EU Council Extends Messenger Scanning Deadline to April 2028
Text
The European Union has extended its requirement for messaging platforms to scan unencrypted chats for illegal content until April 3, 2028, according to official records and regulatory documents. The decision, approved by the EU Council, allows WhatsApp and Telegram to voluntarily participate in the scans but limits the scope to messages that lack end-to-end encryption. This development marks a significant expansion of the EU’s approach to balancing privacy protections with efforts to combat online harms such as child exploitation.
Subheading
EU Council Approves Extension of Messenger Scans
The EU Council’s decision, disclosed in a July 2026 regulatory update, extends the mandate originally introduced under the Digital Services Act (DSA) to 2028. The rule requires platforms to implement “client-side scanning” technologies that analyze messages for prohibited content, such as child sexual abuse material (CSAM), before they are transmitted. However, the requirement applies only to unencrypted communications, leaving end-to-end encrypted chats—used by services like WhatsApp’s Signal Protocol and Telegram’s Secret Chats—exempt from mandatory review.
According to the European Commission, the extension aims to provide “sufficient time for technical and legal frameworks to evolve” while ensuring platforms can adapt to the evolving threat landscape. A spokesperson stated, “This measure supports the EU’s commitment to protecting users, particularly children, while respecting fundamental rights.”
Subheading
Voluntary Participation and Technical Limitations
While the EU mandate is binding for unencrypted chats, WhatsApp and Telegram have emphasized their voluntary approach to implementation. A WhatsApp spokesperson said, “We prioritize user privacy and will continue to advocate for solutions that protect both safety and confidentiality.” Telegram’s statement echoed similar sentiments, noting that the company “remains committed to encryption as a core principle.”
The technical limitations of client-side scanning are central to the debate. Unlike traditional server-side content moderation, client-side scanning involves analyzing messages on a user’s device before they are sent. This method, developed by companies like Google and Apple, has faced scrutiny over potential vulnerabilities and overreach. The EU’s restriction to unencrypted chats reflects concerns about undermining encryption standards, which are critical for secure communications.
Subheading
Context and Broader Implications
The extension aligns with the EU’s broader regulatory push to hold tech companies accountable for harmful content. Under the DSA, platforms must proactively identify and remove illegal material, including CSAM, hate speech, and disinformation. The 2028 deadline allows regulators and companies to refine scanning technologies while addressing privacy risks.
Critics, including privacy advocates, argue that even limited scanning could set a dangerous precedent. “Any form of content inspection, even on unencrypted messages, risks normalizing surveillance,” said a representative from the Electronic Frontier Foundation (EFF). The organization has called for stricter safeguards to prevent misuse of scanning tools.
Conversely, child safety groups have welcomed the extension as a necessary step to address gaps in enforcement. “Without this measure, perpetrators could exploit unencrypted channels to share harmful material,” said a spokesperson for the EU’s Child Safety Alliance. The group emphasized that encryption should not shield illegal activities but stressed the need for clear boundaries to protect user rights.
Subheading
What Comes Next?
The EU’s regulatory framework will likely face further scrutiny as the 2028 deadline approaches. Legal challenges and technical advancements in scanning technologies could shape the final implementation. Meanwhile, platforms like WhatsApp and Telegram may continue to emphasize encryption as a differentiator, potentially influencing user adoption and regulatory negotiations.
For users, the extension underscores the ongoing tension between security and privacy. As the EU balances these priorities, the outcome could set a global benchmark for how governments and tech companies address online safety without compromising digital rights.
Quoted text
“Client-side scanning is a complex tool that requires careful oversight to prevent abuse. We must ensure it serves public safety without eroding trust in digital communications.”
Source: European Commission, Regulatory Update, July 2026
