The EU's proposed regulation on preventing and combating child sexual abuse. Mandatory detection orders, an EU Centre on Child Sexual Abuse, and the most contested digital rights debate in Europe. Here is everything you need to know.
Regulation (EU) 2021/1232, the legal basis for voluntary CSAM scanning in private messages by providers like WhatsApp, Discord, and Telegram, expired on 3 April 2026. The European Parliament adopted a position extending the derogation to 3 August 2027 with significant conditions, but the Council has not yet agreed. Until both institutions reach agreement, there is no EU legal basis for voluntary CSAM detection in private communications.
Online child sexual abuse is growing in scale and severity, increasingly targeting younger children
Three layers: criminal law, voluntary detection (temporary), and the proposed permanent regulation
Layer 1: Criminal law (Directive 2011/93/EU) establishes minimum rules on CSAM offences and penalties across Member States, including grooming. Layer 2: Voluntary detection (Regulation 2021/1232, now expired) temporarily derogated from ePrivacy to allow NI-ICS providers to scan for CSAM. Layer 3: Permanent regulation (COM(2022) 209) proposes mandatory detection, reporting, and removal obligations. Currently in trilogue.
| Layer | Instrument | Status | Key mechanism |
|---|---|---|---|
| Criminal law | Directive 2011/93/EU | In force | Minimum offence definitions, penalties, removal/blocking orders |
| Voluntary detection | Regulation 2021/1232 (as extended by 2024/1307) | Expired 3 April 2026 | ePrivacy derogation for NI-ICS voluntary CSAM scanning |
| Permanent regulation | COM(2022) 209 | In trilogue | Mandatory detection orders, EUCSA, removal within 24 hours |
The legal basis for voluntary CSAM scanning expired on 3 April 2026
The Commission proposed extending the derogation on 19 December 2025. The LIBE committee has taken up the file; per OEIL the committee-stage events run from 19 December 2025 through a committee report on 11 March 2026. As of 23 April 2026 the file is still pre-plenary; no rapporteur name or vote tally has been independently verified against doceo.
As of 23 April 2026 the file is in LIBE committee stage per OEIL (status CLOSE_TO_ADOPTION). OEIL-verified events: legislative proposal 19 December 2025 + 27 January 2026; committee report 5 February + 10 February + 11 March 2026; committee referral 2 March 2026; vote in committee 3 March 2026. No plenary vote recorded.
The temporary derogation expired 3 April 2026. Until the EP plenary votes and the Council adopts a position, voluntary CSAM scanning of OTT communications lacks an EU legal basis.
Commission proposal: 19 December 2025.
LIBE committee work: February-March 2026 (see OEIL for key events).
Previous extension: Regulation (EU) 2024/1307 (to 3 April 2026).
Current status (23 April 2026): derogation EXPIRED, extension pre-plenary.
Mandatory detection, reporting, and removal obligations for hosting services and interpersonal communications providers
Hash-based matching for known CSAM, AI classifiers for new material, and NLP for grooming
| Type | Technology | Accuracy | Human oversight | Privacy impact |
|---|---|---|---|---|
| Known CSAM | Hash-based (PhotoDNA): digital fingerprint compared to database of known hashes | Very high (minimal false positives) | Not needed (illegality already verified) | Low (does not access content, only hash comparison) |
| New/unknown CSAM | AI-based image classification | Higher false positive rate | Required for verification | High (requires accessing image content) |
| Grooming | Text-based NLP pattern detection (Microsoft: 88% accuracy) | Significant false positives | Required (cannot distinguish consensual conversation from grooming) | Very high (requires accessing message text) |
The EPRS complementary impact assessment concluded that the overall effectiveness of detection for new CSAM and grooming is expected to be limited because the technology is not mature enough, and that it would interfere with Articles 7 and 8 of the EU Charter of Fundamental Rights (private life and data protection). This finding underpins Parliament's decision to restrict the extension to known CSAM only.
A proposed new decentralised EU agency to coordinate the fight against online CSAM
The EUCSA would: (1) create, maintain, and operate databases of CSAM indicators (hashes, URLs) for providers; (2) receive reports from providers on detected CSAM; (3) forward reports to competent law enforcement and to Europol; (4) verify that providers have removed content; (5) support national coordinating authorities in their tasks.
The EP's LIBE report (November 2023) added a Victims' Rights and Survivors' Consultative Forum at the EUCSA, plus an online European Child Protection Platform to raise awareness of hotline/helpline services and launch prevention campaigns.
The permanent regulation: key differences between the co-legislators
| Issue | Commission proposal | Parliament (LIBE) | Council (Danish Presidency) |
|---|---|---|---|
| Scope | Hosting services + interpersonal communications | Extended to search engines and AI systems | Closer to Commission |
| E2E encryption | Not explicitly addressed | Encrypted communications excluded from content scanning; metadata analysis only | More open to Commission approach |
| Grooming detection | Mandatory via detection orders | Restricted (technology not mature enough) | Closer to Commission |
| Online games | Not specifically addressed | Included in scope | Not specified |
| Voluntary detection | Would terminate with new regime | Preserved alongside mandatory regime | Not specified |
| Victims' forum | Not included | Victims' Rights and Survivors' Consultative Forum at EUCSA | Not specified |
| Prevention | Limited provisions | Reinforced: safety-by-design, age assurance, enhanced parental controls | Not specified |
"Chat Control" versus fundamental rights: the most polarising aspect of the proposal
The Commission proposal would require providers to deploy automated detection technologies in interpersonal communications, including those protected by end-to-end encryption. Critics call this "Chat Control," arguing it amounts to mass surveillance of private messages and would undermine E2E encryption. Supporters argue that without detection in encrypted channels, child abuse will increasingly migrate to encrypted services where it cannot be reported.
The LIBE committee (rapporteur Zarzalejos) excluded encrypted communications from content scanning. Detection in E2E encrypted services is limited to metadata analysis only, without accessing the content of the communication. This was reaffirmed in the March 2026 extension votes.
The EDPB-EDPS Joint Opinion (2022) expressed "serious concerns about the disproportionality of the envisaged interference" with communication confidentiality. EDPS historical positions on CSAM-scanning derogations consistently emphasise proportionality and targeting over blanket scanning; consult edps.europa.eu for any specific 2026 opinion on 2025/0429(COD).
When the ePrivacy Directive derogation first took effect in late 2020, enabling voluntary CSAM detection by NI-ICS providers, there was initially an 18-week gap before providers could resume scanning. During this gap, EU reports to NCMEC dropped by 58%, illustrating the real-world impact of legal uncertainty on child safety reporting.
A deeply polarised debate between child protection advocates and digital rights organisations
| Stakeholder | Position |
|---|---|
| NCMEC | Supports mandatory detection; voluntary approach insufficient; too many companies decline to participate |
| UNICEF | Welcomes proposal as in line with UN Convention on the Rights of the Child (Art. 3(1)) |
| IWF | Supports mandatory framework; 70% of CSAM hosted in Europe needs urgent action |
| ECPAT | Supports harmonised implementation; 68% of EU citizens support CSAM detection tools (ECPAT survey) |
| Microsoft | No "silver bullet" solution; regulation should reduce barriers to voluntary efforts, not impede them |
| Supports voluntary system with clear legal basis; notice and takedown in accordance with DSA | |
| EDRi + 117 organisations | Automated scanning and chat controls could be illegal; demand tailored, targeted alternatives |
| German Lawyers' Assoc. | Proposal potentially harmful to fundamental rights including privacy |
| EESC | Supports principle but sceptical about scanning encrypted communications; considers measures disproportionate |
| Global Encryption Coalition | Governments should preserve E2E; encourage metadata analysis as alternative |
| Digital Europe | Welcomes safeguards but orders must respect general monitoring ban from DSA |
| ISFE (videogames) + Cloudflare | Detection of "new" CSAM technically unfeasible; human review risks increasing CSAM access |
| Zoom/ITI | Should only apply to consumer interpersonal communications, not professional services |
Commission guidelines published 14 July 2025 under DSA Article 28(1)
Set minor accounts to private by default. Enable blocking, muting, and explicit consent for group additions. Prohibit screenshot/download features for minor-created content. Modify recommender systems to reduce harmful content exposure. Disable addictive features (streaks, autoplay, push notifications) by default for minors. Restrict manipulative practices (virtual currencies, loot boxes). Implement age assurance methods for adult content access. Improve reporting mechanisms with prompt feedback.
Following these guidelines is voluntary and does not guarantee DSA compliance, but the Commission will reference them during enforcement assessments.
On 5 March 2026, the Commission held the first meeting of the Special Panel on Child Safety Online, hosted by President von der Leyen. The Panel provides expert recommendations on child protection online, potential harmonised age restrictions for social media access, and EU age verification solutions.
In April 2026, the Publications Office of the EU published "The Digital Services Act explained: What online platforms should do to keep kids and teens safe online" (19 pages, catalogue ID 33740183-a581-11f0-a7c5-01aa75ed71a1). The booklet translates the July 2025 DSA guidelines into plain language for parents, educators, youth and platform teams. It sets out 10 recommendation areas, 3 risk tiers for age assurance, and defines the "digital age of majority" (usually 13 or 18, depending on Member State).
| Risk level | Example services | Recommended method |
|---|---|---|
| Low-risk | General-purpose platforms with minimal harm risk | Other safety measures may be enough |
| Medium-risk | Certain social media platforms | Age estimation or age verification |
| High-risk | Gambling, dating, adult content (18+), loot boxes | Age verification required |
Self-declaration ("I am over 13/18") is explicitly judged ineffective and unreliable. Age verification via the EU Digital Identity Wallet and the Commission's age-verification app blueprint (launched July 2025) are the privacy-preserving standard.
Covered: social media (TikTok, Instagram, Snapchat, Yubo, BeReal); video-sharing and streaming (YouTube, Twitch); games with user-generated content (Roblox, Minecraft); post-and-share platforms (Discord, Reddit).
NOT covered: private messaging services or features. Minimum age on TikTok, Snapchat, Instagram, BeReal and Steam: 13 years old.
From criminal law directive to trilogue negotiations
All primary documents and institutional references