Skip to main content
Chat control 2.0

Chat control 2.0

AISocial


« Back to the blog

Europe's surveillance, paid in instalments

Update 5 August 2026: Italy

While Brussels argues about scanning communications, in Italy the Council of Ministers gave its final approval on 4 August 2026 to the legislative decree adapting national law to Regulation (EU) 2024/1689 — the AI Act — for the part on the use of artificial intelligence systems in police work and on civil and criminal liability, under the delegation contained in law 132/2025. Article 8 of the draft allows real-time remote biometric identification in public places only to prevent specific and serious threats — attacks, dangers to physical safety — or to search for missing people and victims of abduction, trafficking and sexual exploitation: matching is done against databases built for that single purpose and deleted when the authorisation expires, and building them by harvesting images from the web is forbidden. Article 10 allows facial recognition to be added to video surveillance systems already installed only after a crime and only to identify people already under suspicion, with footage kept for a maximum of seven days. Authorisation comes from the public prosecutor, on a reasoned request from the police authorities, with review by a judge in the cases provided for; in urgent cases operations may start immediately with notice to the prosecutor, who then has 24 hours to decide.

The initial version provided for automated biometric processing of images captured in squares, stadiums and courtyards: it was dropped after remarks from the European Commission and the conditional opinion of the Italian data protection authority of 14 July 2026, which called for processing only ex post on recorded footage, quality standards for the databases and measures against their incremental expansion. The most contested point remains: authorisation is granted by the public prosecutor — a party to the proceedings — and not by an independent judge, whereas Article 5 of the AI Act, which in principle prohibits real-time remote biometric identification for law enforcement purposes, allows exceptions only with prior authorisation from a judicial authority or an independent administrative authority. As of this update the final text has not yet been published in the Official Gazette. It is the same pattern as the three European tracks, seen from the Italian side: the ban remains the rule, the derogation becomes the infrastructure.

You can lose by winning
You can lose by winning

Losing a vote by winning it

On 9 July 2026 the European Parliament voted at second reading on reinstating the derogation from the rules on the confidentiality of electronic communications — the one that allows online service providers to voluntarily scan messages and emails for child sexual abuse material and grooming attempts. 314 MEPs voted against the text: a majority of those present in the chamber, but not the absolute majority of members — around 360 votes — that the rules of procedure require to reject the Council's position at second reading. The text therefore passed despite being opposed by a majority of those present.

This was not an accident, it was a procedural choice. In late March 2026 Parliament had rejected the extension of the derogation, which duly expired on 3 April. In late June the Council sent the text back to the chamber for a second reading, where the voting thresholds are different and friendlier to those who want it adopted; on 7 July the chamber agreed to the urgent procedure, skipping committee scrutiny; on 9 July it voted. On 23 July the Council gave its final green light to the text as amended by Parliament. The derogation is in force again until 3 April 2028.

The amendments that were adopted matter as much as the procedure: the chamber excluded end-to-end encrypted communications — WhatsApp, Signal, Threema — from the scope, by a handful of votes (369 and 362 on the two key amendments). Other amendments, the ones that would have limited scanning to suspected users or excluded "unknown" material flagged by statistical methods, fell short. The result is a narrower measure than the Council wanted, but still built on the same principle: analysing everyone's communications, outsourced to private companies, with no individual suspicion.

A surveillance camera taking root in the garden
A surveillance camera taking root in the garden

Track two: the permanent regulation

The derogation is provisional by design: it keeps voluntary scanning alive while the definitive regulation against child sexual abuse — proposed by the Commission on 11 May 2022 and nicknamed chat control by its critics — is negotiated. The original text provided for so-called detection orders: an authority could require a service to search its users' communications for illegal content, encrypted ones included, which in practice means client-side scanning — on the device, before the message is encrypted.

The three institutions started from irreconcilable positions and, four years on, they still are. The Commission wants broad detection obligations; Parliament, in the position it adopted in November 2023, accepts them only against people already under suspicion and subject to judicial review; the member states, in the partial general approach agreed on 26 November 2025 under the Danish presidency, dropped the obligations altogether and instead made voluntary scanning permanent — four countries (Czechia, Poland, Slovakia, the Netherlands) voted against, Italy abstained.

Trilogue negotiations began on 9 December 2025. The fifth round, on 29 June 2026, ended without agreement on precisely the point that splits everything: blanket scanning at the platforms' discretion, or targeted detection ordered by a judge. One provisional result does exist: negotiators agreed to keep end-to-end encrypted communications out of the scope, which would take client-side scanning obligations off the table. The sixth round is expected in September 2026, under the Irish presidency.

Every passer-by reduced to a metadata card
Every passer-by reduced to a metadata card

Track three: everybody's metadata

While chat control takes up all the attention, the bigger game is being played elsewhere. In April 2025 the Commission presented ProtectEU, its internal security strategy; on 24 June 2025 it spelled out the digital part in a roadmap for "effective and lawful" access to data by law enforcement, structured around six pillars: data retention, lawful interception, digital forensics, decryption, standardisation and artificial intelligence. The timetable includes a technology roadmap on encryption due in the second quarter of 2026, and funding for "next-generation" decryption capabilities for Europol from 2030.

The heaviest piece, though, is the new European data retention framework, expected after the public consultation of May 2025 and the impact assessment: as of 4 August 2026 the proposal has not yet been tabled. Council working documents reported by the specialist press point the way: retention of metadata — who contacted whom, when, from where, through which service — for one year, the preference of most member states, with a six-month minimum and the option to go further; and above all a scope that does not stop at telecom operators but reaches over-the-top services, encrypted messengers included. Not content, metadata: which is usually more than enough to reconstruct a person's life.

This track faces a historic obstacle: in 2014 the Court of Justice of the European Union struck down the old data retention directive precisely because it imposed general and indiscriminate retention, and it has kept drawing the boundaries ever since. Meanwhile the Digital Omnibus, the digital simplification package now under discussion, would dismantle the ePrivacy Directive and redistribute its parts: that is the legal frame the scanning derogation lives in, and rewriting it means rewriting the pitch as well.

Surveillance built one brick at a time
Surveillance built one brick at a time

One project in three pieces

Taken together, the three tracks tell a single story: the normalisation of generalised suspicion. The derogation establishes that the communications of people suspected of nothing may be analysed; the permanent regulation is only arguing about how far to make it mandatory; data retention extends the same principle to the metadata of every digital service. The instrument changes, the idea does not.

The mechanism has a name: the Overton window, the range of ideas a politician can back at any given moment without losing support, and which shifts when someone keeps proposing what sits just outside it. The 2021 derogation was born as an extraordinary, temporary exception to the confidentiality of communications; four years on it is the neutral ground the debate stands on, and the position now seen as moderate — voluntary scanning made permanent — is exactly the measure that in 2020 was presented as a time-limited emergency. The maximalist 2022 proposal, with mandatory detection orders extended to encrypted content, does not necessarily need to pass: it needs to move the centre. When it is withdrawn or watered down, what remains looks like a reasonable compromise and is hailed as a victory for fundamental rights, even though it ratifies a principle that ten years ago would not even have been up for discussion. Every instalment is painless precisely because the previous one moved the yardstick of what counts as normal.

The objections are well known, and they do not come from the usual suspects. The European Data Protection Supervisor has flagged high error rates in detecting new material and grooming attempts: across billions of messages, even a small share of false positives means masses of innocent conversations sent for review — and the first people at risk are journalists, lawyers, doctors, anyone working under a duty of confidentiality. On 27 February 2026 the German data protection authorities called on the Union to abandon chat control "completely and definitively", recalling that weakening encryption creates vulnerabilities that do not distinguish between investigators and attackers. And July's vote made one political point plain: when scanning is "voluntary", the decision about what to look for in Europeans' conversations is taken by private companies, almost all of them non-European — an objection Italy itself put on record in the Council while voting in favour of the stopgap measure.

There are three dates to watch in the coming months: the sixth trilogue on the permanent regulation in September, the data retention proposal, and the encryption roadmap. They are separate files, with different acronyms and different timetables, and that is exactly why they are so hard to notice.

Mass surveillance never arrives in a single vote: it arrives in instalments, and every instalment looks small.

SOURCES

  • Council of the European Union, Fighting child sexual abuse online: interim measure protecting children now reinstated, 23 July 2026 — consilium.europa.eu
  • Council of the European Union, Council moves to reinstate interim measure to combat child sexual abuse online, 2 July 2026 — consilium.europa.eu
  • European Parliament, Combating child sexual abuse: support for a more limited ePrivacy derogation, July 2026 — europarl.europa.eu
  • European Parliament, Child sexual abuse online: voluntary detection measures will not be extended, March 2026 — europarl.europa.eu
  • Regulation (EU) 2021/1232, temporary derogation from the ePrivacy Directive — EUR-Lex
  • European Commission, proposal for a regulation to prevent and combat child sexual abuse, COM(2022) 209 of 11 May 2022 — EUR-Lex
  • European Commission, proposal to extend the derogation, COM(2025) 797 — EUR-Lex
  • EDPB and EDPS, Joint Opinion 4/2022 on the proposed regulation, 28 July 2022 — edps.europa.eu (PDF)
  • eucrim, CSA Regulation: Council Position Reached (partial general approach of 26 November 2025) — eucrim.eu
  • EDRi, CSA Regulation Document Pooledri.org
  • EDRi, Mass surveillance of telecommunications Document Pool (data retention) — edri.org
  • European Commission, Roadmap for effective and lawful access to data for law enforcement, 24 June 2025 — home-affairs.ec.europa.eu
  • Council of the European Union, document ST 10806/2025 on the roadmap for access to data — data.consilium.europa.eu (PDF)
  • European Commission, Encryption policy page (technology roadmap, Europol decryption capabilities) — home-affairs.ec.europa.eu
  • heise online, Data Retention: Commission to present proposal by mid-2026, 3 December 2025 — heise.de
  • netzpolitik.org, EU-Parlament: Freiwillige Chatkontrolle geht mit Verfahrenstrick durch, July 2026 (in German) — netzpolitik.org
  • netzpolitik.org, Interne Dokumente: Trilog zur Chatkontrolle geht in entscheidende Phase, June 2026 (in German) — netzpolitik.org
  • netzpolitik.org, Appell der Datenschutzbehörden: EU soll "vollständig und endgültig" auf Chatkontrolle verzichten, 27 February 2026 (in German) — netzpolitik.org
  • EDPB, Digital Omnibus: EDPB and EDPS support simplification and competitiveness while raising key concerns, 2026 — edpb.europa.eu
  • Il Fatto Quotidiano, Chat Control salva la crittografia end-to-end, ma la sorveglianza privata entra dalla porta di servizio, 10 July 2026 (in Italian) — ilfattoquotidiano.it
  • Mackinac Center for Public Policy, The Overton Window (the original formulation of the concept) — mackinac.org
  • Regulation (EU) 2024/1689 (AI Act), in particular Article 5 on real-time remote biometric identification for law enforcement purposes — EUR-Lex
  • Italian law of 23 September 2025, no. 132, Provisions and delegations to the Government on artificial intelligence (the delegation to align national law with the AI Act) — Gazzetta Ufficiale
  • Presidency of the Council of Ministers, meeting of the Council of Ministers no. 185 of 4 August 2026 — governo.it; agenda in the convocation notice
  • Italian data protection authority, opinion no. 531 of 14 July 2026 on Titles I and III of the draft legislative decree implementing Regulation (EU) 2024/1689 (doc. web 10275606) — garanteprivacy.it
  • Directive (EU) 2016/680 on personal data processing for the prevention and prosecution of crime — EUR-Lex — and its Italian implementation, legislative decree of 18 May 2018, no. 51 — Gazzetta Ufficiale

Support us with Buy Me a Coffee.

Buy Me a Coffee