EU voluntary CSAM-scanning law lapses after lawmakers fail to agree on extension

April 6, 2026
EU Digital COVID Certificate displayed on smartphone and paper form, vaccination proof.
Photo by Nataliya Vaitkevich on Pexels

Legal limbo

It has been reported that the European law allowing tech and social media companies to voluntarily scan for child sexual abuse material (CSAM) expired on April 3 after lawmakers could not agree on the terms of an extension. The result: companies that have been operating under that legal framework now face an uncertain legal landscape. Do they keep scanning and risk fresh legal challenges? Or do they pull back and risk leaving victims without a critical detection tool?

What's at stake

The deadlock puts a stark choice in sharp relief — child protection versus privacy and civil liberties. Advocates for stronger detection say stopping scans could let abuse slip through the cracks. Privacy campaigners warn that any rushed or poorly‑scrutinized extension could open the door to broad surveillance. It’s the kind of trade-off that keeps regulators up at night and policy wonks arguing in public forums. Remember Apple’s client‑side scanning row? This feels eerily similar: same nervous energy, different arena.

What happens next

With the voluntary route expired, it has been reported that EU institutions and member states will need to find a path forward fast — whether that’s a new deal, emergency guidance, or a return to litigation and national rules. Tech firms will have to make a decision under pressure: continue scanning and face legal risk, or stop and face criticism from child‑protection groups. Expect frantic behind‑the‑scenes talks, headline-grabbing statements, and a lot of finger-pointing. The human stakes are as clear as they are painful — but so is the political complexity.

Sources: politico.eu