We can't scan what we don't have.
The proposed EU regulation on preventing and combating child sexual abuse — known across Europe as EU Chat Control, or formally CSAR (COM/2022/209) — would require messaging providers to scan private communications for known child sexual abuse material (CSAM), and to introduce "effective and proportionate" mitigation measures against the risk of grooming.
uOS rejects this proposal in principle, and more importantly, it cannot apply to our architecture in practice. We can't scan what we don't have. That is the entire situation.
What the proposal actually asks
In its most contested form, CSAR would require messaging providers — including end-to-end encrypted services — to:
- Assess annually the risk that their service is used for CSAM distribution or grooming;
- Implement "effective and proportionate" mitigation measures;
- Execute "detection orders" issued by a judicial authority against specific users or groups;
- Remove reported CSAM content;
- Report detected content to EUROPOL or national law enforcement;
- Publish an annual transparency report.
Where this stands — July 2026
On 9 July 2026 the European Parliament voted 314 against and 276 in favour of extending Chat Control 1.0 — and it passed anyway. The vote was a second reading, where rejecting the text required an absolute majority of all MEPs; the opponents did not reach that threshold. Suspicionless scanning is therefore legal again in the EU until 2028 under the voluntary framework, on services such as Gmail, Messenger, Snapchat and Skype.
The permanent regulation — CSAR, or "Chat Control 2.0" — is still being negotiated. Five trilogue rounds have failed to produce a deal; the fifth collapsed on 29 June 2026 over precisely this question of suspicionless scanning. A sixth round is expected under the Irish Presidency, around September 2026. The core dispute has not moved: blanket scanning at the platform's discretion, versus targeted detection ordered by a judge.
Restoring Chat Control 1.0 did not settle the question — it removed the Council's incentive to compromise on the permanent text. Which is why the argument below matters more now, not less.
Why the proposal cannot apply to uOS
uOS is built around the following technical facts:
- No plaintext on our servers.Every message exchanged between uOS users is encrypted end-to-end with XChaCha20-Poly1305, with session keys derived via HKDF-SHA256 from a shared secret exchanged through ML-KEM-768 (FIPS 203). Our servers only ever relay ciphertext frames.
- No private keys on our servers.User identity is generated client-side from secrets only the user controls, producing the ML-DSA-65 signing keypair and ML-KEM-768 keypair locally. The private keys never leave the user's device memory.
- No persistent data on user devices.Each browser session starts from a wiped state — IndexedDB, localStorage and caches are deliberately cleared at boot. There is no device-side state to seize.
- No metadata beyond transport routing.We log only what is required to forward the WebSocket frame: user_pub, platform_id, counter, timestamp. We do not log message bodies, contact graphs, or content hashes.
No component of this stack can be modified to perform content scanning without breaking the confidentiality of every user on the platform. The proposal is asking the impossible. We don't say this as defiance — we say it as an architectural fact.
Our position
- We will not implement client-side scanning.The EU Charter (Articles 7 and 8) and the European Convention on Human Rights (Article 8) protect private communications as a fundamental right. Any technical mechanism that allows content scanning before encryption is a backdoor, regardless of its stated purpose.
- We will defend the architectural fact in court.We support the existing challenges to CSAR before the Court of Justice of the European Union and national constitutional courts. Where an order requires us to act on content we cannot read, we will seek judicial review before any compliance.
- We will publish what is asked.We will publish a Transparency Report listing the orders we have received from authorities, the ones we have complied with within the limits of what is technically executable, and the ones we have contested.
- We will stay in Europe.We will not relocate offshore to avoid this debate. European digital sovereignty is defended within European institutions, not from a Swiss or Icelandic exile.
- We support restricting any detection to individuals identified by a judicial authority.That is the Parliament's position, and it is the only version of CSAR compatible with fundamental rights. Services whose architecture makes scanning technically impossible should be explicitly exempted, by construction rather than by political carve-out.
What this means in plain language
If a regulator comes to uOS and says: "scan your users for CSAM" — we respond: "we cannot, we have nothing to scan."
If the regulator responds: "then leave Europe" — we respond: "we will stay, and we will contest that order."
If the regulator responds: "we will fine you" — we respond: "we will pay the fine, if it is lawful and proportionate, and continue to defend our position through every available legal avenue."
We cannot be made to scan. We cannot be made to backdoor. We can only be made to keep being a working argument for digital sovereignty.