Policy · Client-side scanning
Scanning the endpoint you promised not to touch
Europe has spent four years trying to write a law that detects illegal content inside conversations nobody can read. The cipher survives every draft. The question is what happens to the device — and the accuracy numbers, once you read them next to the regulators' reply.
13 September 2026 · The OSHI project · ~7 min
The document at the centre of the argument Europeans call “Chat Control” is not a wiretapping bill. It is COM(2022) 209 final, a proposed Regulation laying down rules to prevent and combat child sexual abuse, tabled by the Commission on 11 May 2022. Four years on the file is still open: Parliament's Legislative Observatory records its status as “Awaiting Parliament's position in 1st reading”, and Parliament's legislative-train entry notes trilogues began on 9 December 2025 and were “still ongoing” after the meeting of 29 June 2026.
Why anyone wants it: Parliament's research service reports that in 2024 “more than 20.5 million reports of suspected online child sexual abuse materials were detected”, and that reports of AI-generated material “saw a 1 325 % increase, rising from 4 700 in 2023 to 67 000 in 2024.” Those are not rhetorical numbers, and the engineering objection below does not need them to be wrong.
The shape of the technical problem
End-to-end encryption means the operator cannot read the traffic. Require the operator to detect something in it anyway and, per the Council's own Legal Service, there are three ways out. Providers “would have to consider (i) abandoning effective end-to-end encryption or (ii) introducing some form of ‘back-door’ to access encrypted content or (iii) accessing the content on the device of the user before it is encrypted (so-called ‘client-side scanning’).” The first two are politically dead, which is why the third keeps coming back.
That is the cryptographers' objection, and it is not a slogan. In Bugs in our Pockets: The Risks of Client-Side Scanning — Abelson, Anderson, Bellovin, Diffie, Landau, Rivest, Schneier, Troncoso and six co-authors, published in the Journal of Cybersecurity in 2024 — the authors state that “CSS by its nature creates serious security and privacy risks for all society while the assistance it can provide for law enforcement is at best problematic.” Europe's own data-protection authorities said the same: client-side scanning “would likely lead to substantial, untargeted access and processing of unencrypted content on end user's devices.”
A scanner on the endpoint is an endpoint compromise, with the difference that you shipped it, signed it, and put it through review.
What the accuracy numbers actually say
The Commission's impact assessment gives figures, and they sound reassuring. For known material matched by PhotoDNA the “rate of false positives is estimated at no more than 1 in 50 billion”; for classifiers finding new material it cites “an industry example that can be set at 99.9%”; and “the accuracy of [Microsoft's] grooming detection tool is 88%.”
Now read the regulators' reply. The EDPB and EDPS point out what the 99.9% figure omits: at that precision the tools “are only able to identify 80% of the total CSAM in the relevant data set”. On grooming they call a “12% failure rate” a high risk that providers are “highly unlikely” to have the resources to review. Then the arithmetic that governs everything: “even a very low false positive rate will imply a very high number of false positives given the volume of data.” One in fifty billion is superb until you multiply it by every photograph in Europe — and it covers only the easy case, matching a picture already in a database.
The hard case holds up worse. Struppek and colleagues, at ACM FAccT 2022, showed perceptual hashes can be pushed either way — “from hiding abusive material to framing innocent users, everything is possible” — concluding that “deep perceptual hashing in its current form is generally not ready for robust client-side scanning.” The 807 scientists from 37 countries who signed the September 2025 open letter put it operationally: “changing a few bits in an image is sufficient to ensure that an image will not trigger state-of-the-art detectors.” The targets can evade it. Everyone else cannot opt out.
Where scope creep actually lives
The scope-creep argument is usually a guess about future politicians. The better version is already in the file: the Council's Legal Service assessed the detection-order regime as a “particularly serious limitation to the rights to privacy and personal data protection”, risking “generalised access to the content of interpersonal communications” and “general and indiscriminate screening” in pursuit of crimes that, however serious, “do not constitute threats to national security.” A mechanism built to that description gets asked to do other work.
The drafting has moved in response. Parliament's committee position “excluded end-to-end encryption from the scope of the detection orders”, and the Council's November 2025 partial mandate states in Article 1(5) that the Regulation “shall not prohibit, make impossible, weaken, circumvent or otherwise undermine cybersecurity measures, in particular encryption, including end-to-end encryption.” Real concessions. Whether one text can mandate detection and forbid undermining encryption is the open question of the whole file — and it is an engineering question, not one about intentions.
The precedent nobody cites enough
One company built this. Apple announced on-device CSAM detection for iCloud Photos in 2021, paused it weeks later, and in December 2022 abandoned it, telling WIRED: “We have further decided to not move forward with our previously proposed CSAM detection tool for iCloud Photos.” The best-resourced attempt at client-side scanning ever made was cancelled by the company that designed it, on hardware it controlled completely.
What this means here
OSHI has nothing clever to say about the politics, and the structural point cuts at us: the interesting attacks moved to the endpoint years ago, and a mandated scanner is only the most formal example. Our own open bug lives there too — GET /api/web/sessions still answers without a signature, so a stranger who knows your public address can list your linked devices. Nobody here gets to be smug about somebody else's endpoint.
The honest summary: the goal is legitimate, the harm is real, and the mechanism is one Apple could not make safe on its own hardware, that the Council's lawyers call a particularly serious limitation, and that 807 researchers call evadable at scale. All true at once. That is why the file is still open in 2026.
Sources
- European Commission, Proposal for a Regulation … laying down rules to prevent and combat child sexual abuse, COM(2022) 209 final, 11 May 2022. eur-lex.europa.eu
- European Parliament, Legislative Observatory, Procedure file 2022/0155(COD) — the status line quoted above. oeil.europarl.europa.eu · Legislative Train, New legislation to fight child sexual abuse online, updated 1 August 2026 — the trilogue dates. europarl.europa.eu
- EPRS, Mar Negreiro, Combating child sexual abuse online, briefing PE 738.224, January 2026 — the 2024 report volumes and the Council common position of 26 November 2025. europarl.europa.eu (PDF)
- Council of the European Union, Opinion of the Legal Service, 8787/23, 26 April 2023 — the three-options passage (§50), and the proportionality conclusion (§§77–78). data.consilium.europa.eu (PDF)
- Council of the European Union, Partial mandate for negotiations with the European Parliament, 15318/25, 13 November 2025 — draft Article 1(5) on cybersecurity and encryption. data.consilium.europa.eu (PDF)
- European Parliament, LIBE press release, Child sexual abuse online: effective measures, no mass surveillance, 14 November 2023 — the committee position excluding end-to-end encryption from detection orders. europarl.europa.eu
- EDPB & EDPS, Joint Opinion 04/2022, adopted 28 July 2022 — client-side scanning, the 80 % recall figure, and the false-positive arithmetic. edpb.europa.eu (PDF)
- European Commission, Impact assessment report, SWD(2022) 209 final, 11 May 2022 — the PhotoDNA, 99.9 % and 88 % figures, in the Commission's own words. eur-lex.europa.eu (PDF)
- H. Abelson, R. Anderson, S. M. Bellovin, J. Benaloh, M. Blaze, J. Callas, W. Diffie, S. Landau, P. G. Neumann, R. L. Rivest, J. I. Schiller, B. Schneier, V. Teague, C. Troncoso, Bugs in our Pockets: The Risks of Client-Side Scanning, arXiv 2110.07450 (2021); Journal of Cybersecurity 10(1), 2024. arxiv.org
- L. Struppek, D. Hintersdorf, D. Neider, K. Kersting, Learning to Break Deep Perceptual Hashing: The Use Case NeuralHash, ACM FAccT 2022. arxiv.org · A. Athalye, NeuralHash Collider — a working collision generator. github.com
- Joint statement of scientists and researchers on the EU Presidency's new proposal for the Child Sexual Abuse Regulation, 9 September 2025 — 807 signatories from 37 countries as printed on the letter. csa-scientist-open-letter.org (PDF)
- Lily Hay Newman, Apple Kills Its Plan to Scan Your Photos for CSAM. Here's What's Next, WIRED, 7 December 2022 — Apple's statement, on the record. wired.com
- Note on fetching: europarl.europa.eu answers a bare command-line request with HTTP 202 and the page with ordinary browser headers; every source above was retrieved and read before being quoted.
Readers' notes
No account, no name, no email. Nothing is stored about you — not an address, not a browser string. Notes appear immediately and are not reviewed first, so they are capped at 160 characters, and a link can be typed here but will never be made clickable.
Loading notes…