rights.