Chat Control: what it is — and why ZERO builds against it
The proposed EU regulation to fight abuse material (officially the CSA Regulation, nicknamed “Chat Control”) could oblige providers to scan private communication on the device itself — before a message is encrypted. That is precisely what undermines end-to-end encryption at its core.
What it is
Client-side scanning means: your phone runs a check against a database of your photos and messages — before encryption kicks in. Once the scanner is there, it is technically extensible to arbitrary content. “Against abuse material” quickly becomes a precedent for mass surveillance without any concrete suspicion.
Current status
The text has been bouncing between Council, Parliament and trilogue for years. Mandatory scanning of end-to-end encrypted services was off the table at times, but keeps resurfacing in new drafts. As of August 2026 we are tracking it continuously — this post is updated whenever something solid changes.
What you can do
- Use end-to-end messengers — Signal (or the hardened fork Molly), Threema.
- Hardware without bugs — devices whose microphones/sensors you control.
- Stay informed & apply pressure — this regulation is decided politically, not technically.
Why ZERO builds against it
Our devices assume the opposite: data minimisation, an auditable open-source base (GrapheneOS), no tracking. A mandate to scan devices is diametrically opposed to that — which is why we cover the development here instead of ignoring it.
This post is a living document. We add corrections and sources as we go.