A month ago, the European Parliament held a vote that looked, on paper, like a win for privacy. It was not. On 9 July 2026, MEPs voted on whether to block the continuation of a rule that lets platforms voluntarily scan unencrypted private messages, emails, and photos for child sexual abuse material. 314 voted to kill it. Only 276 voted to keep it. It survived anyway, because blocking it required an absolute majority of 361 votes under the parliamentary procedure used, and the rejection fell 47 votes short (The Register; Hive Security).
The rule, commonly called Chat Control 1.0, is now extended until April 2028. It does not require companies to scan, and it does not touch fully encrypted apps like WhatsApp or Signal (GDPR Register; Brussels Signal).
A second, far more sweeping proposal, the permanent Child Sexual Abuse Regulation, sometimes called Chat Control 2.0, would make scanning mandatory and reach into encrypted messages via client-side scanning, checking a message before it is even encrypted. That version is not law. It collapsed in trilogue negotiations between the Council, Parliament, and Commission in June 2026, and the next attempt to revive it is expected in September (Numi; closednetwork.io tracker).
Europe’s own regulator has flagged the tension
On 11 February 2025, the European Data Protection Board adopted Statement 1/2025 on Age Assurance, warning that age verification technologies collide with the GDPR’s own data minimisation principle under Article 5(1)(c). EDPB Chair Anu Talus said age assurance methods must be “the least intrusive possible,” and the statement itself says the processing “should not enable the further targeting or profiling of users” (EDPB official statement; EDPB news release).
The United States is one week into the same path
On 5 August 2026, the Senate Commerce Committee, chaired by Ted Cruz, advanced four bills out of committee: the Kids Online Safety Act (KOSA), the Youth AI Privacy Act (Sen. Ed Markey), the CHATBOT Act (Sen. Cruz), and the Children’s Artificial Intelligence Toy Safety Act. None are law yet — all still require a full Senate floor vote and passage in the House (Senate Commerce Committee press release; IAPP).
KOSA’s central mechanism is a “duty of care” provision, requiring platforms to take reasonable steps to prevent harms to minors including anxiety, eating disorders, and “compulsive usage.” The Center for Democracy and Technology has warned the provision “creates new privacy problems” and pushes companies toward invasive age verification. The Electronic Frontier Foundation has called the surrounding package a step toward “an internet where speaking to the public requires a government ID” (EFF; EFF).
The infrastructure has already failed once
Platforms rely on third-party identity verification vendors — Yoti in the UK works with Meta, Spotify, and TikTok; Persona in the US works with Reddit and X; k-ID in Singapore works with Snapchat, Twitch, and Discord.
On 3 October 2025, a vendor named 5CA, which handled age verification appeals for Discord, was breached. Approximately 70,000 users had government-issued ID photos exposed, according to Discord’s own disclosure (Discord official statement; Proton).
Four days later, on 7 October 2025, a class action lawsuit, Uceta v. Discord, Inc. (Case No. 3:25-cv-08582), was filed in the US District Court for the Northern District of California. The case remains open, with no settlement reached as of the most recent public filings (CourtListener docket; original complaint, PDF).
Britain has moved furthest
On 10 July 2026, Ofcom published its official Register of Categorised Services under the Online Safety Act, legally designating eleven platforms as “Category 1” services: Facebook, Instagram, Pinterest, Quora, Reddit, Roblox, Snapchat, TikTok, WhatsApp, X, and YouTube. These platforms must assess the risk of adult users encountering specific categories of content and offer verified-adult filtering tools (Ofcom register; Global Policy Watch).
Separately, on 15 June 2026, the UK government announced a proposed outright ban on social media access for under-16s, targeting Spring 2027 (GOV.UK announcement; NPR).
Wikipedia was nearly caught in the same net
The Wikimedia Foundation formally challenged the UK’s OSA categorisation regulations in court, arguing that applying Category 1 duties would be incompatible with an open, volunteer-run encyclopaedia. The UK High Court of Justice dismissed the challenge, and the Foundation chose not to appeal, opting to monitor implementation instead. When Ofcom published its final register in July 2026, Wikipedia was placed on a lower-tier “emerging” watchlist rather than formally designated Category 1 — a reprieve, not a resolution (Wikimedia Foundation statement).
The pattern
Three separate legal systems. Three different mechanisms — a voluntary scanning regime with a mandatory version waiting in reserve, a package of bills still moving through Congress, and a finalised regulatory register already in force. The same stated justification in every jurisdiction, and the same practical requirement underneath it: verify everyone in order to identify the few.
Sources
- EU Chat Control vote, 9 July 2026: The Register, Hive Security, GDPR Register
- Chat Control 2.0 / permanent CSA Regulation status: Numi, closednetwork.io tracker
- EDPB Statement 1/2025 on Age Assurance: official EDPB page, EDPB news release
- US Senate Commerce Committee markup, 5 August 2026: official committee release, IAPP
- EFF analysis of KOSA and related bills: EFF, “Senate Should Reject KOSA’s Privacy Risks”, EFF, “Four Internet Bills, One Wrong Direction”
- Discord/5CA breach, October 2025: Discord official disclosure, Proton
- Uceta v. Discord, Inc., 3:25-cv-08582: CourtListener docket, original complaint
- Ofcom Register of Categorised Services, 10 July 2026: official Ofcom register, Global Policy Watch
- UK under-16 social media ban announcement, 15 June 2026: GOV.UK, NPR
- Wikimedia Foundation’s OSA legal challenge: official Wikimedia Foundation statement