An announced deadline, weeks of deadlock, and an outcome that the big platforms themselves call “irresponsible.” While the European Union lets the rules on detecting online child sexual abuse material expire, Google, Meta, Snap and Microsoft respond with a joint statement and promise to continue monitoring activities anyway. Meanwhile, Europol warns that the legal vacuum risks directly compromising investigations and victim identification.
THE EU PARLIAMENT VOTE AND THE BIG TECH REACTION
The European Parliament rejected the extension of the temporary regulation that allowed platforms to detect online child sexual abuse material (CSAM), with 311 votes against, 228 in favor, and 92 abstentions. The law thus expired on April 3, making content scanning illegal.
The decision came despite pressure from national governments, the European Commission, and Big Tech. Among these, Google, Meta, Snap and Microsoft reacted with a joint statement, announcing they will voluntarily continue to monitor their platforms to detect CSAM. “We are disappointed by this irresponsible failure to reach an agreement to maintain consolidated efforts to protect minors online,” they said. The same companies had already warned that “inaction will reduce the legal clarity that has allowed companies, for nearly 20 years, to voluntarily detect and report online child sexual abuse material in interpersonal communication services.”
“As a parent, legislator, and European, I find today’s vote in the European Parliament hard to understand,” commented Home Affairs Commissioner Magnus Brunner, adding that the decision will leave “countless victims without visibility or protection.”
A LEGAL VACUUM THAT AFFECTS INVESTIGATIONS
With the end of the e-Privacy exemption, content scanning thus becomes illegal, while the removal obligation under the Digital Services Act (DSA) remains. Meanwhile, platforms find themselves in a situation of regulatory uncertainty.
Europol Executive Director Catherine De Bolle also issued a direct warning about operational consequences. “If the current legal basis for voluntary detection by online platforms were to disappear, a significant reduction in CyberTip reports is expected.” This “would compromise the ability to identify relevant investigative leads” and “would seriously harm the EU’s security interests in victim identification and child protection.”
From the law enforcement perspective, she added, allowing platforms to continue detecting and reporting suspicious content is “fundamental to child protection.”
THE RISK OF A COLLAPSE IN REPORTS IS REAL, DATA SHOW
Concerns are based on concrete precedents. During a similar regulatory gap in 2021, the European Child Sexual Abuse Legislation Advocacy Group states that CSAM reports in the EU decreased by 58% over 18 weeks.
According to data from the National Center for Missing and Exploited Children (NCMEC), a US organization that acts as a reporting hub for abuse and forwards reports to competent law enforcement worldwide, in 2021 reports dropped from about 4.3 million in 2020 to 1.8 million. Meanwhile, in 2025, the organization received 21.3 million reports containing over 61.8 million suspicious files globally, with about 90% coming from outside the United States.
Europol also handled about 1.1 million CyberTips relevant to 24 European countries.
“When detection tools are interrupted, we lose visibility,” said NCMEC Vice President John Shehan. “When detection stops, abuse doesn’t.”
THE POLITICAL CLASH OVER PRIVACY
The vote is the result of a prolonged clash between privacy advocates and child rights defenders. The Parliament insisted on limiting the scope of scanning, considering existing measures disproportionate to the risks to fundamental rights.
The vote, argues an article by EuObserver, also reflects the rise of what is called the “privacy cult,” an approach that prioritizes personal data protection over other needs, such as child safety. According to this reading, the European Parliament indeed prioritized a “theoretical” protection of privacy, neglecting the concrete effects on combating abuse.
“Blocking CSAM is not a privacy evasion. Freedom of expression does not include child sexual abuse,” said Hannah Swirsky, Head of Policy and Public Affairs at the Internet Watch Foundation, a UK nonprofit for child safety.
On the other side, opponents of the rules argue that “millions of innocent citizens’ private messages have been analyzed for years without adequate results,” said Czech Green MEP Markéta Gregorová. And former MEP from the same party, Patrick Breyer, added that “indiscriminate scanning of our private digital messages must remain strictly prohibited.”
FAILED NEGOTIATIONS AND UNCERTAIN PROSPECTS
Negotiations between Parliament, Council, and Commission repeatedly failed in the weeks before the vote. As Euractiv wrote, national governments pushed for a quick extension, while Parliament demanded stricter restrictions. “Unfortunately, the European Parliament insisted on changing the scope of the temporary measure in a way that made it ineffective,” said the Cypriot Council presidency. Socialist MEP Birgit Sippel instead stated that member states “deliberately accepted that the temporary regulation would expire in April.”
Meanwhile, the negotiation on the permanent regulation (CSAR) remains stalled, leaving a legal vacuum just as platforms – even without a clear legal basis – declare they want to continue detection activities. “The EU is effectively risking leaving doors open to predators,” concluded Swirsky.




