Thursday, July 23, 2026Thu, Jul 23
HomeTechEU Extends Child Abuse Detection Powers Through 2028
Tech · Politics

EU Extends Child Abuse Detection Powers Through 2028

EU extends legal powers for platforms to detect child abuse material until 2028, keeping encrypted chats private. What Malta residents need to know about online safety.

EU Extends Child Abuse Detection Powers Through 2028
Illustration of scales of justice with gavel, representing balance between punishment and rehabilitation in sentencing

Online platforms operating in Malta and across the EU can once again legally scan for child sexual abuse material, after European lawmakers extended temporary detection powers through April 2028. The renewal, approved July 23, gives negotiators 21 months to finalize permanent rules while keeping WhatsApp and Signal's encrypted messaging off-limits to scanning.

For Malta residents, this means familiar apps and services will continue operating detection systems without interruption, while your encrypted WhatsApp and Signal messages remain legally protected from scanning.

The Malta-based offices of major tech firms operating across the EU—including messaging services, social media platforms, and cloud storage providers—can now resume voluntary detection efforts that were briefly suspended when the previous temporary regulation lapsed on April 3, 2026. Both the European Parliament and the Council approved the extension on July 23, marking the second time Brussels has extended interim powers while lawmakers wrestle with the architecture of a long-term system.

Why This Matters

Legal clarity restored: Platforms can once again use hash-matching (digital fingerprints) and AI classifiers to flag known abuse imagery without fear of violating EU privacy law.

Encrypted chats remain off-limits: The renewed measure explicitly excludes end-to-end encrypted communications—services such as WhatsApp, Signal, and Telegram's secret chats are not covered.

Deadline pressure: EU member states and the Parliament have until April 3, 2028 to finalize a permanent Child Sexual Abuse Regulation, or face another legal vacuum.

The Detection Gap and Its Consequences

When the original temporary powers expired earlier this year, child-safety advocates warned of an "online blind spot" that could cost an estimated 55,000 missed reports per day. Historical precedent supports that alarm: during a similar regulatory lapse in late 2020 and early 2021, reports of child sexual abuse material from EU-based accounts to the U.S. National Center for Missing and Exploited Children (NCMEC) plummeted 58% in 18 weeks—not because abuse declined, but because detection stopped.

Up to 99% of abuse-material reports historically originated from voluntary platform scans using automated tools. Four out of five criminal investigations into child exploitation were triggered by these industry-generated alerts, underscoring the operational importance of legal authorization. In 2023 alone, more than 36.2 million reports of suspected online child sexual abuse were filed globally, a record high. Detected reports exceeded 20.5 million in 2024, even as AI-generated abuse imagery surged 1,325% year-on-year—from 4,700 cases in 2023 to 67,000 in 2024.

What the Renewed Authorization Allows

The temporary regulation grants online service providers a legal basis to deploy two primary detection technologies:

Hash-matching (PhotoDNA): Platforms generate unique digital fingerprints of images and videos, then compare those hashes against databases of known child sexual abuse material. Because the comparison happens at the hash level, no human reviewer sees the illicit content itself, preserving both efficiency and operator wellbeing.

AI-based classifiers: Machine-learning models trained to identify new or previously unknown abuse imagery, prioritize reports for human review, detect objects or age indicators in photos, and extract keywords from audio tracks in videos. These tools are used by law enforcement agencies, INHOPE Hotlines, and the tech industry to sift through billions of files uploaded daily.

Crucially, the renewed measure does not permit scanning of end-to-end encrypted messages. That limitation reflects intense lobbying by privacy advocates and cryptography experts who argue that any backdoor—even one designed for child protection—would weaken the security of financial transactions, health records, and journalistic communication for all EU residents.

What This Means for Malta Residents

For individuals living in Malta, the practical implications are threefold:

Service continuity: Popular messaging and social-media apps will not face sudden bans or service disruptions. Platforms such as Facebook, Instagram, Google Photos, and Microsoft OneDrive can continue to operate detection systems without legal risk.

Privacy boundaries: Your end-to-end encrypted chats on WhatsApp, Signal, and similar apps remain private by law. Providers are forbidden from scanning the content of these messages under the interim regulation, though metadata—who you messaged and when—may still be collected for other compliance purposes.

Regulatory uncertainty ahead: The 2028 deadline is firm. If the EU fails to adopt permanent rules by then, Malta and other member states will face a choice: another temporary extension, a patchwork of national laws, or a return to the legal vacuum that disrupted detection earlier this year.

The Broader Legislative Puzzle

Parallel to the interim measure, the EU reached a provisional agreement on June 22, 2026 for a revised Criminal Law Directive on Child Sexual Abuse. That directive expands offense definitions to cover paying to access livestreamed abuse, designing AI systems to generate child sexual abuse material, and grooming minors to produce such content. Penalties increase, and the statute of limitations extends up to 32 years after the victim reaches adulthood. Member states have three years to transpose (incorporate) the directive into national law, meaning it will be enforceable across Malta and the rest of the bloc by April 2028.

The more contentious piece is the Child Sexual Abuse Regulation (CSAR), originally proposed by the European Commission on May 11, 2022. CSAR would create mandatory detection, reporting, and removal obligations for online service providers, backed by a new EU Centre to Prevent and Combat Child Sexual Abuse. The Centre would maintain centralized databases of hash indicators and AI classifiers, issue detection orders to specific platforms, and coordinate cross-border investigations.

Negotiations between the Council and Parliament remain deadlocked over three core issues: whether detection orders can apply to encrypted services, what judicial oversight is required before a detection order is issued, and how to define the threshold for "reasonable suspicion" that a platform is being used for abuse. Privacy advocates warn that mandatory scanning could normalize mass surveillance; child-safety groups counter that voluntary measures alone cannot keep pace with offender tradecraft, especially as criminals migrate to smaller, less-regulated platforms.

Operational Impact on Law Enforcement

Europol's Victim Identification Task Force has demonstrated the value of coordinated detection and reporting. During an operation in September 2025, collaborative analysis identified 51 sexually abused children and generated 213 investigative leads sent to national authorities, resulting in victim safeguarding and multiple arrests. National statistics reflect steady caseloads: Italy recorded over 2,400 child sexual abuse cases in 2022, with significant increases in possession of pornographic material and sexual violence offenses between 2012 and 2022. Finland reported 3,210 sexual offenses against children in 2021, up from 2,660 the previous year.

Without legal authorization to scan, those leads dry up. Law enforcement agencies in Malta and across the EU rely heavily on automated alerts to prioritize finite investigative resources; manual detection and undercover operations alone cannot match the scale of abuse occurring on mainstream platforms and encrypted forums alike.

What Happens Next

The renewed interim regulation offers a 21-month runway for negotiators to resolve fundamental questions about balancing privacy and child protection. If April 2028 arrives without a permanent framework, Malta's Data Protection Commissioner and counterparts in other member states will be forced to interpret national law in the absence of EU-wide guidance—a situation that could see services available in one country but blocked in another.

For now, the immediate crisis has been averted. Platforms can continue voluntary detection, law enforcement will receive critical reports, and encrypted messaging remains off-limits to scanning. But the hard questions—how to extend detection to encrypted services, who decides when a platform poses sufficient risk to warrant a detection order, and what penalties apply for non-compliance—remain unanswered. The next 21 months will determine whether the EU can craft a workable solution or whether child-safety policy becomes another casualty of the bloc's contentious legislative process.

Author

David Vella

Business & Tech Editor

Writes about Malta's financial services sector, iGaming industry, and emerging tech scene. Enjoys breaking down complex regulatory and economic topics into clear, useful reporting.