[{"data":1,"prerenderedAt":94},["ShallowReactive",2],{"blog-\u002Fblog\u002Feu-chat-control-encryption-legislation":3,"blog-more-\u002Fblog\u002Feu-chat-control-encryption-legislation":82},{"id":4,"title":5,"author":6,"body":7,"date":64,"description":65,"draft":66,"extension":67,"featured":66,"image":68,"imageAlt":69,"meta":70,"navigation":71,"path":72,"readingTime":73,"seo":74,"stem":75,"tags":76,"__hash__":81},"blog\u002Fblog\u002F2025-07-15-eu-chat-control-encryption-legislation.md","When Encryption Meets Legislation: The EU's Chat Control Debate","Silentel editorial",{"type":8,"value":9,"toc":57},"minimark",[10,14,17,22,25,28,31,34,37,41,44,48,51,54],[11,12,13],"p",{},"On July 1, 2025, Denmark took over the rotating presidency of the Council of the EU and, within days, revived one of the most contested pieces of legislation in the bloc's history. Nicknamed Chat Control by its critics, the proposal has been debated since 2022 and has repeatedly failed to find enough support to pass. Denmark is now pushing for a vote as early as October 2025, with roughly nineteen member states currently backing the plan and a handful, including Germany, still undecided.",[11,15,16],{},"For anyone working in secure communications, it's worth understanding what's actually being proposed and why it matters even for platforms that have nothing to do with mass market messaging.",[18,19,21],"h2",{"id":20},"what-chat-control-would-actually-require","What Chat Control would actually require",[11,23,24],{},"The core of the proposal is straightforward to state and difficult to implement: providers of messaging services operating in the EU, including those built on end to end encryption, would be required to scan users' private communications for child sexual abuse material before that content is sent. This isn't scanning content already sitting on a server. It's scanning on the device itself, before encryption is ever applied, commonly referred to as client side scanning.",[11,26,27],{},"The technical objection isn't really about whether the goal is worthwhile, protecting children from exploitation is not a controversial aim. It's about whether the mechanism can exist without undermining the encryption itself. Security researchers and cryptographers have argued consistently that requiring scanning inside an end to end encrypted service means building a detection system into every user's device, one capable of inspecting content before it's protected. Once that capability exists, the argument goes, it becomes a standing feature that could be expanded, misused, or exploited by anyone able to compromise it, regardless of the original intent behind it.",[11,29,30],{},"There's also a proportionality question worth sitting with, separate from the technical one. Chat Control would apply scanning to everyone's private messages by default, the overwhelming majority of whom have never done anything wrong, in order to catch a small fraction of people distributing illegal material. Whether monitoring an entire population by default is an acceptable way to reach that fraction, rather than a targeted approach aimed at those already under suspicion, is a legitimate question in its own right, separate from whether the scanning technology can even be built securely.",[11,32,33],{},"There's a practical objection too, and it cuts at whether the approach would work at all. People distributing child sexual abuse material are, by definition, already breaking the law and already have reason to avoid detection. Client side scanning targets known material moving through mainstream, regulated messaging apps. It does nothing to stop someone from switching to an app outside the regulation's reach, encrypting a file before sending it through a scanned channel, or using any of the other methods that were never going to be caught by scanning one category of consumer app. Once the people the law is actually aimed at simply route around it, the real world results could end up close to zero, while everyone else's private messaging remains subject to scanning that was never able to reach its intended target in the first place.",[11,35,36],{},"And there's a fourth angle worth considering, one that isn't hypothetical. We've written before on this blog about Salt Typhoon, the campaign that spent years inside the lawful intercept systems US carriers were legally required to build for government-authorized wiretapping. That infrastructure existed for a narrow, sanctioned purpose. It ended up being used by an outside actor instead, exposing the same access point it was built around. A mandated scanning mechanism embedded in every device for CSAM detection has the same basic shape, a standing detection capability built into an entire population's devices, all running the same mechanism, all reachable through whatever controls it. If a system like that were compromised the way Salt Typhoon compromised carrier wiretap infrastructure, the exposure wouldn't stop at catching illegal content, it would be a window into the private communications of everyone the scanning was built to cover, through a single point of failure. Given how attractive a mandated, universally deployed detection system would be to exactly the kind of state-level actor Salt Typhoon has already shown can get inside comparable mandated access points, that's a risk worth weighing seriously, not dismissing as unlikely.",[18,38,40],{"id":39},"why-this-debate-keeps-resurfacing","Why this debate keeps resurfacing",[11,42,43],{},"Chat Control hasn't failed because of a lack of political will behind it. It's failed repeatedly to secure the specific majority required under EU procedure, only for successive Council presidencies to bring a modified version back. Each new version tends to adjust scope, exemptions, or voting mechanics rather than abandoning the core requirement. That pattern is worth watching closely, because a proposal that keeps returning in slightly different form is one that eventually finds a version of the procedure that lets it through.",[18,45,47],{"id":46},"where-closed-self-hosted-architecture-sits-in-this-conversation","Where closed, self-hosted architecture sits in this conversation",[11,49,50],{},"Silentel wasn't built as a mass market consumer app offering a service to the general public. It's deployed by individual government and enterprise customers, each running their own instance, controlling their own user base, and setting their own policy for what happens inside their own organization. That's a meaningfully different starting point from the platforms this legislation is primarily aimed at, which serve hundreds of millions of members of the public with no relationship to any single organization's governance.",[11,52,53],{},"That distinction matters architecturally, but it's not a substitute for legal advice. Whether and how any specific regulation applies to any specific deployment depends on jurisdiction, deployment model, and the final text of a law that is still being negotiated, and that's a conversation for an organization's own legal counsel, not something to assume from a blog post.",[11,55,56],{},"What is fair to say is this: an architecture built around organizational control from the outset, rather than one built for anonymous, at scale public use, starts from a fundamentally different design position than the platforms this debate has mostly been about. As Chat Control continues to evolve, that's a distinction worth understanding clearly, both for what it does and doesn't mean.",{"title":58,"searchDepth":59,"depth":59,"links":60},"",2,[61,62,63],{"id":20,"depth":59,"text":21},{"id":39,"depth":59,"text":40},{"id":46,"depth":59,"text":47},"2025-07-15","The EU's long-running push to mandate message scanning keeps resurfacing, and it raises real questions for how encrypted platforms are built.",false,"md","\u002Fimages\u002Fblog\u002Fblog-default-hero.png",null,{},true,"\u002Fblog\u002Feu-chat-control-encryption-legislation",5,{"title":5,"description":65},"blog\u002F2025-07-15-eu-chat-control-encryption-legislation",[77,78,79,80],"security","government","encryption","eu-policy","a_hzzCSbERx5d0aAczMnMjyF_uKsYC1ul1LUYLlRI_8",[83,88],{"path":84,"title":85,"tags":86},"\u002Fblog\u002Fdhs-hsin-breach-world-cup-coordination","When the Platform Built to Coordinate Security Becomes the Incident",[77,78,87],"third-party-risk",{"path":89,"title":90,"tags":91},"\u002Fblog\u002Ffbi-dcsnet-wiretap-breach","When the Surveillance Infrastructure Itself Becomes the Target",[77,78,92,93],"surveillance","telecom",1787861245369]