This article incorporates text from a large language model, which is prohibited in Wikipedia articles. (July 2026) |
| European Union regulation | |
| Text with EEA relevance | |
| Title | Proposal for a Regulation of the European Parliament and of the Council laying down rules to prevent and combat child sexual abuse |
|---|---|
| Made under | Articles 114 and 294 TFEU |
| Preparative texts | |
| Commission proposal | COM(2022) 209 final |
| EESC opinion | EESC 2022/02804 |
| EP opinion | A9-0364/2023 |
| Reports | A9-0364/2023 |
| Pending legislation | |
The Regulation to Prevent and Combat Child Sexual Abuse (also known as the Child Sexual Abuse Regulation, or CSAR) is proposed European Union legislation designed to compel digital platforms to assess and mitigate risks related to the dissemination of abuse material and online grooming. The draft law also aims to enable authorities to remove or block illegal content while establishing a specialized center for regional coordination and victim assistance. In public and political discourse, the initiative is widely criticized and referred to by detractors as Chat Control 2.0 or simply Chat Control.
While the framework is strongly supported by child advocacy groups and most EU member states, the legislative process has been gridlocked by disagreement over the scope and legal safeguards of automated monitoring. Although inter-institutional compromises have been achieved on a majority of the provisions, there remains an ongoing deadlock regarding controversial mandatory detection orders. Civil society organizations and privacy activists contend that requiring social media companies and messaging apps to proactively scan communications would compromise the right to privacy and data protection by introducing indiscriminate surveillance.
The European Union's historical approach to child sexual abuse was fragmented, divided between a 2011 criminal-law directive implemented unevenly by member states, voluntary industry practices by digital platforms, and disconnected law enforcement and victim support initiatives. Official reviews of the 2011 directive identified significant implementation gaps, prompting the Council and the Parliament to call for a more coordinated EU-wide framework in late 2019.
The onset of the COVID-19 pandemic intensified these vulnerabilities by shifting schooling and social interactions online, which increased the digital exposure of children to offenders while simultaneously reducing the operational capacity of hotlines and law enforcement bodies. In response, the European Commission integrated the issue into its 2020 Security Union programme, and formally adopted its strategy for "a more effective fight against child sexual abuse" on 24 July 2020. This comprehensive strategy consolidated prevention, enforcement, and victim support under a single initiative, proposing temporary and permanent legislative measures to harmonize and expand voluntary platform detection mechanism practices.
In October 2022, Article 18 of the Digital Services Act introduced emergency reporting mandates for specific online businesses to flag imminent threats to life or safety. While these mechanisms are broadly compatible with the objectives of the CSAR, the regulation explicitly stopped short of imposing general or proactive content monitoring obligations.
Voluntary detection of child sexual abuse material (CSAM) by digital platforms dates back at least to the mid-1990s, when AOL manually reviewed suspected abuse material and subsequently developed automated detection processes. By 2015, the Internet Watch Foundation (IWF) was distributing a database of digital fingerprints, or hashes, derived from confirmed abuse material. The database included material identified through the IWF's own investigations, reports from the public and internet companies, and the UK's Child Abuse Image Database. Facebook, Google, Microsoft, Twitter and Yahoo participated in trials and implementation of the service, comparing hashes generated from newly uploaded images with those in the IWF database.
The use of automated detection and reporting systems has since become widespread, but their implementation and coverage vary substantially between services. A 2022 analysis submitted in the context of the proposed regulation argued that the voluntary system of detection and reporting by companies had proven insufficient to adequately protect children. The number of reports submitted to the National Center for Missing & Exploited Children (NCMEC) also varies considerably between platforms. In 2020, Facebook submitted 20.3 million reports, compared with 546,704 from Google, 144,095 from Snapchat, 96,776 from Microsoft, and 265 from Apple.
The extent to which these systems can be evaluated is limited by differences in transparency and reporting practices. A 2023 survey of 50 online services found that only 20 published transparency reports on child sexual exploitation and abuse, while only 10 defined such material in sufficient detail to establish what was prohibited on their services. A separate study likewise found substantial differences in the metrics and reporting methods used by online services, making it difficult to assess the effectiveness of their measures.
Existing industry practice relies primarily on automated detection technologies. Perceptual hashing is widely used to identify previously known material, while some providers use machine learning to detect previously unknown images and videos, and machine-learning-based analysis of text to identify potential online grooming.
One of the most widely used perceptual hashing systems is PhotoDNA, developed by Microsoft and Dartmouth College in 2009. In an analysis published by Ofcom in 2024, a PhotoDNA threshold selected to provide greater resistance to image alterations produced a false-positive rate of 0.3% under the conditions of the study. Published independent performance data for other commercial classifiers and systems designed to detect grooming have generally been limited. Child Rights International Network noted that claims about the accuracy of PhotoDNA and other detection tools were not supported by sufficient independent evaluation, while the European Commission's impact assessment did not provide specific false-positive rates for some of the classifiers it considered.
The accuracy and implications of automated detection can vary depending on the prevalence of the material being sought and the characteristics of the detection system. Of 4,192 reports assessed by the Irish police in 2020, 852 were confirmed to contain child sexual abuse material and 471 were classified as false positives. The figures have been cited as an illustration of the base rate fallacy in the context of large-scale detection systems. However, these figures describe reports received and assessed by law enforcement and should not be interpreted as a general estimate of the accuracy of automated detection systems. In contrast, a 2025 European Commission review reported that the automated detections examined in its assessment were "overwhelmingly confirmed" as child sexual abuse material following human review.
The ePrivacy Directive was adopted in 2002 to regulate the processing of personal data and the protection of privacy in the electronic communications sector. The European Electronic Communications Code (EECC), adopted in 2018, included interpersonal communications services within the EU electronic communications regulatory framework. Member States were required to apply the EECC from 21 December 2020.
The change in the legal framework affected the use of technologies by providers of number-independent interpersonal communications services to detect child sexual abuse material (CSAM) and the solicitation of children in private communications. In September 2020, the European Commission proposed a temporary derogation from certain provisions of the ePrivacy Directive to permit such technologies to continue to be used under specified conditions. The legal uncertainty surrounding the change was associated with a reduction in reports of suspected child sexual abuse material from services operating in the European Union to the National Center for Missing & Exploited Children (NCMEC); the Internet Watch Foundation reported a 58% decrease over an 18-week period in late 2020 and early 2021.
Regulation (EU) 2021/1232 established the temporary derogation in July 2021. It allowed providers of number-independent interpersonal communications services to voluntarily use specified technologies to detect, report and remove online child sexual abuse material and to detect and report the solicitation of children, subject to conditions and safeguards. The regulation entered into force on 2 August 2021 and, following an extension in 2024, remained applicable until 3 April 2026. The derogation was sometimes referred to as "Chat Control 1.0", particularly by organisations opposing the voluntary detection measures.
During 2023, Meta reported that its services had actioned approximately 3.6 million pieces of CSAM detected using its media-matching technology in message threads involving an EU user. Users appealed approximately 7% of these actions, and 4.6% of the appealed items were restored after review.
In March 2026, the European Parliament rejected a proposal to extend the application of Regulation (EU) 2021/1232. On 26 March, Parliament voted by 228 votes to 311, with 92 abstentions, against the proposed extension. Parliament had supported a shorter extension, until August 2027, with a narrower scope, while the Commission proposal would have extended the derogation until 3 April 2028. No agreement was reached with the Council, and Regulation (EU) 2021/1232 consequently ceased to apply on 3 April 2026.
A new temporary derogation was subsequently adopted as Regulation (EU) 2026/1881. Adopted by the European Parliament and the Council on 24 July 2026, it again permits providers of number-independent interpersonal communications services to voluntarily use specified technologies to detect, report and remove online child sexual abuse material and to detect and report the solicitation of children, subject to conditions and safeguards. The regulation was published in the Official Journal of the European Union on 28 July 2026 and is currently in force. It applies until 3 April 2028.
In furtherance of its 2020 strategy for a more effective fight against child sexual abuse, the European Commission proposed a regulation in May 2022 to lay down rules for preventing and combating child sexual abuse online. The proposal would establish obligations for online service providers to assess and mitigate the risk that their services could be misused for the dissemination of child sexual abuse material (CSAM) or the solicitation of children. It would also establish procedures for the detection, reporting and removal of CSAM, provide measures to assist victims in removing material depicting them, and establish an EU Centre on Child Sexual Abuse.
Under the Commission proposal, providers would be required to carry out risk assessments covering the possibility that their services could be misused for the dissemination of CSAM or the solicitation of children. Providers would then be required to take proportionate measures to mitigate identified risks, including measures relating to the design and operation of their services, reporting mechanisms and user safety.
The Commission proposal also provides for detection orders, which could require a provider to detect known or new CSAM or the solicitation of children under specified conditions. Detection orders would be issued by judicial or independent administrative authorities and would be subject to requirements concerning necessity, proportionality and safeguards. The proposal also provides for measures to prevent general monitoring and for the protection of users' fundamental rights.
The Commission proposal would establish an EU Centre on Child Sexual Abuse to support the implementation of the regulation. The Centre would receive and process reports from providers, maintain databases of indicators relating to known CSAM, support national authorities and providers, and assist with the identification and removal of material depicting victims.
The European Parliament adopted its negotiating position in November 2023. Parliament's position retained risk assessment and mitigation obligations but proposed narrower conditions for detection orders. Detection orders would be used as a measure of last resort, would be targeted to specific users or groups of users reasonably suspected of being connected with child sexual abuse, and would be subject to judicial authorisation and other safeguards. Parliament's position also excluded communications protected by end-to-end encryption from detection orders.
The Council adopted its negotiating position in November 2025. Its position retained mandatory risk assessments and mitigation measures for online service providers, with national authorities able to require additional mitigation measures where necessary. It also established different risk categories for online services and retained the possibility of voluntary detection, reporting and removal of CSAM by providers. The Council position provided for an EU Centre on Child Sexual Abuse and powers for national authorities to order the removal of illegal content, block access to it or, in the case of search engines, delist search results.
The Council's position removed the Commission proposal's mandatory detection orders and instead focused on risk assessment, risk mitigation and voluntary detection by providers. Interinstitutional negotiations between the Council and Parliament began after the Council adopted its position. Council documents record several technical and political trilogues during 2026, but the legislative procedure remains ongoing.
As of October 2026, the permanent regulation has therefore not yet been adopted. The Council and Parliament continue to negotiate the final text, including the scope and conditions of detection measures, while the temporary framework governing voluntary detection is dealt with separately under Regulation (EU) 2026/1881.
The proposal defines known and unknown abuse material, and grooming, definitions later used to determine risks providers must assess and to which its prevention, reporting and enforcement provisions apply. The Council position added risk categories to the assessment framework, with stronger obligations for high-risk services.
Providers of hosting, interpersonal communication, app stores and ISPs anywhere directing service toward the EU are covered, Parliament's position explicitly brought online games into scope.
Non-EU providers must maintain a point of contact within the EU for authorities and the proposed Centre to communicate with, and to support cross-border enforcement.
The EU currently relies on NCMEC, which has experienced backlogs lasting weeks, to triage reports of suspected abuse occurring in Europe. The proposal establishes a regional Centre to:
As of June 2026 most provisions concerning the Centre are agreed, except for its authority to conduct its own searches.
The draft legislation would harmonize industry practice by requiring providers to assess the risk that their services could be misused for abuse, adopt reasonable mitigations, and report their assessments and mitigation measures to the Centre every 3 months.
This section needs expansion. You can help by adding missing information. (July 2026) |
The legislation requires hosting and interpersonal communications providers report potential abuse incidents arising from their own detection, or from any detection order it has received to the Centre immediately. Reporting mandates sufficient information about an incident to be useful to authorities, and information of sufficient quality.
This section needs expansion. You can help by adding missing information. (July 2026) |
The proposal limits how abuse incident data can be used and retained by platforms:
This section needs expansion. You can help by adding missing information. (July 2026) |
A court can issue a detection order against a service where its own efforts have failed to mitigate abuse.
This section needs expansion. You can help by adding missing information. (July 2026) |
A court can also issue a removal order, requiring a hosting provider or communication service to remove content within 24 hours.
This section needs expansion. You can help by adding missing information. (July 2026) |
A blocking order enabled a court to require an ISP prevent access to material that cannot otherwise be removed.
This section needs expansion. You can help by adding missing information. (July 2026) |
Search engines can be required to stop surfacing abuse material through a delisting order.
This section needs expansion. You can help by adding missing information. (July 2026) |
Court orders under the legislation can be challenged by the platform itself or by the users it affects.
This section needs expansion. You can help by adding missing information. (July 2026) |
The legislation introduces enforcement penalties against services:
Fines must be calibrated to the seriousness and intentionality of the breach, and the size and financial health of the relevant service.
The proposed legislation requires app stores to stop children installing apps with a significant risk of grooming.
Private message services are also required to use age verification if their assessment identified a significant risk of grooming.
This section needs expansion. You can help by adding missing information. (July 2026) |
Victims are granted new rights under the proposal to know about incidents involving themselves, to receive support from the Centre, and support to remove abuse material involving them.
This section needs expansion. You can help by adding missing information. (July 2026) |
Providers are required to operate a user-friendly mechanism to flag potential abuse material on their services.
This section needs expansion. You can help by adding missing information. (July 2026) |
Trilogue meetings began after the Council adopted its negotiating position in November 2025. By April 2026, negotiators had reached consensus on risk assessment, mitigation measures and reporting, while detection measures remained the focus of debate.
As of July 2026, the principal dispute concerned whether detection by platforms should remain voluntary, or could also be required through targeted detection orders as a measure of last resort. Open questions included which users or groups could be targeted, how they would be identified and the basis for selection. Negotiation also continues on whether detection should cover known material, previously unknown material and the grooming of children. Reporting has indicated agreement that end-to-end encrypted communications should be excluded from detection technologies.
The proposed regulation has been supported by child advocacy groups including the Internet Watch Foundation and members of the ECLAG coalition. In the European Parliament, the European People's Party has been a strong supporter of the proposal.

Opponents of the original Commission proposal often highlight its mandatory detection provisions could impose surveillance of digital private communications, and as such refer to it as Chat Control. Some civil society organisations and activists have argued it was incompatible with fundamental rights, infringing on the right to privacy. Opposition has come from many sides of the political spectrum including from left-wing, liberal and right-wing politicians.
In April 2023, Parliament confirmed they had received messages calling to vote against the Commission's proposal.
EU Commissioner Ylva Johansson has been criticised regarding how the proposal was drafted and promoted. A transnational investigation by European media outlets revealed involvement of foreign technology and law enforcement lobbyists in its preparation. This was also highlighted by digital rights organisations, which Johansson rejected to meet on three occasions. Johansson was also criticised for the use of micro-targeting techniques to promote its controversial draft proposal, which violated the EU's data protection and privacy rules.
Some claims criticizing the proposals, such as that governments would be able to read the messages of individuals at will, have been characterized as false or misleading.
A poll released in April 2026 by the Central European Digital Media Observatory found that 58% of respondents across 9 EU states believed the proposal would improve online safety, though only 22% of respondents reported being aware of it. 28% of respondents believed the proposal would threaten freedom of speech.
The Commission's plans have been coined "Chat Control" by Patrick Breyer, a human rights lawyer and MEP, because they seek to automatically scan the chats, messages and web-based emails of every person in the EU (including young people)
Under the latest proposal penned by current EU chair Denmark, tech firms deemed high risk could be ordered to scan all links, images and videos — though not texts — shared on their platforms, to report instances of suspected child sexual abuse material to law enforcement ... Most controversially, the rules would also apply to content shared on messengers such as WhatsApp, which use encryption — a technical promise that your message won't be seen by anyone other than the person it's intended for.
EU governments will decide whether to endorse or reject a mass surveillance, encryption-breaking and anonymity-ending law: the EU CSA Regulation
During the previous term, Parliament repeatedly stressed the importance of fully implementing Directive 2011/93/EU.
The Council ... and the European Parliament ... had urged for such measures.
The pandemic has created a unique situation that has seen both child sex offenders and minors spending more time online.
The strategy was announced ... as part of the European Commission's Security Union Strategy.
Where a provider of hosting services becomes aware of any information giving rise to a suspicion that a criminal offence involving a threat to the life or safety of a person or persons has taken place, is taking place or is likely to take place, it shall promptly inform the law enforcement or judicial authorities of the Member State or Member States concerned of its suspicion and provide all relevant information available
Nothing in this Regulation should be construed as an imposition of a general monitoring obligation or a general active fact-finding obligation, or as a general obligation for providers to take proactive measures in relation to illegal content.
when he first started at AOL, in the mid-'90s, the work of finding and reviewing CSAM was largely manual
The master list is based on content the IWF's own analysts investigations have assessed and confirmed. This content may have been flagged up as a part of their own investigations, warnings from the public, internet companies, or from CAID.
When any new image is uploaded onto their services, it will be automatically hashed on their end. Then it can be automatically compared to our hash list.
Facebook topped the 2020 list-making 20.3 million reports last year. Google made 546,704; Dropbox 20,928; Twitter 65,062, Microsoft 96,776; and Snapchat 144,095. Apple made just 265 CSAM reports
Without such an evidence base, there are no objective measures to assess the progress and effectiveness in addressing OCSEA.
Only 10 of the 50 services define CSEA with sufficient detail to understand what is prohibited on their services, and only 20 of the services issue a transparency report on CSEA.
The identification of unknown child sexual abuse material can only be done through artificial intelligence, based on machine learning. [..] The detection of grooming requires the analysis of text through machine learning.
PhotoDNA, which was developed by Microsoft and Dartmouth College in 2009
PhotoDNA will then be able to identify exploitative imagery whenever it comes across any photo with a signature matching one held in its database of known illegal images.
PhotoDNA, one of the main tools for perceptually hashing photos and videos, has been said to have a false positive rate of 1 in 50 billion. However, there is no independent review of this technology.
The Commission's Impact Assessment does not provide specific false positive error rates for Thorn's classifier or the other tools it mentions.
Of the 4,192 reports received, only 852 were found to contain child sexual abuse material, while 471 were categorised as false positives.
The overwhelming majority of content detected using these technologies was confirmed as child sexual abuse material following human review.
The general objective of the proposal is to improve the functioning of the internal market ... by introducing consistent mandatory EU rules to prevent and combat child sexual abuse online, covering both old and new CSAM as well as grooming.
If a covered service has an establishment in Europe, or targets its activities towards one or more Member States, then it will have to comply with the Regulation.
The regulation would also introduce specific mandatory mitigation measures for services directly targeting children, platforms primarily used for the dissemination of pornographic content, and certain chat services within games.
Non-EU covered services will also be obligated to appoint a European representative to serve as a point of contact for regulators.
OSPs might establish their CSAR Proposal point of contact in Country A to receive removal orders while receiving European investigation orders in Country B.
It took them weeks to get through that backlog.
The EU Centre will substitute the EU law enforcement's reliance on the NCMEC as it would provide a triage role for reports of potential CSAM from providers.
These European CSA reports are shared at first solely with the EU Centre via a secure information sharing system.
Having received such a report, the EU Centre has to assess whether the report is "manifestly unfounded" in order to avoid obvious false positives.
When the EU Centre considers a report to be "manifestly unfounded", the EU Centre has to inform the reporting provider to that extent and specify the reasons.
The EU Centre has to forward the report to Europol and to the competent national LEA(s) likely to have jurisdiction.
"It will .. support Member States by serving as a knowledge hub for best practices on the prevention of child sexual abuse and assistance to victims."
The proposed EU Centre will coordinate actions to fight against child sexual abuse, from detection and reporting, to prevention and assistance to victims. It will support law enforcement to act on reports.
The EU Centre would publish annual transparency reports, compiling and analysing information from service providers and coordinating authorities, as well as information on its own activities
Provisional agreement has been reached on almost all the provisions related to the EU Centre, with the exception of own-initiative searches
Provider reports risk assessment and mitigation to CA every 3 months
If a provider receives a detection order, it is obliged to use technologies to detect and report specific types of online CSA to a newly established 'EU Centre'.
Article 22 of the Proposal limits the purposes for which the providers subject to the Proposal may keep the content data and other data processed in connection to the measures taken to comply with the obligations set out in the Proposal
The Proposal indicates that providers may also preserve this information for the purpose of improving the effectiveness and accuracy of the technologies to detect online child sexual abuse for the execution of a detection order
They shall not store any personal data for that purpose
The purposes concern … measures against users, handling complaints and redress, and responding to competent authorities
The data may be retained for as long as strictly necessary, but the retention period will never be more than 12 months
The data retention period may be extended upon request by a competent national authority or court where necessary for ongoing administrative or judicial redress proceedings
The data may only be accessed and processed for the purposes for which it was preserved
order the removal of CSAM from a platform within 24 hours
Under the Commission proposal, ISPs can be ordered to block Uniform Resource Locators (URLs) for known CSA material which is hosted outside the European Union if voluntary removal of the material is not possible.
The competent national authorities will be empowered to require companies to remove content or, in the case of search engines, to delist search results.
Both providers and users will have the right to challenge any measure affecting them in court
In case of noncompliance, penalties must be passed at the national level, with fines up to "6% of the annual income or global turnover of the preceding business year," or period payments of up to "5% of the average daily global turnover […] in the preceding financial year per day
Sanctions for providing incorrect, incomplete or misleading information, for failing to respond, failing to rectify incorrect, incomplete or misleading information or refusing to submit to an on-site inspection, shall not exceed 1% of the provider's annual income or total turnover.
Authorities may impose periodic penalty payments of up to 5% of the provider's average daily worldwide turnover for each day of continued non-compliance
Member States should ensure that the competent authorities, whether to impose a penalty and when determining the type and level of, penalty is account is taken of all relevant circumstances, including: the nature, gravity and duration of the infringement; whether the infringement was intentional or negligent; any previous infringements by the provider or the other person; the financial strength of the provider or the other person; the level of cooperation of the provider or the other person with the competent authorities; the nature and size of the provider or the other person, in particular it is a micro, small or medium-sized enterprise; the degree of fault of the provider or other person, taking into account the technical and organizational taking measures by the provider it to with this regulation.
Article 6 requires app stores ... to block 'child users' ... from downloading apps with a 'significant' risk of grooming ... and to use ... age assessment measures
Article 4.3 requires private message services, including those offered via gaming platforms, to use document-based age verification or age estimation measures if they have identified a risk of grooming
a victim's right to information ... [and] a right of assistance and support for removal of such content.
Article 12(3) of the Proposal requires providers to 'establish and operate an accessible, age-appropriate and user-friendly mechanism that allows users to flag to the provider potential online child sexual abuse on the service,' ... thereby establishing a direct pathway for victims and the general public to report suspected CSAM or solicitation of children to platforms
The Danish presidency of the EU Council has dropped mandatory detection obligations from its latest compromise proposal.
EU countries will now have to thrash out details of the draft legislation with EU lawmakers before it can become law.
Nevertheless, the measures governing content detection continue to be the focus of debate.
Aufdeckungsanordnung: Freiwillig oder als letztes Mittel verpflichtend
Es sei auch nicht klar, wer diese Personen oder Gruppen identifiziere und auf welcher Basis.
LVA sprach sich für einen weiten Anwendungsbereich (bekanntes Material, neues Material, Grooming) aus.
Einigkeit besteht zwischen den Ko-Gesetzgebern, dass Ende-zu-Ende verschlüsselte Kommunikationsinhalte von Aufdeckungstechnologien ausgenommen bleiben sollen.