HomeSecurityEU: Child safety at risk as law on... expires

EU: Child safety at risk as CSAM detection law expires

The increasing circulation of child sexual abuse material (CSAM) online has become a pressing issue for child protection authorities and organisations across the EU. As digital platforms continue to play a central role in communication, the challenge of tackling child sexual exploitation has intensified. The main problem lies in the expiry of a temporary EU legal framework that allowed online service providers to voluntarily scan private communications for CSAM.

See also: Teens against xAI: Grok created child pornography with AI

CSAM

This legislation, originally introduced as a derogation from the ePrivacy in 2021, officially expired on April 3, 2026.

With lawmakers failing to agree on an extension, tech companies now face an uncertain legal environment that could undermine years of progress in combating child sexual exploitation online. The now-expired framework had allowed major tech companies to proactively identify and report child sexual abuse material using tools such as hash-matching technology.

This method relies on digital fingerprinting to detect known abusive content with high accuracy, while preserving user privacy. Law enforcement agencies have consistently described such detection systems as “vital” in identifying perpetrators and rescuing victims. Without a clear legal basis, however, companies risk operating in a gray area where continuing these practices could expose them to legal challenges.

Despite this uncertainty, several major companies, including Google, Meta, Microsoft and Snap, have said they will continue voluntary efforts to detect CSAM. In a joint statement, they stressed the urgent need for EU institutions to establish a stable regulatory framework, noting that the safety of children cannot be compromised by political delays.

See also: West Virginia: Lawsuit against Apple for distributing CSAM via iCloud

EU: Child safety at risk as CSAM detection law expires

Authorities warn that the lack of legal clarity could lead to a dramatic decline in reports related to child sexual exploitation. Data from previous years underscores the scale of the problem. In 2025 alone, Europol processed around 1.1 million CyberTips received from the US National Center for Missing and Exploited Children (NCMEC).

These reports included files, videos and images linked to child sexual abuse material and were relevant to investigations in 24 European countries. Officials have warned that this scenario is not hypothetical. A similar expiry of legal provisions in 2021 led to a noticeable drop in reports, showing how dependent investigations are on cooperation with digital platforms.

Behind every CSAM case is a real child being abused. The constant circulation of such material forces victims to relive their trauma over and over again. Advocacy groups argue that the failure to detect and remove this content effectively denies children their fundamental rights, including privacy and protection. The absence of robust detection tools also means that many victims may remain unidentified and trapped in abusive environments.

Law enforcement agencies rely heavily on digital evidence to locate and rescue affected individuals. Any disruption to this process directly impacts their ability to intervene.

Despite the legal ambiguity, tech companies have reaffirmed their commitment to tackling child sexual abuse material. They argue that voluntary screening practices have been in place for nearly two decades and remain a cornerstone of online safety.

See also: EU: Investigates Grok for creating CSAM images

EU: Child safety at risk as CSAM detection law expires

These companies argue that tools like hash matching are essential to identifying known CSAM and preventing its spread. They also emphasize that such systems are designed to balance security with privacy, addressing concerns about overreach. However, industry leaders have made it clear that a long-term solution must come from lawmakers.

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Absentee Mia
Absentee Miahttps://www.secnews.gr/politiki-syntaxis/
Member of the Editorial Team of SecNews. He writes about cybersecurity, online fraud, privacy and technology. All articles follow the SecNews Editorial Policy.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS