The increasing circulation of child sexual abuse material (CSAM) online has become a pressing issue for child protection authorities and organisations across the EU. As digital platforms continue to play a central role in communication, the challenge of tackling child sexual exploitation has intensified. The main problem lies in the expiry of a temporary EU legal framework that allowed online service providers to voluntarily scan private communications for CSAM.
See also: Teens against xAI: Grok created child pornography with AI

This legislation, originally introduced as a derogation from the ePrivacy in 2021, officially expired on April 3, 2026.
With lawmakers failing to agree on an extension, tech companies now face an uncertain legal environment that could undermine years of progress in combating child sexual exploitation online. The now-expired framework had allowed major tech companies to proactively identify and report child sexual abuse material using tools such as hash-matching technology.
This method relies on digital fingerprinting to detect known abusive content with high accuracy, while preserving user privacy. Law enforcement agencies have consistently described such detection systems as “vital” in identifying perpetrators and rescuing victims. Without a clear legal basis, however, companies risk operating in a gray area where continuing these practices could expose them to legal challenges.
Despite this uncertainty, several major companies, including Google, Meta, Microsoft and Snap, have said they will continue voluntary efforts to detect CSAM. In a joint statement, they stressed the urgent need for EU institutions to establish a stable regulatory framework, noting that the safety of children cannot be compromised by political delays.
See also: West Virginia: Lawsuit against Apple for distributing CSAM via iCloud

Authorities warn that the lack of legal clarity could lead to a dramatic decline in reports related to child sexual exploitation. Data from previous years underscores the scale of the problem. In 2025 alone, Europol processed around 1.1 million CyberTips received from the US National Center for Missing and Exploited Children (NCMEC).
These reports included files, videos and images linked to child sexual abuse material and were relevant to investigations in 24 European countries. Officials have warned that this scenario is not hypothetical. A similar expiry of legal provisions in 2021 led to a noticeable drop in reports, showing how dependent investigations are on cooperation with digital platforms.
Behind every CSAM case is a real child being abused. The constant circulation of such material forces victims to relive their trauma over and over again. Advocacy groups argue that the failure to detect and remove this content effectively denies children their fundamental rights, including privacy and protection. The absence of robust detection tools also means that many victims may remain unidentified and trapped in abusive environments.
Law enforcement agencies rely heavily on digital evidence to locate and rescue affected individuals. Any disruption to this process directly impacts their ability to intervene.
Despite the legal ambiguity, tech companies have reaffirmed their commitment to tackling child sexual abuse material. They argue that voluntary screening practices have been in place for nearly two decades and remain a cornerstone of online safety.
See also: EU: Investigates Grok for creating CSAM images

These companies argue that tools like hash matching are essential to identifying known CSAM and preventing its spread. They also emphasize that such systems are designed to balance security with privacy, addressing concerns about overreach. However, industry leaders have made it clear that a long-term solution must come from lawmakers.
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
