Chat Control
Chat Control is an admission of failure from the EU on two counts; they have failed to protect children and they have failed to propose any effective solution. It also constitutes mass surveillance whilst failing to prohibit serious malefactors.
Blatant Eschatology
Lobbyism and the technological illiteracy among policy-makers is leading us into the Death of Privacy. And rudimentary use of ubiquitous tools by nefarious individuals will render any policy outcome they dream up null and void. All for naught.
Yes, I'm being dramatic. No, I'm not overreacting.
Pretty Good Privacy
Pretty Good Privacy (PGP), just some maths, protocol, and procedure has been around since 1991.
It is not state-of-the-art, but it is dead simple to use. And effective.
GnuPG (GPG) is one of many ubiquitous tools that implements the OpenPGP standard. With it you can encrypt a message or file lickety-split, and be sure that only the intended recipient can access the contents; We are talking all-of-human-computation-until-the-sun-explodes safe*.
Let's say I want to share CSAM, terrorist plans, black-mail material, plans to steal the Declaration of Independence, etc with my trusted compatriot Mr. Nefarious. It's as easy as:
gpg -e -r nefarious@recipient.com things_that_would_get_us_arrested.zip
This creates a things_that_would_get_us_arrested.zip.gpg which I can send over any platform I'd like, without risk. I could send this via email using my personal gmail, CC'ing Interpol; I could post this to Mr. Nefarious Facebook page; I could SMS, Message, WhatsApp, whatsever - and be certain no-one could access the material without full access to Mr. Nefarious (probably encrypted) personal computer. At least not this side of Sol going nova**.
And Mr. Nefarious just runs:
gpg -d things_that_would_get_us_arrested.zip.gpg > things_that_would_get_us_arrested.zip
To get full access.
-^-o-^-o-^-o-^-o-^-
Lets say you are Interpol monitoring a forum called criminal-hub.io and you see this transpire:
*Chazz 2026-07-30:07:51*
Hey you got that *razzmatazz*?
*Rex 2026-07-30:07:53*:
Yup, here comes:
-----BEGIN PGP MESSAGE-----
jA0ECQMKp/cBiAfWaXX/0kUB6C2izfGZShCoUrArqhqOAnTDZ1gO77T70N1BzXjk
XZm4ZD7jFJAi9dNkt1po/db9GuLtJ2EvqW+O4UhzxQEitVuJ6Ho=
=hpuG
-----END PGP MESSAGE-----
Just what are you going to accuse anyone of? You could point to metadata: "Chazz" and "Rex" on an obviously dubious site, one sending the other something encrypted. That might form part of a circumstantial case - if you ever catch them. But it won't tell you what was shared, or with whom else, or whether it was illegal at all. And it certainly won't trigger an automated scan.
-^-o-^-o-^-o-^-o-^-
Now also remember that this technology can be, and is, used by whistleblowers, freedom and civil rights activists, journalists, reporters under oppressive tyranny and people wanting to express themselves and connect in fear of bigotry.
A way to communicate privately is important. It is a human right.
Chat Control won't stop but the most luddite abusers at the cost of basic human rights.
Data At Rest
Alright, so anyone can encrypt data before it hits a platform that can be coerced into scanning all communication or becomes data in flight. Then the answer is to scan all devices, all the time!
That Orwellian Torment Nexus must surely be someone's fetish.
How does the term client side scanning or detection obligations on providers of interpersonal communications and related devices hit you?
Like a ton of bricks, I hope.
As it stands, Chat Control does not involve client-side, full-disk or OS-level scanning. But let's imagine that Chat Control 2 is passed and a year or so later lo and behold! it was utterly ineffective - whodda thunk? Also imagine now that instead of a sensible and rational repeal policy-makers double down; they are just not scanning enough! They need your data at rest.
Now if they're monitoring the entirety of your digital life - what is left?
Client side scanning comes next. It's no different than installing a camera in your home. It's for the children.
A Thorn In One's Side
Thorn, a child-protection NGO (lobbyist for detection mandates) is very much involved in Chat Control. According to Ylva Johansson, the proposals primary architect and promoter, Chat Control is a "close collaboration" with Thorn as technical expert (vendor with product-market fit).
Thorn is a lobby organisation with deep pockets, top access to EU home-affairs politics and a lot to earn.
Failing Forwards
Chat Control is built on a dubious foundation and with spurious motives. It will constitute mass surveillance of unsuspecting innocent people while only adding more hay to the hay stack we desperately want to find needles in. Any perpetrator using encryption today will circumvent their scans and back-doors without a hitch.
Indiscriminate automatic scanning, classification and reporting of CSAM material comes with such risks for your normal everyday internet user it might, at least for a while, render the internet as we know it defunct and any attempts by relevant agencies to combat abusers impossible.
-^-o-^-o-^-o-^-o-^-
Me, a recently become father, mortified and physically ill when hearing of children in harm's way - I am appalled that our elected representatives who are failing to keep our children safe are spending this much time and effort and money on something as toothless as Chat Control.
Me, a recently become father, with a phone overfull of photos from weekends at the beach, the first bathtime, that catastrophe diaper incident - I am scared.