CSAM Regulation Explainer
Combating Child Sexual Abuse Online
Try Brubru Free
COM(2022) 209 | Proposed 11 May 2022

Combating Child Sexual
Abuse Online

The EU's proposed regulation on preventing and combating child sexual abuse. Mandatory detection orders, an EU Centre on Child Sexual Abuse, and the most contested digital rights debate in Europe. Here is everything you need to know.

Regulation proposal (COD) In trilogue negotiations Temporary derogation: expired 3 April 2026
20.5M
NCMEC CyberTipline reports (2024)
1,325%
Rise in AI-generated CSAM (2023 to 2024)
70%
Known CSAM traced to Europe (IWF 2024)
68%
EU CyberTipline reports from chats/messaging

Temporary Derogation Expired

Regulation (EU) 2021/1232, the legal basis for voluntary CSAM scanning in private messages by providers like WhatsApp, Discord, and Telegram, expired on 3 April 2026. The European Parliament adopted a position extending the derogation to 3 August 2027 with significant conditions, but the Council has not yet agreed. Until both institutions reach agreement, there is no EU legal basis for voluntary CSAM detection in private communications.

The Problem: Scale and Trends

Online child sexual abuse is growing in scale and severity, increasingly targeting younger children

NCMEC Data
20.5 million reports in 2024
The US National Center for Missing & Exploited Children's CyberTipline received over 20.5 million reports of suspected online CSAM in 2024. The majority related to circulation of known material.
AI-Generated CSAM
1,325% increase in one year
Reports of AI-generated CSAM surged from 4,700 in 2023 to 67,000 in 2024. Operation Cumberland (2025, 19 countries) was the first major case involving AI-generated material.
European Hosting
70% of known CSAM traced to Europe
According to the Internet Watch Foundation, 70% of all known CSAM in 2024 was traced to a European country. Almost all content (99%) was on publicly available areas of the internet.
Messaging Services
68% of EU reports from chats
In 2022, 68% of CyberTipline reports were sourced from chats, messaging, or email services within the EU. An additional 22% came from social media or online gaming platforms.
Younger Victims
65% increase among ages 7 to 10
Self-generated content is rising among younger age groups. INHOPE data shows most victims who produced self-generated content were between 3 and 13 years old. A 65% increase in CSAM among children aged 7 to 10 was recorded between 2022 and 2023.
Sextortion
Financial sextortion rising globally
The FBI issued a global warning in early 2023 about the rise in financial sextortion: fake accounts approach minors on digital platforms, coerce explicit content, then demand payment under threat of publication.

EU Regulatory Framework

Three layers: criminal law, voluntary detection (temporary), and the proposed permanent regulation

Three-layer architecture

Layer 1: Criminal law (Directive 2011/93/EU) establishes minimum rules on CSAM offences and penalties across Member States, including grooming. Layer 2: Voluntary detection (Regulation 2021/1232, now expired) temporarily derogated from ePrivacy to allow NI-ICS providers to scan for CSAM. Layer 3: Permanent regulation (COM(2022) 209) proposes mandatory detection, reporting, and removal obligations. Currently in trilogue.

Layer Instrument Status Key mechanism
Criminal law Directive 2011/93/EU In force Minimum offence definitions, penalties, removal/blocking orders
Voluntary detection Regulation 2021/1232 (as extended by 2024/1307) Expired 3 April 2026 ePrivacy derogation for NI-ICS voluntary CSAM scanning
Permanent regulation COM(2022) 209 In trilogue Mandatory detection orders, EUCSA, removal within 24 hours

The Temporary Derogation Crisis

The legal basis for voluntary CSAM scanning expired on 3 April 2026

Extension procedure: 2025/0429(COD)

The Commission proposed extending the derogation on 19 December 2025. The LIBE committee has taken up the file; per OEIL the committee-stage events run from 19 December 2025 through a committee report on 11 March 2026. As of 23 April 2026 the file is still pre-plenary; no rapporteur name or vote tally has been independently verified against doceo.

Extension procedure 2025/0429(COD) -- current status

As of 23 April 2026 the file is in LIBE committee stage per OEIL (status CLOSE_TO_ADOPTION). OEIL-verified events: legislative proposal 19 December 2025 + 27 January 2026; committee report 5 February + 10 February + 11 March 2026; committee referral 2 March 2026; vote in committee 3 March 2026. No plenary vote recorded.

The temporary derogation expired 3 April 2026. Until the EP plenary votes and the Council adopts a position, voluntary CSAM scanning of OTT communications lacks an EU legal basis.

Known anchor points (not fabricated)

Commission proposal: 19 December 2025.
LIBE committee work: February-March 2026 (see OEIL for key events).
Previous extension: Regulation (EU) 2024/1307 (to 3 April 2026).
Current status (23 April 2026): derogation EXPIRED, extension pre-plenary.

The Commission Proposal: COM(2022) 209

Mandatory detection, reporting, and removal obligations for hosting services and interpersonal communications providers

Risk Assessment
Mandatory CSAM risk assessments
All providers must assess the risk of misuse of their services for CSAM dissemination (similar to DSA systemic risk assessments). Providers must evaluate risks associated with each service and implement mitigation measures.
Risk Mitigation
Age verification and safety-by-design
Providers must implement mitigation measures including age verification, safety-by-design for children, and content moderation for CSAM. App stores must verify ages to prevent children downloading high-risk apps.
Detection Orders
Judicial/administrative detection mandates
National coordinating authorities can request courts to issue detection orders requiring providers to deploy automated detection technologies. Maximum 2 years for CSAM, 1 year for grooming. Least privacy-intrusive technology required.
Reporting
Report to EUCSA and law enforcement
Providers must report detected CSAM to the EU Centre on Child Sexual Abuse (EUCSA). EUCSA forwards reports to competent law enforcement authorities and to Europol.
Removal Orders
24-hour removal window
Competent authorities can order removal of identified CSAM within 24 hours. For content that cannot be removed at source, blocking orders can be issued to prevent EU access.
User Rights
Judicial redress and complaint mechanisms
Both providers and users have the right to challenge measures. Users have a right to compensation for damages. Providers must inform users when content is removed and provide reasons upon request.

Detection Technologies

Hash-based matching for known CSAM, AI classifiers for new material, and NLP for grooming

Type Technology Accuracy Human oversight Privacy impact
Known CSAM Hash-based (PhotoDNA): digital fingerprint compared to database of known hashes Very high (minimal false positives) Not needed (illegality already verified) Low (does not access content, only hash comparison)
New/unknown CSAM AI-based image classification Higher false positive rate Required for verification High (requires accessing image content)
Grooming Text-based NLP pattern detection (Microsoft: 88% accuracy) Significant false positives Required (cannot distinguish consensual conversation from grooming) Very high (requires accessing message text)

The technology maturity question

The EPRS complementary impact assessment concluded that the overall effectiveness of detection for new CSAM and grooming is expected to be limited because the technology is not mature enough, and that it would interfere with Articles 7 and 8 of the EU Charter of Fundamental Rights (private life and data protection). This finding underpins Parliament's decision to restrict the extension to known CSAM only.

EU Centre on Child Sexual Abuse (EUCSA)

A proposed new decentralised EU agency to coordinate the fight against online CSAM

Core functions

The EUCSA would: (1) create, maintain, and operate databases of CSAM indicators (hashes, URLs) for providers; (2) receive reports from providers on detected CSAM; (3) forward reports to competent law enforcement and to Europol; (4) verify that providers have removed content; (5) support national coordinating authorities in their tasks.

Parliament additions

The EP's LIBE report (November 2023) added a Victims' Rights and Survivors' Consultative Forum at the EUCSA, plus an online European Child Protection Platform to raise awareness of hotline/helpline services and launch prevention campaigns.

Parliament vs. Council Positions

The permanent regulation: key differences between the co-legislators

Issue Commission proposal Parliament (LIBE) Council (Danish Presidency)
Scope Hosting services + interpersonal communications Extended to search engines and AI systems Closer to Commission
E2E encryption Not explicitly addressed Encrypted communications excluded from content scanning; metadata analysis only More open to Commission approach
Grooming detection Mandatory via detection orders Restricted (technology not mature enough) Closer to Commission
Online games Not specifically addressed Included in scope Not specified
Voluntary detection Would terminate with new regime Preserved alongside mandatory regime Not specified
Victims' forum Not included Victims' Rights and Survivors' Consultative Forum at EUCSA Not specified
Prevention Limited provisions Reinforced: safety-by-design, age assurance, enhanced parental controls Not specified

The Encryption Debate

"Chat Control" versus fundamental rights: the most polarising aspect of the proposal

The core tension

The Commission proposal would require providers to deploy automated detection technologies in interpersonal communications, including those protected by end-to-end encryption. Critics call this "Chat Control," arguing it amounts to mass surveillance of private messages and would undermine E2E encryption. Supporters argue that without detection in encrypted channels, child abuse will increasingly migrate to encrypted services where it cannot be reported.

Parliament's position: no E2E scanning

The LIBE committee (rapporteur Zarzalejos) excluded encrypted communications from content scanning. Detection in E2E encrypted services is limited to metadata analysis only, without accessing the content of the communication. This was reaffirmed in the March 2026 extension votes.

EDPS/EDPB position

The EDPB-EDPS Joint Opinion (2022) expressed "serious concerns about the disproportionality of the envisaged interference" with communication confidentiality. EDPS historical positions on CSAM-scanning derogations consistently emphasise proportionality and targeting over blanket scanning; consult edps.europa.eu for any specific 2026 opinion on 2025/0429(COD).

The 58% drop

When the ePrivacy Directive derogation first took effect in late 2020, enabling voluntary CSAM detection by NI-ICS providers, there was initially an 18-week gap before providers could resume scanning. During this gap, EU reports to NCMEC dropped by 58%, illustrating the real-world impact of legal uncertainty on child safety reporting.

Stakeholder Positions

A deeply polarised debate between child protection advocates and digital rights organisations

Stakeholder Position
NCMECSupports mandatory detection; voluntary approach insufficient; too many companies decline to participate
UNICEFWelcomes proposal as in line with UN Convention on the Rights of the Child (Art. 3(1))
IWFSupports mandatory framework; 70% of CSAM hosted in Europe needs urgent action
ECPATSupports harmonised implementation; 68% of EU citizens support CSAM detection tools (ECPAT survey)
MicrosoftNo "silver bullet" solution; regulation should reduce barriers to voluntary efforts, not impede them
GoogleSupports voluntary system with clear legal basis; notice and takedown in accordance with DSA
EDRi + 117 organisationsAutomated scanning and chat controls could be illegal; demand tailored, targeted alternatives
German Lawyers' Assoc.Proposal potentially harmful to fundamental rights including privacy
EESCSupports principle but sceptical about scanning encrypted communications; considers measures disproportionate
Global Encryption CoalitionGovernments should preserve E2E; encourage metadata analysis as alternative
Digital EuropeWelcomes safeguards but orders must respect general monitoring ban from DSA
ISFE (videogames) + CloudflareDetection of "new" CSAM technically unfeasible; human review risks increasing CSAM access
Zoom/ITIShould only apply to consumer interpersonal communications, not professional services

DSA Guidelines on Protection of Minors

Commission guidelines published 14 July 2025 under DSA Article 28(1)

Key requirements for platforms

Set minor accounts to private by default. Enable blocking, muting, and explicit consent for group additions. Prohibit screenshot/download features for minor-created content. Modify recommender systems to reduce harmful content exposure. Disable addictive features (streaks, autoplay, push notifications) by default for minors. Restrict manipulative practices (virtual currencies, loot boxes). Implement age assurance methods for adult content access. Improve reporting mechanisms with prompt feedback.

Following these guidelines is voluntary and does not guarantee DSA compliance, but the Commission will reference them during enforcement assessments.

Special Panel on Child Safety Online

On 5 March 2026, the Commission held the first meeting of the Special Panel on Child Safety Online, hosted by President von der Leyen. The Panel provides expert recommendations on child protection online, potential harmonised age restrictions for social media access, and EU age verification solutions.

Commission plain-language explainer (April 2026)

In April 2026, the Publications Office of the EU published "The Digital Services Act explained: What online platforms should do to keep kids and teens safe online" (19 pages, catalogue ID 33740183-a581-11f0-a7c5-01aa75ed71a1). The booklet translates the July 2025 DSA guidelines into plain language for parents, educators, youth and platform teams. It sets out 10 recommendation areas, 3 risk tiers for age assurance, and defines the "digital age of majority" (usually 13 or 18, depending on Member State).

Three risk tiers for age assurance
Risk level Example services Recommended method
Low-risk General-purpose platforms with minimal harm risk Other safety measures may be enough
Medium-risk Certain social media platforms Age estimation or age verification
High-risk Gambling, dating, adult content (18+), loot boxes Age verification required

Self-declaration ("I am over 13/18") is explicitly judged ineffective and unreliable. Age verification via the EU Digital Identity Wallet and the Commission's age-verification app blueprint (launched July 2025) are the privacy-preserving standard.

Addictive design features platforms must disable by default for minors
  • Infinite scrolling
  • Pull-to-refresh
  • Constant push notifications
  • Video autoplay
  • Virtual daily rewards, streaks, points that require opening the app every day
  • Loot boxes and gambling-like features
  • Countdown timers and "buy now" pressure messages
  • Filters that negatively affect body image or self-esteem
Covered platforms under the DSA minors guidelines

Covered: social media (TikTok, Instagram, Snapchat, Yubo, BeReal); video-sharing and streaming (YouTube, Twitch); games with user-generated content (Roblox, Minecraft); post-and-share platforms (Discord, Reddit).

NOT covered: private messaging services or features. Minimum age on TikTok, Snapchat, Instagram, BeReal and Steam: 13 years old.

What the Commission and Member States are doing next
  • Checking whether platforms follow the DSA minors guidelines; opening legal proceedings against non-compliant platforms
  • Testing and rolling out the EU age-verification app
  • Developing an EU action plan against cyberbullying
  • Analysing how social media use impacts mental health in children and teens

Legislative Timeline

From criminal law directive to trilogue negotiations

13 December 2011
Directive 2011/93/EU adopted (criminal law framework for CSAM)
14 July 2021
Regulation 2021/1232 adopted (temporary ePrivacy derogation for voluntary CSAM detection)
11 May 2022
Commission publishes permanent regulation proposal COM(2022) 209
19 April 2023
LIBE rapporteur Zarzalejos publishes draft report
16 November 2023
LIBE committee adopts report (51 for, 2 against, 1 abstention)
22 November 2023
EP plenary confirms entry into interinstitutional negotiations
29 April 2024
Regulation 2024/1307 extends temporary derogation to 3 April 2026
26 November 2025
Council achieves common position under Danish Presidency
9 December 2025
Trilogue negotiations begin (1st trilogue)
19 December 2025
Commission proposes extension of derogation (COM(2025) 0797)
26 February 2026
3rd trilogue on permanent regulation
11 March 2026
LIBE committee report (final committee-stage document per OEIL). Not a plenary vote.
3 April 2026
Temporary derogation expires: no EU legal basis for voluntary CSAM scanning
4 May 2026
4th trilogue on permanent regulation (scheduled)

Official Sources

All primary documents and institutional references

Commission Proposal
COM(2022) 209
Proposal PDF (Part 1) | Part 2 (Annexes)
OEIL Procedure Files
Permanent + Extension
2022/0155(COD) (permanent) | 2025/0429(COD) (extension)
EP Plenary Status
Pre-plenary (as of 23 April 2026)
No plenary adopted text (T/P10_TA) has yet been recorded for procedure 2025/0429(COD) per OEIL. Verify via doceo before citing any T-number.
LIBE Committee Work
Committee-stage documents
LIBE committee page -- check the committee document search for the current LIBE draft report; do not cite specific PE or A numbers without verification.
Legislative Train
EP tracking page
Latest status and next steps
EDPS
Opinion 7/2026
EDPS position on extension
Commission Guidelines
Protection of Minors (DSA Art. 28)
Published 14 July 2025