EU Denies Deadline Extension for Google, Meta, Microsoft, and Snapchat’s Voluntary Scanning Program

Google, Meta, Microsoft and Snapchat are warning that a major legal change in the European Union could make it harder to fight illegal content shared through private messages. The debate centers on whether online services should be allowed to automatically detect child sexual abuse material (often referred to as CSAM) inside private chats.

Until now, a temporary exemption in the EU’s e-Privacy framework had allowed communication providers to voluntarily scan private messages for known abusive material and report it. That exemption expired on 3 April 2026, after the European Parliament voted not to extend it. Lawmakers rejected the European Commission’s proposal by 311 votes to 228, ending the transitional period that made these voluntary detection measures legally possible in the way they had been used.

The companies pushing for continued detection argue that the method they rely on is narrow and highly targeted. They commonly point to hash-matching, a technique that converts images or files into unique, irreversible digital fingerprints called “hashes.” Instead of “reading” a message like a human would, the system compares these fingerprints against a secure database of material already confirmed as illegal. If there’s a match, it can be flagged and reported. Supporters say this approach is one of the most effective tools available for law enforcement to identify and stop the spread of known abusive content online.

Many members of the European Parliament see the issue differently. Their core concern is privacy and proportionality: scanning private communications, even for a serious purpose, can create a framework that resembles broad surveillance. In their view, allowing automated searches of personal messages risks undermining fundamental rights and the integrity of private communication. The decision to reject an extension signals that protecting private chats from automated inspection is being treated as a priority, even amid calls for stronger enforcement mechanisms.

Behind the scenes, the Parliament and the Council were unable to agree on a long-term, permanent legal solution. The Commission wanted the temporary rules extended to buy more time for negotiations. The Parliament pushed for tighter limits and a shorter, more clearly defined timeframe—reportedly aiming to keep any measures strictly targeted and constrained, with an endpoint around August 2027. With no final compromise reached, the legal foundation for these voluntary scans has now lapsed.

Even so, the companies involved say they remain committed to child safety and plan to continue taking voluntary steps within their messaging services—though the new legal landscape in the EU changes what is permitted and how these systems can operate. For now, the balance has clearly shifted toward data protection, with the European Parliament’s vote reinforcing the principle that private communications should not be routinely subject to automated monitoring by either governments or corporations.

This decision is likely to keep the EU’s private messaging and online safety debate in the spotlight, as policymakers face mounting pressure to find a workable long-term framework that protects children without turning private chats into a space of constant automated surveillance.