EU Council Quietly Revives Chat Control 1.0 Messenger Scanning

EU Council voted an identical copy of the expired April Chat Control regulation back into law via written procedure, ahead of the summer recess vote.

A bronze statue of Lady Justice holding weighing scales, a symbolic depiction of rule-of-law and procedural regularity in EU legislative processes.

On July 2, 2026, the Council of Ministers voted a substantively identical copy of the EU’s Chat Control 1.0 regulation back into existence - using a written procedure so an act that formally expired on April 3 could be technically “renewed” without the usual parliamentary fight. The Parliament’s second-reading vote is now scheduled for the last day before summer recess, when assembling the absolute blocking majority required to reject the position becomes a logistical problem in its own right. If the procedural sprint lands, voluntary AI and hash scanning of encrypted messenger, webmail, and VoIP traffic resumes in the EU on a 12-month default retention floor under an E-Privacy Directive exception that the same Council already conceded was contested in 2022. None of the technical guardrails the digital rights community spent five years negotiating show up in the new draft - it is the same regulation, repackaged to dodge the calendar. It fits the same pattern we have already documented in EU policy fights: when the European Parliament disabled Microsoft Copilot and other AI features on its own members’ devices over data-sovereignty concerns, the legislative body and the Council were already pulling in opposite directions on the same set of AI tools.

The procedural trick

The original Chat Control 1.0 was a 2021 temporary exemption from Article 5 of the E-Privacy Directive, passed to let messaging, webmail, and VoIP providers run voluntary AI and hash-matching scans for known child-sexual-abuse-material (CSAM) and AI-grooming patterns on private chats. According to Heise’s July 4 timeline, the regulation lapsed on April 3, 2026, after Council and Parliament could not agree on a renewal. Heise and Netzpolitik’s leak of internal German delegation documents both report that the Council’s response was to introduce a new legislative proposal substantially identical to the expired act - rather than extending the old one - and to push it onto the Parliament’s agenda for an urgent-procedure vote the week of July 14, ahead of summer recess.

Because the file is now formally in second reading, the Council’s position can only be rejected by an absolute majority of MEPs - a threshold that, as Heise notes, has historically been “almost insurmountable shortly before the summer break.” Netzpolitik quotes an internal Bundesinnenministerium instruction that explicitly frames the priority as the fastest possible restoration of the pre-expiry legal status, regardless of the Parliament’s prior vote: “Die schnellstmögliche Wiederherstellung der Rechtslage vor Auslaufen der Interims-Verordnung hat höchste Priorität.” The Parliament’s rapporteur for the interim regulation, Birgit Sippel, has already publicly rejected the move, calling it a “unlauteres Manöver” - a procedural sleight of hand - and stating she will not support an extension on member-state terms.

The technical reach and the retention floor

The text of the new draft is, per both Heise and Netzpolitik’s reproduced German delegation positions, materially identical to the regulation that lapsed in April: voluntary AI-based detection of known CSAM via hash matching, plus AI-grooming classifiers on the same messenger, webmail, and VoIP services. Heise flags one specific quantitative change worth pulling out: the new draft mandates that processed content and traffic data be “irrevocably deleted no later than twelve months after detection” absent a confirmed concrete suspicion. That is a defensible default by EU data-retention standards, but it is also the first formal retention floor for AI-screened private communications in EU law, and it was inserted without an impact assessment.

The same procedure Germany pushed internally makes the operational scope explicit. The Bundesinnenministerium instruction cited by Netzpolitik sets the German negotiating position as: voluntary scanning “should not be restricted in scope and should cover both known and unknown CSAM content as well as grooming.” That phrasing - “known and unknown” content, “grooming” alongside CSAM - is the substantive red flag. Unknown-content classification is the technical step where AI classifiers decide, with no human in the loop, whether a piece of media resembles CSAM and should be reported. The classifiers that perform this work on major messaging platforms have published false-positive rates that, while improving year over year, remain the central operational complaint from every regulator that has audited them.

The procedural urgency is also notable against the backdrop of the still-stuck permanent regulation. Chat Control 2.0 - the mandatory scanning regime the Commission put on the table in 2022 - remains in trilogue. Netzpolitik’s leaked meeting protocols from the JI-Referent*innen session of June 30, 2026 quote the German delegation as saying “Eine Einigung im Trilog ist weiterhin nicht in Sicht” (“an agreement in the trilogue is still not in sight”), with the political trilogue rescheduled only for September 29, well after the Council’s interim vote. The Council is now asking Parliament to greenlight the same voluntary regime twice: once via the interim that Parliament just rejected, and once via the permanent regulation that may or may not clear trilogue before 2027.

Where the member states actually stand

Netzpolitik’s most striking leak is the bureaucratic cross-pressure inside the German delegation. The instruction from the Federal Ministry of the Interior is unambiguous: restore the interim immediately. A separate EU Commission official quoted at the same AStV-2 meeting, Beate Gminder, makes the time-pressure argument that providers have signaled they would “nach der Sommerpause die freiwillige Aufdeckung [einzustellen]” - that is, discontinue voluntary detection after the summer break - and the Commission line is that the Council must therefore act quickly enough for the Parliament to vote in plenary in July. The German delegate at the same meeting added the moral framing, also quoted by Netzpolitik, that the priority is “combating a serious crime against children and therefore one must not lose any time.”

What makes the bundle politically awkward is that those member states who publicly support the interim do not yet have a working majority in plenary. Netzpolitik paraphrases the Council’s own internal assessment: it is “not certain whether a majority in Parliament will form.” The urgency is, in other words, partly the cause of the procedural urgency. The Council cannot win a normal vote, so it has chosen the calendar in which Parliament is least likely to assemble a blocking majority.

What This Means

For European users of Signal, WhatsApp, Threema, Gmail, and the rest, the practical signal is that the voluntary scan machinery that briefly lapsed between April and July is on track to come back. The clause “voluntary” still matters legally - a provider can refuse - but in practice the same handful of large platforms that were scanning pre-April remain scanning under national-law readings, regardless of whether the EU exemption formally exists. EU regulators have already shown they are willing to reach inside the same messenger app stack over different grievances - the Commission is currently pushing Meta on WhatsApp AI exclusivity in parallel - so the Council’s claim that this is just a procedural housekeeping fix is going to be tested by the same week of plenary. The interim regulation restores the legal certainty those providers asked for, on the Council’s own timeline, and largely without the new technical controls civil-society groups were promised during the 2022 campaign. For journalists, lawyers, doctors, and activists who used the lapse as a brief window to recommend encrypted-messaging-first hygiene to vulnerable contacts, that window is closing.

For the rest of us, the structural lesson of this procedural trick is that an EU regulation can be renewed by repackaging it as a new act and routing it through the calendar’s weakest parliamentary week. The E-Privacy Directive carve-out first used in 2021 was already narrow, only temporary, and ostensibly subject to renewal scrutiny. That scrutiny, when it finally arrived, simply got a procedural workaround. The privacy cost - normalising AI scanning of private chats, with a 12-month retention floor for false positives that survive triage - lands without any meaningful public reset of the underlying debate.

The Bottom Line

The EU Council, on July 2, 2026, voted a substantively identical copy of the expired Chat Control 1.0 regulation back into legal effect via written procedure, scheduling a Parliament second-reading vote for the last day before summer recess. If the vote goes through, voluntary AI and hash scanning of encrypted messenger, webmail, and VoIP resumes across the EU with a 12-month retention floor for processed material. The file that ought to be the long-term fix, Chat Control 2.0, remains stuck in trilogue with no political meeting before late September. The story is the calendar as much as the substance: an expired act can be brought back to life by stitching around the parliamentary process.