Big Tech Continues CSAM Scanning in EU Despite Law's End
Big Tech said it will keep EU CSAM scanning after the legal basis expired Saturday, as officials warned proactive detection may breach EU law.
Cuneyd Erdogan ·

Several large technology companies said they will continue scanning communications in Europe for child sexual abuse material (CSAM) even after a European Union legal framework that allowed such detection expired on Saturday. Microsoft, Google, Meta and Snapchat said in a joint statement on Friday that they intend to keep taking what they called “voluntary action” to complete the scans, while also saying they aim to protect children and preserve privacy.
The companies tied their position to a letter signed by 247 child safety organizations that criticized lawmakers for letting the authorization lapse. In their statement, the firms warned the decision could weaken protections beyond the region, saying Europe “risks leaving children across the globe less protected” from abuse.
European officials, however, cautioned that continuing the practice now conflicts with EU law. Commission spokesperson Guillaume Mercier said that without a legal basis, companies are no longer permitted to proactively detect child sexual abuse in private communications.
Separately, a spokesperson for a European Commissioner said “protection of our children should not be subject to autonomous business decisions by companies,” arguing that child protection should be based on “clear and binding rules,” and urging co-legislators to speed up work on a long-term solution.
The lapse follows a long-running and divisive debate over how to balance child safety with privacy in digital communications. Critics said the scanning enabled indiscriminate surveillance and represented a major intrusion into privacy. Supporters, including law enforcement officials, several European commissioners and German Chancellor Friedrich Merz, backed keeping legal protections in place to allow continued scanning.
Europol executive director Catherine De Bolle said CSAM has been rising and warned that law enforcement will now face constraints in efforts to counter its spread. Negotiations on a permanent framework have been underway since November 2023, but lawmakers have not agreed on terms, and officials have acknowledged that reaching a compromise has been difficult.
The companies had previously urged lawmakers to prevent a gap in legal authority. In a March 19 statement from Google, Snapchat, Microsoft, Meta and TikTok, the firms said inaction would reduce legal clarity that had enabled companies “for nearly 20 years” to voluntarily detect and report known CSAM in interpersonal communication services, and they said children in Europe and elsewhere would have fewer protections than before.
Disagreement also extends to the technology used for detection. Critics said scanning tools have led to false accusations of abuse, while the companies said their detection methods are foolproof. The firms described their approach as hash matching, which compares known CSAM to unique hashes of previously identified material stored in a database, and they said the system provides high-precision detection while aligning with privacy principles.