The Regulation to Prevent and Combat Child Sexual Abuse (Child Sexual Abuse Regulation, or CSAR) is European Union pending legislation to require digital platforms to assess and mitigate the risk of being used to distribute abuse material or solicit children, enable authorities to remove or block illegal material, and establish a center for regional coordination and victim assistance. It is commonly referred to by critics as Chat Control 2.0 or simply Chat Control. The legislation is supported by child advocacy groups and most EU member states. While compromises have been reached on most provisions in EU negotiations, there is no agreement on the scope and safeguards for controversial mandatory detection measures. Civil society and privacy activists argue those measures, affecting social media companies and messaging apps, could undermine privacy and data protection through indiscriminate surveillance.
Background The EU response to child sexual abuse has historically been divided between a 2011 criminal-law directive implemented unevenly by member states, voluntary action by online platforms, and disjoint law-enforcement and victim-support programs. Reviews of the 2011 directive identified implementation gaps, while the Council and Parliament called in late 2019 for more coordinated EU action. The COVID-19 pandemic intensified concerns by moving schooling and social contact online, increasing the time spent online by both children and offenders, and reducing the capacity of hotlines and law-enforcement bodies. The Commission incorporated the issue into its 2020 Security Union programme, and adopted its strategy for "a more effective fight against child sexual abuse" on 24 July 2020. The strategy brought prevention, enforcement, victim support and digital platform responsibilities into one programme, and proposed temporary and permanent legislation to harmonize and then extend voluntary platform detection practices. In October 2022, Article 18 of the Digital Services Act introduced requirements for some businesses to report conduct threatening to life or safety in a manner broadly compatible with CSAR, but explicitly stopped short of requiring proactive detection.
Industry practice Voluntary detection of abuse material by digital platforms dates back at least to the mid-1990s, when AOL manually reviewed suspected abuse material and later developed automated processes. By 2015, the Internet Watch Foundation distributed a fingerprint database created from confirmed abuse material, including images obtained through its own investigations, public and industry reports, and the UK police Child Abuse Image Database. Facebook, Google, Microsoft, Twitter and Yahoo helped trial and implement the service, comparing fingerprints generated from newly uploaded images against the database. Use of automated systems is widespread but uneven, with existing systems providing inconsistent coverage and oversight. In 2020, Facebook submitted 20.3 million reports to NCMEC, compared with 546,704 from Google, 144,095 from Snapchat, 96,776 from Microsoft and 265 from Apple. In one 2023 survey, only 20 of 50 platforms issued transparency reports, and only 10 defined prohibited abuse material in sufficient detail, limiting assessment of the effectiveness of platforms' measures. Another study concluded substantial differences in the metrics and reporting methods used prevented assessment of effectiveness.
Automated detection Existing industry practice relies primarily on automated detection technology, of which the most established is perceptual hashing, while some providers use machine learning to detect previously unknown images, and language models to identify grooming. One of the most widely used perceptual hashing systems is PhotoDNA, developed by Microsoft in 2009. A 2023 analysis of PhotoDNA by Ofcom reported a threshold providing resistance to alterations produced a false positive rate of 0.3% under the study's conditions. Published performance for other commercial classifiers and grooming detection systems have generally been unavailable. Of 4,192 reports assessed by Irish police in 2020, 852 were confirmed abuse material while 471 were false positives, illustrating the potential base-rate problem associated with detection at scale. By contrast, a 2025 European Commission review reported that automated detections were "overwhelmingly confirmed" following human review.
… excerpt ends here. Continue reading the full article.



