Episode 398: Does Chat Control Protect Children or Risk Privacy with Simeon de Brouwer
In this episode of the International Risk Podcast, host Dominic Bowen is joined by Simeon de Brouwer, policy advisor at European Digital Rights (EDRi), Europe’s largest network of digital rights organisations. Simeon explains the controversial EU proposal known as “Chat Control” and explores what mandatory scanning of private communications could mean for encryption, privacy, security and child protection across Europe.
We discuss:
- What the EU’s Chat Control proposal would actually require messaging and hosting platforms to scan for child sexual abuse material and grooming
- Why scanning everyone’s private communications raises fundamental questions about the presumption of innocence and proportionality
- How client-side scanning could affect end-to-end encryption on services such as WhatsApp and Signal
- The risks of false positives, including innocent communications being flagged, accounts being suspended and private material being reviewed by authorities
- Why mass scanning could create opportunities for “function creep”, allowing surveillance infrastructure introduced for child protection to be expanded to terrorism, organised crime or political dissent
- Why encryption is essential not only for ordinary users, but also for journalists, human rights defenders and businesses
- How criminals can adapt their behaviour to evade automated detection, potentially leaving the most sophisticated perpetrators beyond the reach of the technology
- The tension between privacy and child safety, and why EDRi argues that the two do not have to be mutually exclusive
- What alternative approaches could better protect children online, including addressing how platforms enable adults to find and contact young people
- Where negotiations over Chat Control currently stand, and what could happen as the European Parliament, Council and European Commission continue negotiations
- Why Simeon is concerned about Europe’s broader push to simplify digital regulation, and the risk that weakening protections in the name of innovation could ultimately create new security and privacy risks
The International Risk Podcast brings you conversations with global experts, frontline practitioners, and senior decision-makers who are shaping how we understand and respond to international risk. From geopolitical instability and organised crime to cybersecurity threats and hybrid warfare, each episode explores the forces transforming our world and what smart leaders must do to navigate them. Whether you’re a board member, policymaker, or risk professional, The International Risk Podcast delivers actionable insights, sharp analysis, and real-world stories that matter.
Dominic Bowen is the host of The International Risk Podcast and Europe’s leading expert on international risk and crisis management. As Head of Strategic Advisory and Partner at one of Europe’s leading risk management consulting firms, Dominic advises CEOs, boards, and senior executives across the continent on how to prepare for uncertainty and act with intent. He has spent decades working in war zones, advising multinational companies, and supporting Europe’s business leaders. Dominic is the go-to business advisor for leaders navigating risk, crisis, and strategy; trusted for his clarity, calmness under pressure, and ability to turn volatility into competitive advantage. Dominic equips today’s business leaders with the insight and confidence to lead through disruption and deliver sustained strategic advantage.
Episode 398 Transcript: Does Chat Control Protect Children or Risk Privacy with Simeon de Brouwer
Dominic Bowen (00:22)
Few EU digital files have generated as much controversy as chat control. That’s the informal name for the attempt to encourage — and in some cases require — messaging platforms to scan private communications for child sexual abuse material. What began in 2022 as a child protection proposal has become one of the most closely watched fights in Europe over encryption and mass surveillance. Four years later, the topic is still not settled.
In this episode we’ll unpack what chat control actually proposes, why it keeps failing to pass, and what’s really at stake for privacy, for security and, of course, child safety.
I’m Dominic Bowen, host of The International Risk Podcast, where we unpack the topics that really matter. Today we’re joined by Simeon de Brouwer, a policy advisor at European Digital Rights, Europe’s largest network of digital rights organisations. He’s well placed to help us understand what’s going on and what we need to know.
Welcome, Simeon. Whereabouts in the world do we find you today?
Simeon de Brouwer (01:28)
I’m in Brussels, in Belgium, where the European Commission is seated.
Dominic Bowen (01:33)
Fantastic. Thanks very much for coming on the podcast today. Let’s jump straight in with a question that might be a little uncomfortable for some people, but I think we really need to understand it.
We all value our privacy. But if scanning all of our private messages could save even just one child from sexual abuse, why shouldn’t we all be willing to sacrifice some of that privacy to make sure none of our devices are being used as tools to share online child abuse material? Help us understand the topic, why it’s been so controversial, and why four years later there still isn’t legislation around it.
Simeon de Brouwer (02:18)
Precisely because one life is always worth so much, the narrative about children’s lives in particular has been very difficult to navigate. This is a very emotional proposed regulation. It’s hard for people to talk about it without referring to their own children or their own experience.
However, if we agree to the premise that even saving one life is worth doing mass surveillance, then we are doomed for every other kind of harm as well. Right now we’re talking about child sexual abuse, which is a legitimate crime to address — we need to address it, and we need to address it well. But if even one life is worth saving, why don’t we prevent terrorism through mass surveillance too? That narrative is easy to turn on its head.
Dominic Bowen (03:40)
So tell us what this legislation actually means. What would it mean for an ordinary person? What would it mean for you and me when we’re sending messages on WhatsApp or Signal? Would someone be reading our messages? Would AI be examining them? Or is it something more complicated? How would this actually work?
Simeon de Brouwer (04:02)
This regulation is proposed to address two kinds of issues. One is children being groomed online — that is, approached by people with the intention either to meet them or to get intimate images from them. That’s the grooming aspect. The other is preventing sexual predators from exchanging child sexual abuse material among themselves: videos and photos of children being abused.
They are two different kinds of issue, both very real, and both of which need to be addressed. However, the way the European Commission intends to address them is this: since there is a risk this could take place on a service, it should be possible to force that service — be it WhatsApp, Signal, Facebook Messenger or whatever — to scan for that kind of content and those kinds of conversations, using an AI, an algorithm, an automated tool. It would apply both to communication services and to hosting services, such as cloud storage.
The way it would be done is to force a service provider to install scanning capabilities on its service, so that whatever passes through it is checked automatically.
The issue with that is it’s not really how we address crime of any nature in the European Union, because we have requirements of human rights, proportionality and so on. This very approach — scanning everyone in order to find criminals — turns the presumption of innocence on its head. Under this approach you cast as wide a net as you can and consider everyone guilty.
Dominic Bowen (06:22)
That makes perfect sense. When everyone is being surveilled in order to identify where crimes are occurring, there are obvious risks.
But governments are saying that because encryption is now so common — end-to-end encryption on WhatsApp, and Signal with all the encryption it has — this creates spaces where child abusers can operate beyond the reach of law enforcement. We understand mass surveillance is generally not a good thing, and it’s something most of us would push back against. But are governments and law enforcement agencies right that the common tools we all use every single day are also facilitating crime? I assume they’re also facilitating other crimes — drug trafficking, people trafficking, terrorism and so on.
Simeon de Brouwer (07:26)
Encryption, and especially end-to-end encryption — which means no one except the sender and the receiver can read the content you send — is also very useful for human rights defenders, for journalists, for businesses and for people generally, because we have a fundamental right to have our communications secure, safe and private.
One cannot say that since it’s impossible to send letters without opening them, then we cannot send letters. With encryption, you protect everyone. Indeed, criminals can also send messages on encrypted channels and services. But that doesn’t mean we should stop people using those services.
Dominic Bowen (08:20)
If this legislation does pass — and noting that end-to-end encryption already exists and has done for several years — is there even a technological solution that actually allows us to detect child sexual abuse material being sent from one device to another? Or are politicians arguing over something that doesn’t yet have a scientific or technological solution?
Simeon de Brouwer (08:46)
It does remain possible on an individual basis: when you want to infiltrate a device or a communication, there are ways to hack into it. That’s one thing.
But the way this regulation puts it forward is not one-to-one — it would be massive. Where there are encrypted messaging services, the requirement in the law would be not to undermine encryption, while still forcing providers to do the scanning. That translates into what’s known as client-side scanning: scanning the message before it is even sent, because it’s only encrypted when it’s sent.
So the proponents say client-side scanning would not break encryption, because the content is scanned before encryption. But of course, it makes encryption useless if you only get the protection after someone has checked that your message is acceptable.
Dominic Bowen (09:52)
I remember having conversations about this technology about ten years ago — how it could be used to protect children and prevent other sorts of crime. But if an algorithm flags an innocent photograph of my child, or a family at the beach, or a mum sending a photo to a dad of their child getting ready for bed, in a private conversation between two adults — who sees it? What happens to the people sending photos that most people would recognise as perfectly reasonable to share between families or friends? What does the process look like? I assume the European Union has debated not just the law, but what occurs when material is flagged.
Simeon de Brouwer (10:41)
What currently happens is that once a message has been detected as possibly being relevant to the search for CSAM — child sexual abuse material — it is sent to an American agency, which sifts through it and sends back to European police forces whatever is relevant to them. The US therefore has an early peek at everything that is reported before it is transferred.
What the proposed regulation could do is create a European centre which receives these reports, analyses them and then dispatches them.
However, as you point out, when we talk about scanning messages it sounds appealing — as if a machine doing it is better than a human. Of course it can do it at greater scale and speed. But when we talk about scanning conversations, the scope is immense. We’re talking about something like 100 billion WhatsApp messages a day in Europe. At that scale, even the smallest margin of error means millions of mistakes a day to be reviewed by a human.
And these are not mistakes where the consequences are harmless. As we’ve already seen happen: until your case is examined by a human, your services tend to be deactivated or suspended. You have to appeal, and until then you may be locked out of your Google account or whatever accounts you have. That can be very damaging for people’s organisations or their lives.
The consequences don’t stop there, because when we talk about scanning for child sexual abuse material, we’re also talking about detecting what looks like a minor or a young person undressed. That means a big share of the material spotted and sent to law enforcement is merely consensual sexting between minors, or between a minor and someone who isn’t a minor. These cases are not criminally relevant, but they still get examined by a police officer who has to assess them and follow up if they have doubts about whether it was consensual, and to what extent it might be sexual exploitation. So the consequences are not minor.
Dominic Bowen (13:43)
It’s obviously very significant. The debate is around infrastructure, technology and legislation specifically to combat child sexual abuse, which I think nearly everyone — if not everyone — is fully behind.
But once the capability exists to scan hundreds of millions or billions of private communications daily, what prevents future governments from expanding it to terrorism or organised crime, which again most of us would be fully behind — and then to things like political extremism or political dissent? As we’ve seen right across Europe, and just recently over the weekend, we saw the AfD, which until recently the German government and German security services classified as an extremist organisation. How would we prevent future governments, once this is rolled out, from using it against what they classify as political extremists or political dissent?
Simeon de Brouwer (14:44)
Indeed, the risk of function creep, as it’s called, is very big. Once the infrastructure is there, it’s a minor change to use it for something else.
We know that Europol — an EU agency that does police work — already asked, at the very beginning when this was presented, that it be used for purposes other than searching for CSAM. So we know there is an interest, and we know that member states have this narrative that encryption is bad and messaging is to be surveilled.
Of course, the narrative now is about protecting children. It’s everywhere. But as you may have noticed, ten years ago it was terrorism. Since 9/11 in the US there has been a tremendous increase in surveillance capabilities to prevent and detect terrorist activity. This tool could be used for just that: detecting messages which give the impression you are preparing or coordinating a terrorist attack.
And indeed, if you’re looking for political dissidents — people who criticise the regime, whatever it is — that could be done, technically speaking. We tend to say that mass surveillance happens in Russia and in China. But if this proposal is adopted, we get mass surveillance too.
Dominic Bowen (16:36)
What’s your professional opinion, and the opinion of the colleagues you work with? While we’re trying to weigh the right to privacy and the legitimate need for privacy — as you said, journalists, human rights activists — against our obligation to protect children, where are we currently sitting on this debate? Are you and other experts in favour of this legislation, or is there an alternative you’re encouraging the EU to consider?
Simeon de Brouwer (17:08)
We have been very much against this regulation since day one, notably because we know that 90% of child sexual abuse happens in real life, in the offline world, and happens within or close to the household. Ninety per cent of young people being abused know the person who abuses them.
There has been very little effort — legislative or in terms of dedicated resources — from national governments to address that comprehensively, and therefore to address 90% of the abuse. Instead we’re talking nowadays about chat control, which is a measure addressing the part that is online. That part is also horrendous. But it’s not really coherent to say we need to address this at all costs when they’re not doing the rest at all costs.
It’s typical of policymakers who want to be seen doing something: they push the only measure they can think of, or the only one they can actually deliver at their level, and then say they’ve done their part. But this is neither effective at addressing online abuse nor effective at addressing abuse more broadly. And that’s terrible.
What we’re proposing is what the European Parliament ended up adopting. The Parliament restricted the scope of detection very significantly, so that it has to be targeted rather than widespread — targeted at people for whom there are signals or signs that they may be involved. It hasn’t been defined yet, but it could be that if three different people report you for approaching them with grooming intentions, or for sharing inappropriate images, then maybe you would get this automated detection — but not otherwise. That keeps the presumption of innocence.
What we propose, therefore, is an approach based on proportionality — because you don’t need to set privacy against safety. We can do both at the same time, and that’s what we need to do. Otherwise we stay stuck for even longer than the four years this proposal has already been on the table, or it gets annulled. Once it is finally adopted, there will be a legal appeal to the European Court of Justice, which will say this is completely disproportionate, you need to take it down and start from scratch. And we will have lost years and years of effort, resources and time.
Dominic Bowen (19:49)
Simeon, I’ll just take a moment to remind our listeners that if you prefer to watch your podcasts, The International Risk Podcast is always available on YouTube — please go to YouTube and search for The International Risk Podcast. If you like our content, please subscribe and like, and share it with a friend or colleague if you think they might be interested in this episode.
Simeon, if you had a billion euros and the political authority, what would you be recommending to the European Union? How would you demonstrably protect more children from online sexual abuse? What tools could we employ if we didn’t pursue this legislation?
Simeon de Brouwer (20:31)
We need to ask what the platforms are doing that fosters so much online abuse. Again, I need to draw attention to the distinction between addressing grooming — people who approach children online — and addressing the risk that people use a communication or hosting service to exchange material.
If we want to protect children, there is so much that can be done to prevent people finding children online and reaching out to them as easily as they do now. The big platforms today are built on a business model of ensuring you have everything you need online: that you’ll find new content, that people can meet very easily and exchange very easily. This is both great and bad.
If you say that you are a child, you don’t get that much added protection right now on TikTok, on Facebook, on Instagram. They should, and the European Union is pushing for better protection, but right now it’s very easy for an adult to find youth accounts and reach out to them without knowing them. You could create a new account today and reach out to a thousand accounts belonging to people you’ve identified as young, and you wouldn’t be flagged as problematic.
The ease of reach, and the fact that platforms try everything they can to retain children and other users on the platform as long as possible, leads to greater ease of exploitation.
Dominic Bowen (22:27)
Europe is debating this legislation, and debating whether and how governments should be able to penetrate encrypted communications, at exactly the same time as cyber threats continue to increase from hostile states, criminal groups and foreign intelligence services. This has been combined with a significant number of hybrid attacks — more than 200 in the last couple of years — right across Europe.
I’m working with businesses every week that are victims of these attacks, from organised criminal groups, intelligence services and hostile states, either trying to steal intellectual property, trying to make banking and insurance more complicated across Europe, or conducting a variety of other hybrid attacks.
So if the European Union is pursuing this legislation at the same time as all that is going on, could weakening encryption — or deploying a technology like this that’s meant to improve public safety — actually make Europeans less safe?
Simeon de Brouwer (23:31)
Totally, and it’s one of the arguments we put forward, because encryption protects everyone. If we weaken everyone’s communications for the sake of protecting children, the intention is laudable but the means is terrible.
This is exactly what security agencies have been warning their governments about nationally. France is one example: a couple of years ago France was very much in favour of addressing “the encryption problem”, as they put it, but their national security agency told them it would be terrible for French people and French businesses in general to have weakened encryption protection.
Dominic Bowen (24:21)
You mentioned a US agency earlier, and of course European and US relations have become strained under the second Trump administration. I’m wondering about the technology that exists today. Even if it currently sits within government agencies, it has potentially been developed by corporate actors, or at least will become available to them — and then, not long after, to criminal organisations. Bearing in mind that many organised criminal groups around the world, including in Europe, actually have state backing.
I understand from some security researchers that these client-side scanning technologies might be exploited not just by law enforcement for reasonable purposes, but also by criminal organisations. How concerning is that, and is it something platforms like WhatsApp and Signal are trying to engineer solutions to?
Simeon de Brouwer (25:28)
I’m not sure I can fully answer that, because I don’t see how criminal organisations could use the scanning technology themselves — it would be state-backed, an EU-level imposition of scanning.
The one way you could weaponise this, as researchers have proved, is that you could poison datasets, or you could poison a message you send to someone: it’s an actual normal image, but you modify it in a way that will trigger the detection algorithm and have it flagged as CSAM, leading to that account being suspended until a review has been done. So there is potential for weaponisation.
As to criminals — if in that group we include actual sexual predators — this is very much in their interest too, at least for the professional ones, the ones who are not amateurs. The amateurs get caught messaging someone on Facebook. But those who are good at this, unfortunately, know the tricks.
If you write to someone you might get caught. But if two predators want to share actual content, you don’t send the image. You send a link and a password to some hosted place — it doesn’t even have to be encrypted, as long as there’s a password. These people can exchange CSAM without being detected, because they don’t send the picture. What they send is a URL to a hosting service, and the password to access it.
Since the detection technology we’re talking about scans for content but would not be able to check every link and every password, you wouldn’t be able to find the people sharing these accesses with each other. So the professional perpetrators — the ones who actually have loads of images and videos — would mostly not get caught, because they know how to get around it.
Dominic Bowen (28:10)
Organisations like Google, Meta, Microsoft and Snap aren’t always the most popular companies, especially these days with data centres being built. Can you tell us where they sit in this debate? They obviously employ lots of lobbyists, lawyers and advocates to push their agendas across the European Union and North America. What are they arguing for? What do they want to see?
Simeon de Brouwer (28:36)
The position of these big tech platforms tends to be, at least, that they don’t want mandatory scanning. What they want instead is voluntary scanning.
This is the distinction we make between what’s currently called Chat Control 1, which allows companies to scan to detect child sexual abuse, and Chat Control 2, which is the permanent, mandatory version. They don’t want the mandatory version. They want to be able to scan if they want, when they want, how they want. And if they ever are forced to scan, they still want to be able to scan on their own terms as well.
There is a clear interest on their side in presenting the narrative that they are doing their part, because they are detecting content — without really addressing the cause of harm. What enables people being groomed online is the ease of finding young people. They’re not investing in meaningful safety measures or in content moderation. So that’s something they don’t really do, but they do want to be able to continue scanning on their own. And if they have to be forced to scan, they’ll do that too — unless, of course, it’s encrypted messages, and then they’ll be louder about it.
Dominic Bowen (30:04)
I understand there are further debates scheduled for later in September in the European Union, but that the current Chat Control 1.0 is valid until April 2028, or until a permanent child sexual abuse regulation is adopted. We’ve talked about the pros and cons — what’s the current status, and what’s likely to happen next?
Simeon de Brouwer (30:30)
The current status is that what’s agreed is a temporary derogation from the rules protecting the confidentiality of our communications. So temporarily, platforms can scan if they want to.
What’s on the table is to make that scanning mandatory and permanent. We’re at the last stages of negotiations between the Council and Parliament, where Parliament wants the law watered down in a way that protects children sufficiently without being as disproportionate as it currently is.
The next trilogue, as it’s called, is at the end of September. A trilogue is a dialogue between three parties: the Parliament, the Council, and the European Commission, which presented the proposal. So we’re waiting for those discussions to happen.
There is a lot of pressure from survivors’ groups, youth and child rights NGOs, digital rights NGOs and academics. A great deal of input has been put forward over the past four years and keeps being recycled or introduced anew as we come to a close.
The current state of play in the negotiations is that it won’t contain age verification — that was in the proposal, but it’s not a good solution to the problem, and that’s been agreed. What is in scope is some form of detection, though the detail hasn’t been agreed. What is no longer in scope, beyond age verification, is encryption: they have agreed on wording that protects encryption from being forcibly weakened or circumvented.
Dominic Bowen (32:27)
Thanks very much for that update. One question we ask all guests who come on The International Risk Podcast: when you look around the world at the huge variety of issues going on — continued conflict in the Middle East, Ebola outbreaks in the Democratic Republic of Congo, human rights abuses around the world, climate change, massive flooding and natural disasters in Nepal — what are the international risks that concern you the most?
Simeon de Brouwer (32:56)
I care deeply about my work, so I’m going to talk about digital risk.
Right now in Europe there’s a simplification agenda. The actual laws are called omnibus laws, and they simplify the laws already in place in the European Union in the name of greater innovation. What I’m very worried about is that yes, we’re simplifying some laws — but what we’ll end up getting is risky or dangerous innovation: the things we in Europe have been cautioning about for a very long time.
Particularly for digital rules, there’s a law called the Digital Omnibus, which promises to make it easier to rely on people’s data without their consent, to use automated processing, or even to use data to train AI without people having a say. All these changes are put forward in the name of competition or innovation, and end up weakening the protections that benefit us all.
Especially in my work on child protection, it’s completely incoherent to hear calls for greater protection for young people while at the same time the protection that benefits us all — young and not young — gets weakened. So that’s one key risk I see, for consumers and for people.
It also has repercussions for companies, of course. As you mentioned, there’s a lot of lobbying in Brussels, and the tech sector is actually the biggest spender on lobbying. It outperforms — if we can call that performance — pharma, tobacco and the agricultural industry. So there are a lot of commercial interests at play, and the biggest spender is big tech. The rules being put forward benefit these big players a great deal.
Even when we talk about meaningful measures, we need to be very careful. Given how much say big tech companies have in the lawmaking process through lobbying, what we often end up with is very complex rules that only the biggest players can navigate, with their armies of lawyers. That makes it very difficult for European companies and smaller companies in general to compete against them. So that’s a very clear risk for us as well.
Dominic Bowen (35:44)
Excellent. Thank you very much for explaining that — it’s important that we all understand it. And thank you very much for coming on The International Risk Podcast today.
Simeon de Brouwer (35:52)
My pleasure.
Dominic Bowen (35:54)
Can you say your name for me one more time as I close out?
Simeon de Brouwer (35:57)
Yes. My name is Simeon de Brouwer.
Dominic Bowen (36:01)
That was a great conversation with Simeon de Brouwer. I really appreciated hearing his thoughts on the future of chat control, digital rights and security in Europe, and of course the protection of children globally.
Today’s episode was produced and coordinated by Celia Irving. I’m Dominic Bowen, your host. Thanks very much for listening to The International Risk Podcast today. We’ll speak again in the next couple of days.
