Chat Control Regulation and the Future of Encrypted Messaging
The European Union's proposed Chat Control Regulation has spent the better part of three years drifting through Brussels, gathering technical rebuttals, political amendments, and an unusual coalition of technologists, civil liberties groups, and even some governments opposed to it. For Australians, the conversation might feel like someone else's problem, since the legislation targets providers operating inside the EU single market. Yet Signal, WhatsApp, and a long list of smaller encrypted messengers all serve users in Melbourne and Perth just as they serve users in Munich and Milan. What Brussels decides about scanning private messages will, in practice, shape the apps on Australian phones long before anything in our own Parliament comes close to voting on it.
This article looks at what the proposal would actually require, why it is treated by cryptographers as a direct attack on end-to-end encryption, and what everyday users in Australia should understand about the trade-offs. Encryption is one of the few digital tools that genuinely does what its marketing claims: it keeps a private conversation between two people. Anything that weakens it, even with the best of intentions, reshapes the relationship between citizens, platforms, and the state.
What the Proposal Would Actually Require
At its core, Chat Control asks messaging platforms to detect known illegal material, primarily child sexual abuse material, before a message is encrypted and sent. The detection would happen on the sender's device, an approach known as client-side scanning, and would compare images and potentially text against a database of flagged content. Providers would be obliged to report matches and, in some versions of the text, to inform law enforcement agencies across the EU.
The EU Commission has framed this as a narrow, targeted measure. The most recent drafts, however, have widened the scope. Earlier iterations covered only known images, often called hash-based detection. Later proposals have floated the idea of AI classifiers scanning conversations for grooming patterns or previously unseen illegal material. Each expansion is small in itself. Together they move the technology from a forensic tool used after the fact into a continuous, automated moderator sitting inside every private chat.
Critics point out that there is no technical way to scan only what is lawful. A system capable of detecting one category of content can, with a different database, detect another. The mechanism does not care whether the database contains hashes of abuse images, political slogans, or financial records. Once the architecture exists, what it searches for becomes a question of policy, not engineering.
Why End-to-End Encryption Cannot Survive Unchanged
End-to-end encryption means that only the sender and the recipient can read the contents of a message. The platform that delivers it sees nothing but routing data. This is not an accident. It is the defining property that makes Signal and WhatsApp different from SMS or email. Removing the ability of a provider to read messages is what makes interception by hackers, intelligence agencies, or the company itself impractical.
Client-side scanning, by definition, runs before encryption. The message must be inspected in clear text on the device for the system to flag it. Once that step exists, the encryption boundary has moved. The conversation is no longer private between two endpoints; it is private only after a third process on the device has decided it should be. For cryptographers, this is the same as weakening encryption, because the practical security guarantee users care about, namely that their messages cannot be read by anyone but the people in the chat, no longer holds.
The technology industry has been unusually blunt about this. Signal's president has threatened to withdraw the app from the EU entirely rather than implement the requirement. WhatsApp and several smaller European messengers have raised similar warnings. Some governments, including those of the Netherlands and Austria, have publicly questioned whether the proposal can achieve its stated aim without compromising the security infrastructure that businesses, journalists, and diplomats rely on every day.
Australia Already Lives Under Encryption Laws
Australian readers do not need to imagine a future in which governments ask tech companies to bypass their own encryption. The Telecommunications (Assistance and Access) Act, passed in 2018, gives agencies such as the Australian Federal Police and the Australian Signals Directorate the power to issue technical assistance requests, technical assistance notices, and technical capability notices to companies operating in Australia. The third category effectively compels providers to build capabilities they may not already have, including ways to read encrypted communications.
The law has been used quietly and, in some documented cases, to pressure companies into cooperating with criminal investigations. It has also been criticised by the same international bodies that now warn Brussels about Chat Control, including the UN Special Rapporteur on the right to privacy. For Australians, the European debate is not abstract. Canberra already has a legal framework that can compel platforms to weaken encryption. Any new global precedent that legitimises scanning private messages would reinforce, rather than challenge, that approach.
There is also a domestic layer worth noting. The Office of the eSafety Commissioner has built considerable expertise in online harms, and Australian state and federal police have run public campaigns about reporting abuse material. That infrastructure matters, because it shows child protection can be pursued through means other than weakening the private communications of every citizen. Any policy choice in Canberra or Brussels should be measured against what Australian agencies can already achieve under existing powers.
The Function Creep Problem
Function creep is the quiet failure mode of surveillance technology. A tool built for one purpose slowly expands to serve another. The Australian government's metadata retention regime, introduced in 2015, was sold as a counter-terrorism measure limited to phone and internet records. Within a few years, that same data was being accessed for routine criminal investigations, unpaid parking fines, and civil disputes. The data did not change; the list of people authorised to query it grew.
Chat Control would create a similar dynamic at much greater scale. The detection database would start with hashes of known abuse material. Pressure to expand it would come quickly. Lawmakers would hear arguments about online grooming, terrorism recruitment, drug trafficking, and revenge pornography. Each new category would be reasonable in isolation. Together they would turn every Australian's messaging app into a reporting node for an ever-wider range of state interests.
Security researchers have shown how fragile this kind of system is. Hash databases can be poisoned, classifiers can be fooled, and attackers who manage to compromise the database can frame innocent users by planting matching content on their devices. The same broadening logic is already visible in the app economy, where switching off cross-app tracking has become a baseline precaution for anyone who treats their phone as a personal space rather than a public surface.
Who Supports It and Why It Is Not Simple
It would be a mistake to dismiss the proposal as cynical. Child sexual abuse material is a real and growing problem, and the harm to victims is permanent. Many of the organisations lobbying for Chat Control, including victim support groups and some law enforcement bodies, are motivated by genuine concern. The disagreement is not about whether the harm matters. It is about whether breaking the encryption that protects billions of legitimate conversations is a proportionate or effective response.
Australia's federal police, like their European counterparts, have called for lawful access to encrypted communications in serious crime investigations. The Australian Federal Police has publicly stated that some investigations are hampered by platforms refusing to provide decrypted content. That argument deserves to be heard. The harder question is whether there is a path that addresses these cases without converting every phone in the country into a surveillance device. Most of the technical community has concluded there is not, at least not with the tools currently on offer.
Practical Steps for Australians Right Now
Whatever happens in Brussels, Australians who care about private communication can take a few practical steps today. Choosing messengers that publish their encryption protocols and resist voluntary disclosure requests is a start. Signal, for instance, runs on a non-profit basis, has been subpoenaed in Australia, and has published the legal demands it has received. Reviewing the security settings on existing apps, turning off cloud backups that store decrypted copies of chats, and reducing the amount of sensitive information shared through any messaging platform all help.
Users worried about broader data collection should also pay attention to what their phones do outside the chat window. Even when message contents are scrambled, the metadata around them, who you talk to, when, and how often, can be extremely revealing. Researchers have repeatedly shown how metadata exposing your health conditions, relationships, and routines can be assembled from a few months of call and message records, which is why metadata protections matter just as much as content encryption.
Finally, watch the politics. The Australian government reviews its encryption and surveillance legislation periodically. Letters to local members, submissions to parliamentary inquiries, and support for civil society organisations such as Digital Rights Watch have a measurable effect. Chat Control may be a European file, but the principle it sets will travel, and Australians will inherit the consequences either way.
The thing to carry away from all of this is simple. Encryption is not a feature that can be partly removed without changing what it is. Either your messages are private between you and the people you send them to, or they are not. Any system that scans them, however compassionate its motives, pushes them toward the second category. The Chat Control Regulation will not be the last attempt to square that circle. Each time it comes up, in Brussels or in Canberra, the same trade-off will be on the table, and the safest default is to remember what a private conversation is actually worth.