Two European regulatory stories closed out early August. Neither went the way its supporters or opponents expected, and the mechanism by which each resolved is more instructive than the outcome.

Chat Control 1.0, restored by arithmetic

Member states approved the temporary rules allowing online service providers to resume voluntary detection of child sexual abuse material, after the derogation lapsed in April. The regime — “Chat Control 1.0” — now applies until 3 April 2028, or until a permanent regulation is in place.

Under it, providers may voluntarily scan certain unencrypted private communications: direct messages on social media, gaming, and other communication platforms. Detection may target previously known CSAM, and in some circumstances suspected new material and grooming.

The way it survived is the story.

In the July plenary, 314 MEPs voted to reject the extension. That is a majority of votes cast. But this was a second reading, which requires an absolute majority of all serving MEPs361 votes — to reject a Council position. Opponents fell 47 short of a threshold calculated against the full chamber rather than those present and voting.

So a measure that a plurality of the European Parliament actively voted against is now law until 2028, because the procedural bar for stopping it was set higher than the bar for passing it. That is a legitimate constitutional design — second-reading thresholds exist to prevent a small quorum from unravelling an inter-institutional agreement — and it is also how a majority-opposed surveillance measure survives. We covered the vote as it happened; the Council’s August confirmation makes it final.

The distinctions that keep getting collapsed

Three things are worth being precise about, in both directions.

This is the voluntary derogation, not mandatory scanning detection orders. Chat Control 1.0 permits providers to scan. It does not compel them. The fight over mandatory detection orders — the version that would compel providers to scan, including pressure toward client-side scanning of end-to-end encrypted messages — is the permanent CSA Regulation, still unresolved. Conflating them costs credibility.

It applies to unencrypted communications. Signal and WhatsApp message contents are not scannable under this regime without breaking the encryption, which this text does not require.

And yet the concern is legitimate. A “temporary” derogation now on its third extension, running to 2028, is not temporary. Voluntary scanning normalises the infrastructure, the vendor relationships, and the political expectation that private messages are a searchable space — which is exactly the groundwork a mandatory regime is built on. Meanwhile scanning has documented false-positive problems, and the consequences of a false positive in this category are severe and immediate.

The honest summary: nothing changed for encrypted messengers, and the political trajectory got worse.

The AI Act date that was moved three weeks before it landed

2 August 2026 was, for two years, the date the EU AI Act’s requirements for high-risk systems were to apply — recruitment AI, biometric identification, law enforcement systems, education and credit scoring, all of Annex III.

On 27 July 2026, five days before, the Digital Omnibus entered into force following publication in the Official Journal on 24 July. It moved the Annex III high-risk obligations to 2 December 2027, and the Annex I embedded-product obligations to 2 August 2028.

So the flagship compliance date for the world’s most consequential AI regulation was pushed back by sixteen months, less than a week before it arrived, by a simplification instrument.

What did take effect on 2 August, and matters:

  • Article 50 transparency obligations — disclosure that content is AI-generated, marking of synthetic media. This is the provision that prompted Anthropic to watermark Claude’s output globally.
  • Enforcement powers over general-purpose AI models.
  • The full penalty regime — up to 7% of global annual turnover for prohibited practices.

The prohibitions in Article 5 have been in force since February 2025 and remain: no untargeted scraping of facial images to build recognition databases, no emotion recognition in workplaces or schools, no social scoring, no real-time remote biometric identification in public by law enforcement outside narrow authorised exceptions.

Which is worth holding next to this week’s deployment of live facial recognition in the London Underground. The same technology, in the same week: a prohibited practice in Brussels, a police trial in London.

We flagged the biometric delay when it happened. The August date confirmed it.

The shared lesson

Both stories turn on the same thing: in EU privacy law, the deadline is a variable, not a constant.

Chat Control’s temporary derogation has been extended repeatedly and now runs six years past its original expiry. The AI Act’s high-risk date moved sixteen months, five days before it bound anyone. The GDPR’s own Digital Omnibus process is separately reopening settled provisions.

For companies, this creates a rational incentive to defer compliance investment, because the deadline has a meaningful probability of moving. For citizens, it means rights announced in a regulation are not rights until the date passes without being amended — and increasingly, it does not.

The pattern is not corruption or incompetence. It is what happens when ambitious regulation meets a competitiveness agenda and sustained industry lobbying, and the path of least resistance is always to keep the text and move the date.

What it means in practice

Your encrypted messages are unaffected. Signal, and WhatsApp message contents, are not scannable under Chat Control 1.0. Use them.

Your unencrypted DMs on major platforms may be scanned, voluntarily, by the platform. They largely were before April anyway. Treat platform DMs as non-private, which was always the correct assumption.

AI transparency obligations are live now. If you deploy generative AI in the EU, the marking and disclosure duties applied on 2 August regardless of the high-risk delay.

High-risk AI compliance work should not stop. December 2027 is not far, the requirements did not change, and a deadline that moved once can also stop moving.

What you can do

  1. Move sensitive conversations to end-to-end encrypted messengers. Signal is the default recommendation. For WhatsApp, turn off cloud backups or ensure they are end-to-end encrypted, because an unencrypted backup defeats the encryption entirely.

  2. Understand what “voluntary” means here. The provider decides. Your protection is the provider’s policy, which can change without notice. Encryption is the only control that does not depend on a corporate decision.

  3. EU residents: watch the permanent CSA Regulation, not this one. The mandatory detection order fight is the one that determines whether encrypted messaging survives in Europe, and it is still open.

  4. If you build AI products for the EU market, audit your Article 50 disclosures now. Transparency and synthetic-media marking are enforceable today, with the full penalty regime behind them.

  5. Stop treating announced compliance dates as fixed. Build to the requirement, not to the calendar — the requirement is stable and the calendar is not.