Chat Control on September 29: the full dated record, and the honest answer on VPNs
On September 29, 2026, negotiators of the Council of the EU, the European Parliament and the European Commission meet at the Council building in Brussels for the sixth political trilogue on the Child Sexual Abuse Regulation, the file everyone outside Brussels calls Chat Control. Five rounds have ended without a deal. By the Council's own account, only one major question is left: whether the scanning of private messages stays voluntary, or becomes something a government can order.
Most of what has been written about September 29 is either advocacy or a one-day news item. What has been missing is one page that puts the dated record next to what the negotiation documents themselves say was decided, and what remains open. This post assembles that record, and then answers the question we get asked as a VPN provider: does a VPN protect you from any of this? The honest answer, up front, is mostly no, and we will explain exactly where the boundary runs.
What is being decided on September 29, 2026?
The trilogue is negotiating the permanent CSA Regulation, proposed by the Commission on May 11, 2022. According to the Irish presidency's July note to delegations, Council document 11501/26, the fifth trilogue on June 29 "brought significant progress by reaching provisional agreement on almost all the provisions of the proposed Regulation with the exception of detection". Scope, risk assessment, removal orders, blocking orders, delisting orders and the requirements for national authorities are settled. Voice calls are out of the Regulation entirely; voice messages stay in scope but are excluded from detection.
Detection is the block on which five trilogues have failed. The same document scheduled the endgame: technical meetings on September 10 and 18, a meeting of JHA counsellors on September 14, and the sixth trilogue on September 29 at the Council premises. A July reflection paper, WK 10939/2026, says plainly that the presidency "seeks to achieve political agreement on detection obligations and own-initiative searches at the sixth trilogue".
Is Chat Control already in force?
A voluntary version is, and its 2026 history is stranger than most coverage acknowledges: for three months this year, it was dead.
Since 2021, an interim regulation, Chat Control 1.0, has allowed providers of webmail and messaging services to scan content voluntarily for child sexual abuse material, as a derogation from EU privacy rules. Its extension ran out on April 3, 2026, after the European Parliament refused to renew it in March. The lapse was real: between April 4 and July 30, 2026, voluntary scanning by the likes of Meta, Google and Microsoft had no EU legal basis.
The revival was fast and procedurally unusual. The Council adopted a first-reading position on July 2. At second reading on July 9, the motion to reject won the vote, 314 in favour to 276 against, but rejection at second reading requires an absolute majority of all members, not just of votes cast, so the text passed anyway. The result is Regulation (EU) 2026/1881, in force since July 31, 2026 and applying until April 3, 2028.
Parliament did extract two substantive concessions in the same votes. The new regulation "does not apply to interpersonal communications to which end-to-end encryption is, has been or will be applied", and its recitals state that nothing in it may be interpreted as prohibiting or weakening end-to-end encryption. An amendment keeping solicitation, or grooming, detection out of the voluntary regime passed 346 to 254. Chat Control 1.0 as revived is narrower than the version that expired.
The regulation also started a clock that almost nobody has reported. Providers had to tell the Commission by September 1, 2026 which child-protection organisations they report to; the Commission must publish that list by October 1, 2026. First provider transparency reports are due by February 1, 2027. A grace period for scanning technology already in use before July 31, 2026 ends on April 1, 2027.
The dated record, 2021 to 2026
Every row below has a public source; most are the negotiation documents themselves, collected in the EDRi document pool.
| Date | What happened |
|---|---|
| July 14, 2021 | Regulation 2021/1232, Chat Control 1.0, permits voluntary scanning as a temporary ePrivacy derogation. |
| May 11, 2022 | The Commission proposes the permanent CSA Regulation, including detection orders that could compel scanning of private communications. |
| July 28, 2022 | The EU's own data protection authorities, EDPS and EDPB, issue a joint opinion warning the proposal could become the basis for generalised scanning. |
| April 26, 2023 | The Council Legal Service advises in opinion 8787/23 that generalised screening of communications is likely incompatible with the Charter of Fundamental Rights. |
| November 14 and 22, 2023 | Parliament's LIBE committee, then the plenary mandate: detection only as a targeted, judicially authorised last resort, end-to-end encryption explicitly protected. |
| February 13, 2024 | The European Court of Human Rights rules in Podchasov v. Russia that legislation requiring the weakening of end-to-end encryption for all users cannot be regarded as necessary in a democratic society. |
| October 2025 | Germany declares it will not support suspicionless scanning, per reporting by The Register; the Danish presidency's planned October 14 vote on mandatory detection is subsequently scrapped. |
| November 26, 2025 | The Council adopts its mandate: mandatory detection is dropped; scanning stays voluntary. |
| December 9, 2025 | First trilogue. Four more follow through June 2026 without agreement on detection. |
| March 26, 2026 | Parliament votes down the extension of Chat Control 1.0. |
| April 3, 2026 | Chat Control 1.0 expires. Voluntary scanning loses its legal basis. |
| May 2026 | The Cyprus presidency tables a detection compromise built on a public versus private content split (document 9659/26). |
| June 29, 2026 | Fifth trilogue: provisional agreement on everything except detection; age verification references deleted from the text. |
| July 9, 2026 | Parliament fails to reject the revival of Chat Control 1.0, 314 votes to 276, short of the required absolute majority. |
| July 31, 2026 | Regulation 2026/1881 enters into force: voluntary scanning, end-to-end encrypted and audio communications excluded, until April 3, 2028. |
| September 29, 2026 | Sixth trilogue at the Council premises, aimed at political agreement on detection. |
Will the EU scan encrypted messages? The two positions
The disagreement that remains is precise, and it is worth stating both sides from their own documents rather than from slogans. The Parliament's four principles, as recorded in the presidency's July reflection paper, are: detection orders in private content only as a last resort, targeted to specific users linked to child sexual abuse and subject to judicial authorisation; the same targeting for providers' own searches; no generalised scanning of private content; end-to-end encryption fully protected; and no detection of new material or grooming in private content at all.
| Open issue | Council mandate (Nov 26, 2025) | Parliament position (Nov 2023, restated July 2026) |
|---|---|---|
| Detection orders for private messages | None; scanning stays voluntary for providers | Permitted only as a targeted, judicially authorised last resort against specific users |
| Generalised scanning | Voluntary scanning may cover services broadly, as under the interim regime | Prohibited outright on private content |
| End-to-end encryption | Protected only indirectly, by keeping scanning voluntary; no explicit protection clause | Must be explicitly and fully protected |
| Scope of detection | Majority of delegations want known and new material plus grooming covered | Known material only; no new-material or grooming detection in private content |
| Public vs private content | Open to the Cyprus split: detection orders for public content, voluntary searches for private | Accepts the coexistence of orders and voluntary searches if targeted, with safeguards |
Around this table stand three legal landmarks that any deal has to survive: the EDPS and EDPB warning of 2022, the Council's own Legal Service opinion of 2023 calling generalised screening incompatible with the Charter, and the Strasbourg court's Podchasov judgment of 2024 on weakened encryption. They are why the negotiation keeps circling toward the words "targeted" and "voluntary" and away from "mandatory" and "general".
Which countries oppose mandatory scanning?
The Council's arithmetic explains both the 2025 retreat and the residual nervousness. Blocking a Council position requires at least four member states representing 35% of the EU population. In October 2025, Germany's declared refusal to accept suspicionless scanning, alongside opponents including Poland, Austria, the Netherlands, Finland, Luxembourg and the Czech Republic, put the blocking threshold out of the presidency's reach and forced the mandatory-detection plan off the agenda. Germany alone accounts for close to a fifth of the EU's population, so no blocking minority on this file forms without it, and none survives if Berlin changes its mind.
That is also why observers keep watching Berlin rather than Brussels. The Council's negotiating mandate is voluntary-only, but a mandate can be amended the same way it was created, and the German government's public line against suspicionless scanning has always been narrower than a rejection of every mandatory element. Nothing in the documented record settles how Germany would vote on a compromise that keeps orders targeted. September 29 may be the day that question stops being hypothetical.
Does a VPN protect against Chat Control?
We sell VPN services, so read this section with that in mind; it is also the section where we tell you what our product does not do.
Client-side scanning happens on the device before encryption, so no VPN, and no encrypted messenger, can protect a message that is read before it is sent. If a future version of the CSA Regulation compelled apps to scan content as you type it or before it is encrypted for transport, that scanning would take place in the app itself. Your VPN tunnel begins after that point. So does end-to-end encryption. This is precisely why the fight over detection orders matters so much: once the reading happens on the endpoint, no amount of cryptography or tunneling in the middle changes what was read.
The same logic applies to the regime in force today. Voluntary scanning under Regulation 2026/1881 happens on the provider's servers, on services that do not use end-to-end encryption, such as most webmail. Your message is scanned where it is stored and forwarded, not on the wire. A VPN never sees that stage either.
What a VPN does protect, in this context, is the transport path. It encrypts traffic between your device and the VPN server, which keeps your ISP, a public Wi-Fi operator, or any other on-path observer from reading unencrypted traffic or cataloguing which services you connect to, and it keeps your IP address out of the hands of the sites and services you use. Those are real protections against network-level observation. They are simply not protections against endpoint or server-side scanning, because a VPN operates below the layer where that scanning happens.
If your concern is Chat Control specifically, the honest priority list looks like this: first, the legislative outcome itself, because the difference between targeted judicial orders and generalised scanning dwarfs any tool choice; second, your choice of messenger, because end-to-end encryption is what the current law explicitly refuses to touch; third, transport privacy, which is where a VPN belongs. For where VPN use itself stands legally across Europe and beyond, see our country-by-country guide to VPN legality in 2026. Nothing in the CSA Regulation, in any draft on the table, penalises using one.
Is age verification part of Chat Control?
It was, and then it quietly was not. The Council's mandate wanted mandatory age verification for certain services; the Parliament wanted it left to providers. At the fifth trilogue the co-legislators cut the knot by agreeing that "this Regulation was not the place to regulate age verification" and deleting the references from the text, per Council document 11501/26.
Age checks are not going away; they are moving to other instruments. The EU's KIDS Act and a wave of national laws are building age rules service by service, and we track those, including which ones a VPN affects and which ones it does not, in our country-by-country ledger of social media age limits. France already runs the hardest-edged national version, an age-verification blocking regime for adult sites with its own court-tested register. The removal from the CSA Regulation narrows this trilogue to its real subject: detection.
What happens if there is no deal?
Nothing dramatic on September 30, which is part of the problem. The voluntary regime runs until April 3, 2028 regardless of what happens in the trilogue room. If the sixth round fails like the five before it, the file passes to the Lithuanian presidency in January 2027 and the Greek one after that, and the negotiation continues under a harder deadline: if April 2028 arrives without the permanent regulation, even voluntary scanning loses its legal basis again, exactly as it did for three months in 2026.
There is one more dated marker worth keeping. Whatever happens on September 29, the first transparency reports under the voluntary regime land by February 1, 2027, and they will show, provider by provider, how much scanning is actually happening and with what error rates. Those numbers will either justify the Parliament's caution or the Council's confidence. We will update this page when the trilogue's outcome is known.
About the author
Le VPN News Desk
The Le VPN Research Team is the news desk of the Le VPN blog. It tracks internet shutdowns, censorship, new privacy laws, and cybersecurity incidents as they unfold, and turns them into clear, sourced reporting. Every article is built from primary sources, fact-checked against them, and reviewed under Le VPN's editorial rules before it is published.
Articles by Le VPN Research Team →