
Before the switch: Europe, privacy and the machinery of Chat Control
by Kai Ochsen
As I wrote some weeks ago, tomorrow is being sold as the day Europe decides, yet the calendar hides a more complex truth. On 12 September 2025, EU Member States are set to finalise their positions on the CSAM scanning proposal known as Chat Control, a step that clears the runway for a formal Council vote that could happen as soon as 14 October 2025. What is framed as a procedural milestone reads, to many citizens, like the moment a new default for digital life is set.
Behind the neutral language sits a simple mechanism with profound reach. Client-side scanning means messages and photos can be analysed on your device before encryption, which converts a private channel into a checkpoint. Services that pride themselves on end-to-end encryption would be asked to examine content before it is protected, creating a systematic inspection layer that privacy advocates consider incompatible with secure communications.
The politics are razor thin. Reporting suggests the measure is close to the threshold needed in Council, with Germany cast as the pivotal holdout that could tilt the outcome. Campaign dashboards circulating this week count a majority of Member States leaning in favour, though tallies shift by the hour and should be treated with caution. The direction of travel, however, is plain enough to alarm anyone who cares about digital rights.
This is not a marginal technical tweak. More than 500 scientists have urged governments to reject the plan as technically infeasible and constitutionally corrosive, warning that mass flagging systems would normalize surveillance for hundreds of millions. That coalition spans cryptographers, network engineers and legal scholars who rarely sign the same letter, which is telling in itself.
The debate is not happening in a vacuum. On 8–10 September, a new Banksy mural appeared outside London’s Royal Courts of Justice, showing a judge striking a protester with a gavel. It was covered and then scrubbed away, officially to protect a listed building, unofficially read by many as a symbol of how speech that challenges power is contained, cleaned, and removed. Whether one agrees with that reading or not, the fact is stark: the work surfaced, was authenticated, drew crowds, and was erased. The timing does not create causation, but it does sharpen the question of what Europe is willing to tolerate in the public square.
What Chat Control proposes would reach into everyday life. False positives are not a theoretical edge case, they are a mathematical certainty in large-scale pattern matching, which means innocent material and private conversations can be swept into review queues. The chilling effect is predictable. People change how they speak when they know a system is listening, and over time the system does not simply detect content, it shapes it.
Proponents answer with child protection, a cause that deserves seriousness rather than security theatre. The tension is not privacy versus safety, it is whether indiscriminate scanning of the entire population is either necessary or proportionate, and whether it can coexist with robust encryption that shields citizens, journalists, lawyers, activists and ordinary families from abuse and crime. Europe has traditionally claimed the high ground on fundamental rights; the burden of proof sits with those who would rewrite that contract.
So here we are, on the eve of positions being locked and a vote pencilled in. If this path continues, Europe may enter a period where private communication is treated as conditionally private, where art that bites is removed quickly, and where institutions ask citizens to accept permanent pre-screening as the cost of living online. The question for tomorrow is procedural. The question for the years after is civic. What happens to a democracy when the tools it builds to protect children also instrumentalise trust and normalize inspection as a way of life.

The fragility of privacy
Privacy in Europe was once considered a non-negotiable right, etched into charters and upheld in courts with near-sacred conviction. The General Data Protection Regulation (GDPR) was hailed as the gold standard, exported as a model to the rest of the world, and invoked in countless debates as proof that Europe still placed the individual at the centre of the digital equation. Yet, in less than a decade, that aura of permanence has started to erode. What once felt like bedrock now feels like sand.
The argument begins innocently enough: protecting children, preventing terrorism, combating disinformation. These are framed as exceptional cases that require exceptional tools. The problem is that exceptions rarely remain exceptions. Once the infrastructure is built to screen, monitor, or filter communication, it rarely stays limited to its first mandate. History shows that emergency measures almost always extend into ordinary life, a lesson Europe itself has had to relearn several times in the last century.
The introduction of client-side scanning represents precisely this shift from exceptional to routine. Unlike a traditional warrant that requires suspicion and judicial oversight, scanning occurs by default, for everyone, all the time. It is not targeted surveillance, it is ambient surveillance. And because it is automated, the scale is virtually infinite. No police force could read billions of messages a day, but an algorithm can flag them in real time.
What worries critics most is not just the technology itself but the political precedent it sets. If the EU endorses such a system, other governments will follow, each with their own interpretation of what content should be flagged. What starts as a tool against child exploitation in Brussels could become a tool against dissent in Budapest, Warsaw, or beyond Europe’s borders. The standard once set, the slope is slippery and steep.
Ordinary citizens, meanwhile, are told not to worry, that only criminals have something to hide. This rhetorical trick is as old as surveillance itself. But privacy is not about hiding, it is about autonomy. It is about the ability to think, speak, and love without external scrutiny. When people know their words may be scanned before they even leave their device, they adapt, often unconsciously. They self-censor, they reduce nuance, they avoid sensitive subjects. A culture of silence is not imposed by law but by design.
Some governments will argue that there are safeguards: oversight bodies, technical restrictions, periodic reviews. Yet safeguards are only as strong as the political will that sustains them, and political winds shift quickly. Today’s liberal parliament may be tomorrow’s populist chamber, inheriting the same tools but wielding them with far less restraint. The fragility of privacy lies not in its legal definition but in its susceptibility to political convenience.
In this climate, it becomes clear that privacy is not simply a right under attack but a concept being reframed. It is no longer treated as an intrinsic human need but as a negotiable commodity, something that can be traded for the promise of security. Once that mindset takes root, reclaiming the old definition becomes nearly impossible. Europe may still have the words written into treaties, but the lived reality risks diverging from the text.
Freedom of expression under siege
If privacy is being reframed as a negotiable right, then freedom of expression is quietly being treated as a conditional privilege. What we are witnessing is not just a legal debate about the scope of surveillance, but a broader cultural shift in which dissent, satire, and even artistic commentary are increasingly unwelcome when they cut too close to the nerve of power. The recent Banksy mural outside the Royal Courts of Justice is a case in point: unveiled, authenticated, admired, and then erased within hours. Officially, the explanation was about the protection of a historic façade, but the symbolism is impossible to miss. Art that directly challenges the state’s instruments of authority is literally scrubbed from public view.
This incident speaks volumes about the climate of control developing across Europe. What once would have been celebrated as the work of a globally renowned artist commenting on the justice system has instead been treated as graffiti to be removed. It is not the first time that controversial works of art, sharp satire, or biting political cartoons have faced backlash, but the speed and decisiveness of the response here suggest a reflex: silence first, explain later.
The wider pattern is visible across different domains. Journalists in several European countries face increasing pressures when reporting on corruption or state failures. Online platforms are nudged, and in some cases legally compelled, to filter content preemptively under the guise of tackling hate speech or misinformation. Critics are not wrong to note that while the intention may be noble, the effect is a shrinking public sphere. The scope of acceptable discourse narrows not by direct bans, but by administrative decisions, automated filters, and cultural chilling effects.
In such an environment, expression becomes something citizens perform with caution. Artists think twice about how provocative their imagery can be. Writers calibrate their language to avoid falling afoul of loosely defined categories of disinformation. Even ordinary social media users internalize a quiet discipline, asking themselves not “what do I want to say?” but “what can I say without triggering a warning, a takedown, or a flag?” Expression shifts from the authentic to the performative, a curated presentation of thought that passes through invisible gatekeepers.
The paradox is that Europe continues to brand itself as a global defender of rights, criticizing authoritarian governments abroad for restricting press freedoms and artistic expression. Yet at home, its institutions increasingly adopt mechanisms that resemble those very systems of control, albeit wrapped in more palatable language. It is a contradiction that erodes credibility: how can Europe defend expression abroad while quietly narrowing it at home?
The Banksy mural becomes, then, more than a fleeting artwork. It is a metaphor for the state of European speech. Creative, subversive, and raw, it appeared suddenly, spoke truth in a way few other mediums could, and was gone before the day ended. The absence it left behind feels heavier than the image itself, because it reveals how fragile the right to speak without erasure has become.
Silencing does not always come with censorship decrees or court orders. More often, it comes through banal bureaucracy, through “heritage regulations,” “community standards,” or “platform guidelines.” This bureaucratic silencing is more insidious, because it cloaks control in procedural legitimacy. Citizens do not see a jackboot; they see a checklist. But the effect is the same: expression that once thrived in freedom is now tolerated only in narrow, sanitized spaces.
The hypocrisy of European values
Europe has long projected itself as the guardian of human rights, a continent that learned from its own turbulent history and vowed never to repeat the same mistakes. Institutions such as the European Court of Human Rights and frameworks like the Charter of Fundamental Rights of the European Union are often cited as proof of this moral high ground. Yet, the march toward Chat Control and the steady erosion of freedoms reveal a deep contradiction between Europe’s self-image and its current trajectory.
On paper, Europe stands firm against surveillance states. It condemns mass monitoring in countries like China and Russia, pointing to how digital control tools are used to stifle dissent, manipulate society, and enforce conformity. Yet what is being proposed in Brussels today mirrors those same practices, only wrapped in the language of child protection and security compliance. The words differ, but the underlying architecture of mass inspection is eerily familiar.
This double standard is not new, but the stakes are higher now. For decades, the EU has presented itself as a counterbalance to the United States’ corporate-driven tech model and Asia’s state-driven surveillance model. By positioning itself as a defender of privacy and freedom, Europe sought to carve out a distinct identity in the digital world. GDPR was the clearest embodiment of this ambition, a law that forced global companies to rethink how they handle user data. Now, however, Europe risks undoing its own achievement by building a surveillance framework that undermines the very principles it once exported.
The hypocrisy becomes even sharper when seen against Europe’s rhetoric on democracy promotion. The EU spends millions funding NGOs and civic initiatives in countries under authoritarian rule, often with the stated goal of empowering free expression and digital rights. But what credibility will those programs have if Europe itself adopts laws that weaken encryption and normalize scanning of private communications? To citizens abroad, the message is clear: Europe is telling you to resist what it is simultaneously imposing on its own people.
One could argue that the difference lies in intention: Europe claims to act out of protection, not repression. Yet history teaches us that intentions matter less than capabilities. Once surveillance tools exist, they can be redirected and reinterpreted according to whoever holds power. Today’s liberal government might respect limits, but tomorrow’s authoritarian-leaning coalition could easily expand the system’s reach. The very presence of such infrastructure is the danger.
The broader effect is a slow corrosion of trust. Citizens begin to see European values not as principles but as marketing slogans, invoked when convenient and discarded when politically costly. The gap between words and actions becomes harder to ignore, especially for younger generations who grew up hearing that Europe was the champion of freedom. For them, the betrayal cuts deeper, because it undermines not only laws but also the narrative of belonging to a community of rights.
The question then is not just about legality or technical feasibility. It is about coherence. Can Europe continue to claim the mantle of moral authority in human rights while installing tools of mass surveillance at home? Can it lecture others about censorship while tolerating the erasure of critical art on its own streets? Unless these contradictions are confronted honestly, Europe risks being seen not as a leader in rights but as a practitioner of doublespeak.
The myth of security vs. freedom
The debate around Chat Control is framed in the most familiar of binaries: security versus freedom. Policymakers argue that in order to protect children from abuse or society from terrorism, a certain amount of freedom must be sacrificed. It is a seductive narrative, one that casts restrictions as noble trade-offs and positions those who object as naïve or reckless. But it is also a myth, because security and freedom are not zero-sum; one does not need to collapse for the other to stand.
True security comes not from permanent surveillance but from trust, accountability, and effective justice systems. Societies that constantly monitor their citizens are not inherently safer. In fact, history shows the opposite: pervasive surveillance breeds paranoia and conformity, conditions in which genuine threats can be harder to detect because the environment itself becomes flooded with false positives. The danger of algorithmic scanning lies precisely in this flood. Every false flag drains resources and attention from actual cases, creating an illusion of vigilance while weakening real protection.
What makes the myth so persistent is its emotional appeal. Invoking children is a powerful rhetorical device, one that immediately stifles critical debate. Few want to be the voice that seems to oppose child protection, so the conversation is reduced to a moral equation in which surveillance equals safety. But this is a false equivalence. One can oppose mass scanning while simultaneously demanding better funding for child protection agencies, more cross-border cooperation against trafficking networks, and stronger investigative tools targeted at perpetrators rather than citizens at large.
The myth also thrives on fear. Citizens are reminded of terrorist attacks, child exploitation cases, or waves of online disinformation, and the natural instinct is to accept almost any solution that promises safety. Governments know this, which is why fear is routinely mobilized to justify extraordinary measures. Yet, when examined closely, these measures often provide psychological comfort rather than tangible protection. They are more about proving that something is being done than about genuinely addressing root causes.
Meanwhile, the erosion of freedom is slow and subtle. No one wakes up one morning to find themselves in a totalitarian system. Instead, the boundaries shift gradually, each justified by an exceptional circumstance, each defended as temporary, until the line between temporary and permanent blurs beyond recognition. By the time citizens realize what has been lost, the architecture of control is already embedded in law, culture, and infrastructure.
Another danger of this myth is its ability to divide societies. Those who value freedom are framed as reckless idealists, while those who demand security are portrayed as responsible realists. This polarization distracts from the fact that most people want both: to live without fear and without constant oversight. Yet the myth forces a false choice, and once that choice is accepted, the conversation is over before it begins.
In Europe’s case, this myth strikes at the heart of its identity crisis. A continent that promised its citizens “never again” after the darkest chapters of the 20th century now finds itself considering tools that echo those very chapters, albeit under digital guises. If freedom can be permanently traded for the illusion of safety, then the promise of a rights-based Europe dissolves into a managed system of controlled expression and conditioned privacy.
Historical echoes
Europe’s history is filled with moments when rights were suspended in the name of necessity, often accompanied by solemn promises that restrictions would be temporary. Yet, time and again, these “temporary” measures hardened into permanent features of governance. To understand what is at stake with Chat Control, it is useful to remember how fragile liberties have been when confronted with the machinery of security.
During the First World War, governments across the continent introduced sweeping censorship and surveillance measures, ostensibly to protect military secrets and maintain morale. Many of those controls lingered long after the war ended, shaping interwar politics and stifling dissent. Citizens quickly discovered that extraordinary measures, once normalized, seldom retreat without resistance.
The Second World War deepened this pattern. Occupied territories and authoritarian regimes perfected the art of monitoring speech, correspondence, and association. The lesson Europeans swore never to forget was that when governments have the power to pry into private lives without checks, that power will eventually be abused. Out of those ashes came the post-war human rights framework, with privacy and free expression written into constitutions and international treaties. But memory fades, and with each generation the urgency of those lessons dulls.
Even in more recent times, we see similar cycles. The post-9/11 era brought about unprecedented surveillance expansions, both in Europe and the United States. Programs rolled out under the banner of counter-terrorism, mass data retention, airline passenger tracking, financial monitoring, were described as urgent and temporary. Two decades later, many remain in place, and the infrastructure for data sharing between agencies has only deepened. Once built, systems of control rarely dismantle themselves.
The current debate over client-side scanning belongs squarely to this lineage. Officials insist the tools are strictly for combatting child exploitation. But history teaches us that once such tools exist, the definition of their use widens. What begins as CSAM detection could later encompass “extremist content,” “disinformation,” or other vaguely defined categories. Each expansion will be justified by appeals to crisis, just as they always have been.
It is not alarmist to draw these parallels; it is responsible. The very reason Europe enshrined rights so strongly in its legal frameworks was to prevent repetition of past mistakes. The point of fundamental rights is not to make governance easier, but to make abuses harder. Yet by introducing preemptive scanning, Europe risks inverting this logic, making surveillance easier and resistance harder.
The tragedy is that each of these historical cycles has ended with the same refrain: citizens recognizing too late that what was promised as temporary had quietly become permanent. Today’s generation still has the memory of their grandparents’ warnings, but tomorrow’s may only know a Europe where surveillance is the default and privacy the exception.
If Europe proceeds down this path, it will not be the first time liberties have been surrendered for security. The echoes of the past remind us that such surrenders are rarely reversed, and that the cost is not just legal but cultural, altering how people see themselves in relation to power. The danger is not simply that we repeat history, but that we accept it as normal.
The road ahead
If the Council solidifies its support for Chat Control, Europe will soon enter a new digital landscape where privacy is no longer presumed but conditional. Every photo, message, and file exchanged through mainstream platforms would carry the shadow of inspection. While the technical and legal debates will continue, the psychological shift may prove even more consequential. Once people internalize the idea that their devices are potential informants, trust in communication itself begins to erode.
The practical consequences will be immediate. Encryption services will face enormous pressure to comply, even if doing so undermines their core promise of security. Smaller companies and open-source projects may lack the resources to implement scanning systems, effectively shutting them out of the market. The result is a concentration of power in the hands of larger corporations willing to compromise, further shrinking the already fragile diversity of Europe’s tech ecosystem.
For journalists, lawyers, and activists, the stakes are existential. Confidentiality is not a luxury in these professions; it is the foundation of their work. A whistleblower considering whether to contact a journalist will think twice if they know their messages might be screened before encryption. A client confiding sensitive details to their lawyer cannot feel secure if software on their own device could flag the exchange. In this sense, Chat Control is not just a privacy issue but a direct threat to democratic infrastructure.
On the societal level, the chilling effect will deepen. People may avoid certain conversations or retreat to less accessible platforms, fragmenting the digital public sphere. Ironically, criminals will adapt fastest, moving to tools and channels beyond the reach of European regulation, while ordinary citizens will be left carrying the burden of mass surveillance. The very population Chat Control claims to protect will be the one most exposed.
There is also the question of global precedent. If Europe, with its long-standing reputation for rights and protections, adopts such a system, it will embolden governments elsewhere to do the same. Authoritarian regimes will cite the EU as justification, claiming that if Brussels deems scanning necessary, then so can they. The moral authority Europe once held in setting rights-based standards will evaporate, replaced by the image of a continent that traded its principles for an illusion of safety.
Resistance, however, is not entirely futile. Civil society groups, digital rights organizations, and a growing number of academics are already preparing legal challenges. Courts may yet intervene, particularly if the legislation clashes with constitutional guarantees in member states. But these processes take time, and once surveillance systems are operational, they are difficult to dismantle. The road ahead is not just about passing or blocking a law, it is about the cultural normalization that happens once surveillance becomes routine.
Perhaps the most insidious risk is that citizens simply get used to it. Much as cameras on every street corner or routine ID checks in airports became background noise, so too could client-side scanning fade into the fabric of daily life. People adapt, sometimes too well, and what should spark outrage becomes an accepted condition of modernity. If that adaptation occurs, Europe will not just lose a legal battle, it will lose a generation’s sense of what freedom means.
In this unfolding reality, the road ahead feels less like a crossroads and more like a slope. The further Europe slides, the harder it becomes to climb back. The immediate decision belongs to policymakers, but the long-term consequences will belong to all citizens. The choice is not whether to protect children or not, but whether to do so by building a society where everyone is treated as a suspect. And that choice will define the character of Europe for decades to come.
Beyond Europe: ripple effects and resistance
What Europe decides in the coming weeks will not remain confined within its borders. The ripple effects of Chat Control will spread outward, shaping how other regions approach the balance between privacy, security, and digital sovereignty. For better or worse, the EU has positioned itself as a norm-setter in digital governance. GDPR reshaped global corporate practices, and the Digital Services Act has begun to influence content moderation beyond Europe. If Chat Control is adopted, it too will set a precedent, only this time with far darker implications.
In the United States, where debates about encryption and law enforcement access have long been contentious, lawmakers will inevitably point to Europe as a model. Advocates of scanning will argue that if the EU can mandate such measures, America should follow suit. Across Asia, governments that already lean toward heavy-handed surveillance will seize on Europe’s decision to validate their own policies. Authoritarian leaders will frame it as proof that mass monitoring is not a betrayal of democratic principles but a legitimate tool of governance.
The impact will also be felt in the technology sector. Global platforms rarely maintain separate technical infrastructures for different regions. If scanning is required in Europe, the easiest path for many companies will be to implement it universally, extending the system to users worldwide. In this sense, the decision of a few European ministers could end up reshaping the architecture of digital communication across the globe.
But ripple effects do not flow only one way. Resistance can spread just as quickly. Civil liberties groups, encryption advocates, and independent developers around the world are already networking across borders to prepare coordinated responses. Legal challenges in European courts may inspire similar pushbacks in other jurisdictions. And as often happens in moments of overreach, innovation may find its own countermeasures. Developers could design new protocols that make scanning technically impossible, or citizens could migrate en masse to decentralized networks where such laws are unenforceable.
There is also the possibility of political backlash. If citizens feel betrayed by governments that promised to protect their rights, the issue could become a rallying point for new movements. Privacy, once seen as an abstract concern, might become a tangible political demand, especially for younger generations raised in digital environments. Paradoxically, by pushing so aggressively, policymakers risk awakening a stronger culture of resistance than they anticipated.
The global stage thus magnifies the stakes. This is not just about European citizens but about the future template of communication worldwide. If Chat Control becomes law, it could normalize surveillance at an unprecedented scale. If it fails, however, it could send the opposite message, that even in moments of fear and political pressure, societies can draw a line and defend freedom. Which of these paths unfolds will depend not only on governments, but on how vigorously citizens, technologists, and civil society rise to meet the challenge.
Final thoughts about current reality
Europe stands at a threshold. What is being decided is not simply the fate of a single law, but the definition of freedom in the digital age. Chat Control is more than a technical mandate; it is a cultural statement about how much trust a society is willing to extend to its citizens. Once that trust is withdrawn, once privacy and expression are reframed as conditional allowances rather than fundamental rights, the relationship between people and power is transformed.
The irony is painful. A continent that once swore “never again” after experiencing the full weight of authoritarian surveillance now flirts with embedding surveillance into the everyday. Policymakers insist the cause is noble, but the nobility of the cause cannot erase the structural reality of the tools. A system designed to scan every message before it is sent cannot be reconciled with the promise of secure, private communication. It is a contradiction written into code.
This moment also forces us to reflect on how freedom erodes. Rarely is it ripped away overnight. More often, it is chipped at quietly, piece by piece, each cut justified by necessity. A little monitoring here, a new filter there, a silence imposed on one piece of art, a hesitation before speaking in a chat, until one day, the culture of openness has been replaced by a culture of compliance. The danger is not only that rights are lost, but that people forget they ever had them.
And yet, resistance remains possible. The Banksy mural may have been scrubbed from stone, but its message circulates digitally, reminding us that expression finds a way even when silenced. Civil groups, legal experts, and technologists continue to push back, offering alternative visions of security that do not require mass suspicion. Citizens, too, retain the power to say no, not only at the ballot box but in daily choices about the platforms they use, the conversations they protect, the movements they support.
The broader question is whether Europe will choose to remain a beacon of rights or become a cautionary tale. To defend privacy and freedom now is not to dismiss the seriousness of abuse or violence, but to insist that such challenges be met without dismantling the foundations of democratic life. If Europe cannot hold that line, who will?
So tomorrow’s vote is not merely procedural, and next month’s Council decision is not merely bureaucratic. They are inflection points. The story of Europe has always been written in moments like these, where fear tempts leaders to compromise and citizens must decide whether to resist or to yield. The future will not be determined by slogans about safety, but by whether Europeans still believe that freedom and dignity are worth protecting, even when inconvenient.
The consequences reach deeper than legal statutes. They will define how Europeans see themselves: as active citizens in a union built on rights, or as passive subjects in a managed system of oversight. The choice is not abstract; it will echo in how children grow up using technology, how communities speak to each other, and how trust in institutions is preserved or lost. The cultural DNA of Europe is being rewritten in real time.
If the legislation passes, future generations may inherit a Europe where surveillance is so normalised that its presence is invisible. They will not question why their conversations are scanned, any more than people today question why cameras are fixed on every street corner. That quiet acceptance is perhaps the most dangerous outcome: not outrage, but indifference. Once indifference sets in, the door to deeper abuses stands wide open.
Conversely, rejecting or reforming Chat Control could rekindle confidence that Europe still honours its own values. It could send a signal not just internally but to the wider world that democracies can resist the easy lure of mass surveillance and still confront real dangers with proportionate, targeted tools. It would not make Europe perfect, but it would keep alive the belief that rights are not just lines in treaties but living principles. And in the long arc of history, that belief may prove more powerful than any technology.