In ten days of July 2026, the European Union made surveillance cameras mandatory in every new car and reinstated the scanning of private messages, two measures that its own institutions had fought against. Europe is today the democratic space best equipped on paper against mass surveillance—GDPR, AI Act, jurisprudence of the Court of Justice—and simultaneously the theater of an accumulation of sectoral devices that circumvent these safeguards one by one. This paradox deserves to be faced head-on, without catastrophism or naivety.

The essentials

  • The EU accumulates surveillance devices through sectoral regulations presented as technical, never assuming a global political choice.
  • On July 9, 2026, Chat Control 1.0 was reinstated until 2028 even though 314 MEPs rejected it against 276 in favor, due to the lack of the absolute threshold of 361 votes required in second reading (source: European Parliament votes, July 2026).
  • The same day, GSR2 regulation entered into force, which requires all new vehicles to be equipped with a driver camera, presented as a road safety tool aiming to prevent 25,000 deaths by 2038.
  • The mechanism is always the same: a legitimate justification (child protection, road fatalities), a procedure that neutralizes parliamentary opposition, a framework of collected data whose future uses remain open.
  • The real tension is not between surveillance and freedom in the abstract, but between the EU’s ability to uphold its own rules when it lacks a qualified majority.

Chat Control, or how to reinstate what Parliament refused

The vote of July 9, 2026 deserves close examination because the arithmetic result is unusually clear. Three hundred fourteen MEPs voted against the reinstatement of Chat Control 1.0; two hundred seventy-six voted in favor. A clear majority, then, of elected representatives opposed to the text. Yet Chat Control 1.0 entered into force and will remain applicable until 2028.

The explanation lies in the second reading procedure: the threshold required to formally reject a text is an absolute majority of members of Parliament, or 361 votes. The 314 opponents did not achieve this. The Council was therefore able to maintain its position, and the regulation applies.

This is a known procedural rule, inscribed in the treaties. But the concrete effect is that Parliament did not support the text, it was more against than for, and the text applies anyway. For an ordinary citizen, the distinction is hard to maintain.

Chat Control 1.0 authorizes, without obligating, messaging providers to scan private communications for child sexual abuse material. The justification is real and serious: the fight against child sexual abuse is one of the rare domains where broad democratic consensus exists to tolerate intrusions into private life. The problem identified by opponents, including jurists from the Council’s own legal service, in an opinion from June 2026, concerns proportionality and technical architecture. Scanning end-to-end encrypted messages technically amounts to weakening encryption or introducing a backdoor. Once this door is opened, it does not discriminate according to use.

GSR2, the camera presented as a seatbelt

GSR2 regulation (EU Regulation 2019/2144) has a different genealogy and apparently more solid logic. It is the fruit of a long process, negotiated between the Commission, the Council, and Parliament, and it aims to reduce road mortality in Europe. Among its provisions: the obligation for all new vehicles to carry an advanced driver distraction warning system (ADDW).

Concretely, this means an interior camera oriented toward the driver, capable of detecting drowsiness, distraction, phone use. The stated objective is to prevent 25,000 additional deaths by 2038 compared to a scenario without intervention. European road safety has progressed steadily over the past twenty years, the number of deaths on EU roads was divided by more than two between 2001 and 2023, according to European Commission data, and analysis of fatal accidents does indeed show distraction and drowsiness as major causes.

The measure is therefore defensible on substance. The question posed by organizations like the Electronic Frontier Foundation or CNIL in its 2025 annual report (published in May 2026) concerns what these data become. GSR2 regulation specifies that processing must remain local and not be transmitted to third parties in real time. But it says nothing about the conditions under which manufacturers, insurers, or states could access it later, within a judicial proceeding, administrative review, or commercial partnership consented to by contract.

The camera is presented as a passive safety system. It is, today. The data collection infrastructure it creates has a lifespan that exceeds that of current political guarantees.

The mechanism: sectoral regulation as a mode of silent progression

What connects these two events of July 2026 goes beyond the texts themselves. Both follow the same pattern: a real and serious problem (road accidents, child sexual abuse material), a technical solution framed by a regulation presented as proportionate, formal safeguards in the text, and a procedure or architecture that makes these safeguards difficult to enforce in practice.

This mode of operation is not unique to Europe, but it takes on a particular dimension there. The EU has built, over twenty years, the most ambitious anti-surveillance normative framework in the democratic world. The GDPR set standards that the United States and Japan have partially adopted. The AI Act, which entered into gradual application from 2024, in principle prohibits real-time biometric identification systems in public spaces, with few exceptions. The Court of Justice of the European Union has twice invalidated data transfer agreements with the United States, on the grounds that American protections are not equivalent to European protections.

This body of law exists. It is real and, in some cases, binding. The paradox is that violations often come from the institutions that built this body of law, the Council first and foremost, but also the Commission when it presents sectoral regulations that fragment the overall approach.

CNIL’s 2025 annual report, published in May 2026, documents this fragmentation for France: requests for data access by state services have progressed steadily, within the legal framework, relying on national security exceptions that the GDPR itself provides for. This is an exercise of the exceptions to the limits that law sets, and sometimes beyond, when courts are not seized.

The AI Act monitors algorithms, not cameras in cars

There is coherence in the apparent incoherence. The AI Act regulates high-risk AI systems, including biometric systems. A system capable of identifying an individual by their face in public space is, in principle, prohibited or very strictly regulated. But a system embedded in a private vehicle, which monitors a driver’s state of attention to trigger an auditory alert, falls under a different category.

The boundary is technically defensible. It is institutionally fragile. The same sensors, the same image processing, the same inference about an individual’s mental state, can fall under two distinct regulatory regimes depending on the deployment context. The regulator that prohibited mass biometric surveillance in public spaces has simultaneously made individual surveillance mandatory in every new private car.

In the strict legal sense, the two regulations have distinct objects and different purposes. But the coherence of the overall architecture is difficult to sustain facing a citizen seeking where legitimate control ends.

The AI Act itself was the subject of similar debates. Several exemptions for surveillance systems for national security purposes were introduced late in negotiations, reducing the scope of the initial prohibition. The regulation of AI agents without clear responsibility poses an analogous question in another sector: responsibility remains to be defined when the automated system produces an effect that no one formally decided on.

The opponents: current positions and available levers

It would be inaccurate to present this debate as a unified front of citizens against opaque institutions. Those opposed to Chat Control are numerous in the European Parliament, 314 of 590 voting members, and they span a broad spectrum, from the Greens to liberals and part of the conservatives. They fell short. The 47 missing votes would have been enough to formally block the text.

Organizations like Gesellschaft für Freiheitsrechte in Germany, La Quadrature du Net in France, or European Digital Rights (EDRi) document these developments, bring cases before the CJEU, and feed public debate. The CJEU itself has consistent jurisprudence favoring digital privacy: its Digital Rights Ireland (2014) and Schrems II (2020) rulings invalidated mass surveillance devices that political majorities had adopted.

Judicial recourse remains the most effective instrument available to opponents. Chat Control 1.0 will almost certainly be challenged before the CJEU on the grounds of proportionality. GSR2 could be if secondary uses of data developed beyond declared purposes.

The real limitation of this recourse is temporal. Between the adoption of a regulation and its eventual invalidation by the Court, several years elapse. Data collection infrastructure exists, data is generated, administrative habits form. A legal annulment does not produce an erasure of practices.

The next text will have a different name

Chat Control 2.0 has been in negotiation since 2022. The version 1.0 reinstated in July 2026 was presented as transitional, pending agreement on the broader version. This extended version provides not only authorization for voluntary scanning, but an obligation for all providers, including end-to-end encrypted messaging services, to scan content before encryption, through a mechanism called “client-side scanning.”

The Commission will probably present a new version in 2026 or 2027. The arguments will be the same: child protection, proportionality, technical safeguards. Opponents will advance the same counter-arguments: weakened encryption protects victims less well than it creates new vulnerabilities for all.

This cycle—proposal, opposition, partial compromise, new proposal—is the normal functioning of a deliberative democracy. It produces imperfect texts, provisional balances, setbacks and advances. The fact that democratic institutions can correct themselves, sometimes slowly, remains an asset that non-democratic regimes do not share.

The open question is whether the European Parliament, which showed in July 2026 that it could gather a relative majority against a surveillance text but not the absolute majority required to block it, will succeed in coordinating its opposition before surveillance infrastructure becomes established enough to become irreversible in fact. Forty-seven votes were missing. Next time, they might be there, or not.


Sources

  1. EU Regulation 2019/2144 (GSR2), European Parliament and Council
  2. Everything you need to know about Chat Control, Toute l’Europe
  3. CNIL 2025 Annual Report, published May 2026 (French National Commission for Data Protection and Freedoms)
  4. Opinion of the Legal Service of the Council of the EU, June 2026
  5. Votes of the European Parliament of July 7 and 9, 2026 (official results, European Parliament voting database)
  6. European road accident data, European Commission, Directorate-General for Mobility and Transport