# Exit Chat Control · Become Ungovernable Source: https://exitchatcontrol.org ## Summary The EU's "Chat Control" proposals would amount to mass surveillance of private messages, and encrypted tools are presented as the main defence. The interim scanning rules were reinstated on 23 July 2026 until 3 April 2028 and exclude end-to-end encrypted messengers such as Signal. The permanent proposal, first put forward by Ylva Johansson in May 2022, has no final text after a trilogue ended without agreement on 29 September 2026. Citing Irish police figures, the piece says only about 20% of automated reports were actual material, and over 11% were false positives. ## Article Contents The guide, topic by topic Delete / AdoptThe big picture at a glance. Each tool is detailed in the numbered sections below. Encrypted messagingThe first move, the one that protects you fastest: leave WhatsApp, Messenger and Telegram for a genuinely encrypted (ideally open-source) messenger.10 tools Encrypted email & PGPGmail reads your email and lives in the US, under "Five Eyes" jurisdiction. Leaving Gmail/Outlook is a huge win for minimal effort.3 tools Browser & searchChrome is an advertising tracker. Google Search profiles every query. Replace both.5 tools Encrypted DNS & CloudflareDNS is the directory that turns a site name (example.com) into a machine address. The catch: by default your internet provider runs that directory, so it…4 tools VPN: the truthA VPN is useful, but sold with a lot of lies. Here's what it actually protects.5 tools Censorship & identity checksThe same pretext ("protect minors") is used to force identity checks to access the internet. It's the planned end of online anonymity, and therefore a form… Leave GoogleGoogle is a single account that knows your email, calendar, files, movements and searches. Replace the whole suite. Encrypted storageYour files, photos and backups without handing them to Google or Apple: end-to-end encrypted cloud, client-side encryption and encrypted drives.4 tools Password managerOne strong, unique password per service: the foundation of everything that follows. Drop the notebook, drop the reused password.3 tools Two-factor auth & hardware keysA password, even a strong one, can leak. Two-factor authentication (2FA) adds a second proof at login: even if your password is stolen, the account stays…2 tools Decentralised socialInstagram, X and Facebook belong to companies that profile you and can censor or delete you overnight. The "fediverse" offers networks owned by their users.4 tools Financial sovereigntyMoney is surveilled and censorable too. Activists' accounts have been frozen, donations blocked, and every card payment is tracked. Financial privacy is…3 tools Conversational AIWhile we fight to encrypt our messages, hundreds of millions of people pour their most intimate thoughts into ChatGPT, Gemini or Copilot, on US servers…3 tools The everyday toolboxGoogle and Apple are not just email: maps, notes, calendar, photos, video calls, everything is tied to your identity. Here's how to replace each brick, one…7 tools Self-hostingThe ultimate level of sovereignty: host your services yourself. Your data lives on your hardware, under the jurisdiction you choose.4 tools TorThe network that separates who you are from what you do online.1 tool Free operating systemsThe keystone. If client-side scanning can be imposed by the operating system itself, the only real counter is to control that OS. That's true on the phone…4 tools Telephony & physical deviceThe best app is useless if the device itself betrays you. Here are the hardware threats and the moves that neutralise them. Anonymity & OPSECFor the pseudonymous account and the whistleblower. Here you no longer protect just a message: you protect an identity. The full free ecosystemFully de-Googling means replacing each brick with a free equivalent. The common logic (free software + control of your device + self-hosting) is the real… Migration & digital civil disobedienceA progressive migration plan, week by week, the classic mistakes to avoid, and how to act collectively against Chat Control. Thirty years of precedentsEvery generation is told the surveillance is new, limited and temporary. Dated and sourced: the same script since 1993. Click a date to cite an entry. Big Brother observatoryChat Control is one front among five. What passed, what is on the table, what was pushed back, region by region, theme by theme. Allied initiativesThe organisations fighting this in courtrooms and parliaments, and the projects keeping the receipts. Open-source directory66 free-software tools in 14 categories. Every entry is open source: verifiable code, no goodwill required. Migration checklistFourteen steps, from ten-minute wins to weekend projects. Ticks are saved in this browser only. Nothing leaves your device. Read the whole guide on one page → PART 00 · THE WHY Understand the threat Before you change tools, understand what you are protecting against. Otherwise you install random apps and feel safe when you are not. Chat Control 1.0 and 2.0, plainly “Chat Control” is the nickname for two EU texts that allow (or would require) scanning your private messages for child sexual abuse material (CSAM). The stated goal is legitimate; the method, blanket scanning of the communications of unsuspected people, amounts to mass surveillance. Chat Control 1.0Chat Control 2.0 (CSAR) TextRegulation (EU) 2021/1232, ePrivacy derogationProposal COM/2022/209 (Ylva Johansson, May 2022) Scanning Voluntary, platforms may scan Commission proposal: mandatory via “detection orders”. Council position (Nov 2025): voluntary scanning made permanent, plus “risk-mitigation measures” Who Mostly unencrypted US services: Gmail, Messenger/Instagram, Skype, Snapchat, iCloud Mail, Xbox All platforms, including end-to-end encrypted messengers DurationTemporary: lapsed on 3 April 2026, reinstated on 23 July 2026 until 3 April 2028Permanent (no expiry date planned) Status (Oct 2026) In force, end-to-end encrypted communications excluded from its scope Under negotiation (trilogue): no final text, nothing in force Chat Control 1.0 today: what is covered, what is not The interim regulation lapsed on 3 April 2026, then came back: after a second reading in the European Parliament, the Council gave it final approval on 23 July 2026 (Regulation (EU) 2026/1881), until 3 April 2028. It allows, without requiring, providers to scan private communications for child sexual abuse material. What is covered: communication services that are not end-to-end encrypted and whose provider chooses to scan, for example Messenger or Instagram messages, Gmail or Outlook e-mail, chat built into game consoles and platforms. Google, Microsoft, Meta and Snapchat are among the signatories of the 19 March 2026 call to keep this detection going. What is excluded: an amendment adopted by Parliament, then accepted by the Council, removes from its scope communications “to which end-to-end encryption is, has been or will be applied”. Messengers that are end-to-end encrypted by default, such as Signal, Session, Threema, SimpleX Chat or Olvid, are therefore not covered by this text (see encrypted messaging). This exclusion only applies to this interim text. The permanent regulation, or a harsher version, can go back on it: this guide plans for that scenario and recommends tools that stay protective even if scanning became mandatory. E-mail, the weak link Proton Mail and Tuta encrypt messages between their own users. But an e-mail exchanged with a Gmail or Outlook address reaches that provider in the clear, and it can scan it on its side: neither Proton nor Tuta can prevent that. PGP encryption also works from Gmail; it protects the message body, but not the subject line or the metadata (see encrypted e-mail). Chat Control 2.0: what the text would do The permanent regulation (CSAR) is still being negotiated between the Commission, the Council and Parliament (trilogue). The sixth trilogue, on 29 September 2026, ended without agreement and technical talks continue. There is no final text and nothing is in force. The Commission proposed mandatory “detection orders” in 2022, encrypted messengers included. The Council (position of 26 November 2025) dropped mandatory orders, but makes voluntary scanning permanent and requires “risk-mitigation measures”, which could include scanning. Parliament wants detection limited to suspects, on a judge’s order, and end-to-end encryption protected. If client-side scanning became mandatory What follows is not in force: these are the plausible consequences if the final text required scanning on devices. Messengers that comply would ship an EU version with a scanning module running before encryption, distinct from the versions offered elsewhere. Messengers that refuse could leave the European market, as Signal publicly announced in October 2025. The app would then disappear from European app stores: on iOS it would become hard or impossible to get; on Android the publisher can offer the APK on its official website. If the download or the service were blocked from the EU, only a VPN or Tor would reach it. Scanning at operating-system level: if the obligation targeted the systems themselves, a free app would no longer be enough. Out of reach would remain non-cooperating systems, GrapheneOS on mobile and non-regional GNU/Linux distributions on computers (see free operating systems), used with a messenger that also refuses scanning. Thanks to Jérémy Roche, lawyer at the Béziers bar, for his advice on this part. Client-side scanning: the legal wiretap The heart of Chat Control 2.0 is a technique called client-side scanning. The idea: instead of breaking encryption in transit, software is installed directly on your phone to inspect every message, photo or link before it is encrypted and sent. Signal put it in one line: it is “like malware on your device”. Technical honesty, read twice Against client-side scanning, neither a VPN nor end-to-end encryption is enough if the app or the operating system cooperates. The scan happens on the device, before encryption: the VPN has nothing to protect, and encryption kicks in too late. What actually protects you is choosing free/open-source software that refuses to implement scanning, favourable jurisdictions, self-hosting, and taking back control of your device (an untampered OS). Everything else in this guide follows from this truth. Worst of all: the tool doesn’t even work Everyone’s privacy is sacrificed for a technology that fails. The European Parliament’s own study concludes no system detects this content without a high error rate (because across billions of messages, even a tiny false-positive rate yields millions of false accusations). Irish police figures show it: of automated reports, only about 20% were actual material, and over 11% were outright false positives. Landmark research (“Bugs in Our Pockets,” 2021) further shows that once client-side scanning is installed, it is inevitably repurposed (terrorism, copyright, opinions). The pretext: “protecting children” No one is against protecting minors, which is exactly what makes it such an effective lever. Fighting child abuse serves as an emotional Trojan horse: who would dare object? Under that banner, a principle is made acceptable that, on its own, would be flatly rejected, the automated inspection of the private communications of hundreds of millions of unsuspected people. Children are the stated motive; the real target is everyone’s encryption and privacy. The tell: the companies pushing hardest for this scanning are the ones whose business model is surveillance. On 19 March 2026, a joint appeal urged EU lawmakers to entrench “voluntary” detection, signed by: GoogleLinkedInSnapchatMicrosoftTikTokMeta “Failure to do so would be irresponsible.” The tech giants’ argument for keeping message scanning alive. Those same players even announced they would keep scanning messages after the legal basis lapsed on 3 April 2026. Citizens are thus asked to entrust the inspection of their intimate conversations to the very companies known for harvesting and monetising their data. This is the real face of Chat Control: an attack on privacy wrapped in a motive no one can refuse. This is not “just” surveillance They try to reassure you: “it’s only Gmail, Instagram, Snapchat, Messenger.” That’s false, and it’s the most alarming part. Three shifts hide behind that downplaying. It’s not targeting, it’s dragnet. This doesn’t watch suspects: it installs systematic collection of entire populations’ communications. Surveillance at state scale, continuously. It’s no longer reading, it’s the power to block. Software that inspects a message before it’s sent can also refuse to send it. Client-side scanning builds the infrastructure of prior censorship: blocking speech before it even reaches its recipient. Once the infrastructure exists, it gets repurposed. A system built “for the children” becomes a general-purpose control tool. The motive changes; the machine stays. The logical next step: the digital euro The same logic is about to reach your money. The ECB’s digital euro rests on a traceable currency, bars companies from holding any, and comes with a holding cap: the ECB has floated about €3,000 per person as a working assumption, and the position voted in the European Parliament’s committee (June 2026) leaves the cap for the Commission to set on the ECB’s recommendation, reviewed every two years. The ECB swears the currency won’t be “programmable,” but the cap and the traceability are very much on the menu. When it lands, will you say “relax, it’s only a cap”? That’s the very same rhetorical trap as “it’s only Gmail.” The real question is never what is controlled today, but the control infrastructure being installed for tomorrow. Which profile are you? No tool is magic and nobody needs to do everything. Find your profile: each section tells you how far to go. Beginner 🟢 The ordinary citizen You just want your conversations and private life to stop being scanned and monetised. Goal: everyday privacy, without becoming an expert. Intermediate 🟡 The pseudonymous account Information account, activist page, creator: you fear being deanonymised, doxxed, or losing your account. Goal: separate your real identity from your public one. Advanced 🔴 The whistleblower Journalist, activist, source, facing a powerful adversary (state, employer). Goal: strong anonymity, anti-correlation, passing documents without being caught. Manifesto Changing tools is an act of individual responsibility, one that belongs to each of us: it is how you refuse an illegitimate mass surveillance. Encrypting is protecting your private life. Self-hosting is pulling yourself out of Big Tech's surveillance. Taking back control of your tools is becoming ungovernable and sovereign. The fight is political. Support the organisations opposing it, like the fightchatcontrol.eu initiative, and write to your representatives. That is what almost brought Chat Control down. But since the solution will probably come neither from the ballot box nor from the European Parliament, it falls to each of us to win our freedom and protect our privacy with every tool the Internet offers.