
End-to-End Encryption News: Mid-2026 Developments Worth Your Attention
If you follow end-to-end encryption news closely, the last six months have been dense. A European Parliament vote that passed despite losing. Apple back in court against the UK government, again. Meta killing E2EE in one product while building something arguably more ambitious in another. And a new category forming quietly underneath all of it: encrypted AI chat. This piece covers what happened, what it means, and what to watch next.
Key Takeaways
- The EU's Chat Control 1.0 measure passed in July 2026 even though more MEPs voted against it than for it, due to an absolute-majority procedural threshold. A separate encryption carve-out amendment did pass, but the permanent CSAR regulation (the one that could mandate client-side scanning on E2EE services) is still being negotiated, with trilogue resuming in September.
- Apple filed a second legal challenge at the UK's Investigatory Powers Tribunal over a revised Technical Capability Notice demanding access to encrypted iCloud data. UK users still cannot enable Advanced Data Protection.
- Meta removed end-to-end encryption from Instagram DMs entirely, then weeks later launched "Incognito Chat" for Meta AI, an architecture where the provider itself cannot read user prompts or responses. Moxie Marlinspike's Confer system is the cryptographic layer underneath.
- RCS messaging between iPhone and Android gained E2EE for person-to-person chats via the GSMA Universal Profile and MLS protocol, though business messages and metadata remain outside that envelope.
- Encrypted AI chat is now a real product category, not a research curiosity, and it has almost none of the advocacy infrastructure that encrypted messaging built over two decades.
What Happened with EU Chat Control in July 2026?
314 MEPs voted against reinstating Chat Control 1.0; 276 voted for it. It passed anyway. The procedural rules required an absolute majority of 361 votes to reject the measure, and the opposition fell 47 votes short. So a regulation allowing suspicionless scanning of private messages without a warrant is now legal again until 2028.
Read that again if you need to. The measure had more votes against it than for it, and it still became law. The majority voted no, and Chat Control passed anyway.
There is a partial bright spot. In the same session, MEPs passed encryption carve-out amendments by margins of 369 and 362, formally exempting genuinely end-to-end encrypted messaging from this particular scanning regime. Those margins cleared the 361-vote threshold that the rejection couldn't reach. So E2EE services are carved out, for now, from this specific measure.
Why Does the Chat Control Carve-Out Not Settle Things?
Because Chat Control 1.0 is a temporary, voluntary derogation. The permanent regulation, the CSAR (Child Sexual Abuse Regulation), is a separate legislative track. Earlier drafts of CSAR would have obligated E2EE providers to implement client-side scanning to comply. That mechanism has not been foreclosed by the July vote. Trilogue negotiations resume in September 2026, and Q4 is the real decision window.
The encryption exemption in Chat Control 1.0 has been described as a "positive, yet rather cosmetic amendment" that covers communications where E2EE "is, has been, or will be applied." That language is narrow enough to be redefined during trilogue. Any product team claiming "we're E2EE so we're exempt" is making a bet on unfinished legislation. That bet may pay off. It also may not.
Architecture outlasts regulation. If your privacy guarantee depends on a carve-out that can be rewritten in a committee room, it is not a guarantee. It is a permission.
What Is Happening with Apple and the UK Government?
Apple filed a fresh legal challenge in July 2026 at the UK's Investigatory Powers Tribunal against a revised Technical Capability Notice (TCN) demanding access to encrypted iCloud data. This is a follow-up to the original January 2025 TCN, which demanded global backdoor access. Apple's initial response to that order was to disable Advanced Data Protection for UK users entirely rather than build a backdoor.
The broader global order was withdrawn in August 2025 under US diplomatic pressure. The Home Office then issued a revised, UK-specific TCN, which is the subject of the current challenge. Privacy International and Liberty have parallel challenges to the broader TCN regime.
What Does This Mean for UK Users Right Now?
UK users still cannot enable Apple's Advanced Data Protection. That is a real, ongoing degradation of privacy for an entire national user base. Not theoretical. Not hypothetical. Millions of people have weaker iCloud encryption today because of a government order that Apple is actively contesting in court.
No ruling timeline has been announced. The Investigatory Powers Tribunal process is opaque by design, and earlier proceedings were initially held in secret before being partially opened. This could drag on for years.
The UK situation is a clean case study in how government pressure doesn't need to succeed legally to succeed practically. The TCN is being challenged. The feature is still off. The damage is already done.
Why Did Meta Remove E2EE from Instagram DMs?
On May 8, 2026, Meta shut down optional end-to-end encryption for Instagram Direct Messages entirely. Users who had previously enabled it were told encrypted messaging on Instagram was no longer supported and were urged to back up their conversations before the cutoff.
Meta cited low opt-in usage. Optional E2EE on Instagram DMs never saw mass adoption, and the engineering cost of maintaining a parallel encrypted pipeline for a small fraction of users apparently exceeded Meta's appetite for it.
This is worth sitting with. Meta made E2EE available. Users largely didn't turn it on. Meta removed it. The lesson is not subtle: opt-in encryption at scale doesn't work. If it's not the default, it's decoration. Signal understood this a decade ago. WhatsApp understood it when it rolled out default E2EE in 2016. Instagram DMs just provided the negative proof.
How Does Meta's Incognito Chat Relate to This?
Here is where it gets interesting. Within weeks of killing E2EE on Instagram, Meta announced "Incognito Chat" for Meta AI, described by researchers as the first mass-market chatbot deployment the provider itself architecturally cannot read.
The cryptographic layer underneath is Confer, built by Signal protocol creator Moxie Marlinspike. Confer encrypts both prompts and responses so that Meta, advertisers, and anyone else on the infrastructure side cannot access the underlying conversation data.
Experts have noted the architecture doesn't fully solve the problem, since AI inference still needs to process data somewhere. The model has to see your plaintext prompt to generate a response. The question is what happens to that plaintext after inference, who has access during inference, and what the attestation guarantees look like. Confer's approach uses confidential computing enclaves to limit exposure, but "the provider can't read it" is a stronger claim than the architecture can fully deliver when inference is in the loop.
This is the honest tension at the center of encrypted AI. Messaging encryption is conceptually clean: encrypt on one device, decrypt on another, no server-side plaintext ever. AI encryption is structurally harder because the service has to understand your input to be useful. Every system in this space, including ours, has to grapple with that constraint.
Is RCS Messaging Finally Encrypted?
Yes, partially. In 2026, end-to-end encryption arrived for cross-platform RCS between iPhone and Android, built on the GSMA Universal Profile and the MLS (Messaging Layer Security) protocol. Person-to-person chats between iOS and Android now have E2EE by default.
Two significant gaps remain. Business and A2P (application-to-person) messages are not covered. And metadata (who messaged whom, when, how often) stays outside the encryption envelope entirely. If you're a consumer texting a friend, this is a meaningful improvement over the old SMS/MMS fallback. If you're worried about metadata analysis, it changes nothing.
The MLS protocol choice is worth noting. MLS is designed for large groups and federation, which makes it a better fit for the carrier ecosystem than Signal's protocol would have been. It also means the IETF standardization work that went into MLS is now deployed at genuine carrier scale, which gives the protocol real-world battle-testing it didn't have before.
What Happened with Proton and Tutanota?
Two cases from the encrypted-email world illustrate a point that gets lost in encryption debates. Proton handed over an activist's IP address under a French/Swiss legal order. A German court compelled Tutanota to provide message content in a blackmail investigation.
These outcomes are not failures of encryption. They are the ordinary reach of judicial process. E2EE limits what a provider has to give up: Proton could provide an IP address but not message contents, because they don't have the keys. Tutanota's situation was different because of how their system handles certain message types. The point is that encryption defines the boundary of what a provider can be compelled to produce. It does not place anyone beyond a valid court order.
This distinction matters because both sides of the encryption debate tend to overstate their case. Advocates sometimes imply E2EE makes surveillance impossible. Governments sometimes imply E2EE makes law enforcement impossible. Neither is true. Encryption narrows the attack surface. It doesn't eliminate it.
Is Encrypted AI Chat a Real Category Now?
Yes. Confer and Incognito Chat are the highest-profile entries, but the category is broader than one company's product. AI chatbot conversations are already showing up as evidence in criminal investigations. The sensitivity of what people tell an AI assistant (health concerns, legal questions, relationship problems, financial details) is often higher than what they put in a text message. And the advocacy infrastructure that spent twenty years defending encrypted messaging barely exists for encrypted AI.
A recent academic paper framed this as "Round 3" of the Going Dark debate, noting that governments worldwide have proposed or enacted laws limiting E2EE for law enforcement and national security purposes. Round 1 was the 1990s Clipper Chip. Round 2 was the post-Snowden messaging encryption wave. Round 3 is now, and AI is the new surface.
The structural problem is that AI chat doesn't map cleanly onto the messaging encryption model. In messaging, the server is a relay. In AI, the server is a participant. It has to process your input to generate output. That means the protections have to be different: confidential computing, attestation, minimal retention, architectural constraints on what the provider can extract during inference. These are real engineering problems, not just protocol choices.
We think about this constantly. Selina's file transfers (SelinaSEND) are end-to-end encrypted. Memory is encrypted at rest, but a slice of each request reaches a frontier provider at inference. That is the honest architecture of any AI assistant that uses frontier models. The question isn't whether the tradeoff exists; it's whether the system is designed to minimize exposure and whether the provider is honest about what's protected and what isn't.
What Should You Watch in Q3 and Q4 2026?
Four things, in order of likely impact.
EU CSAR trilogue, September onward. This is the legislative process that could mandate client-side scanning on E2EE services across the EU. The Chat Control 1.0 vote and its encryption carve-out are sideshows. CSAR is the main event. If the final regulation requires client-side scanning, every E2EE messaging and chat app serving EU users will face a build-or-exit decision.
Apple vs. UK IPT proceedings. No timeline, but any ruling here sets precedent for how Technical Capability Notices interact with encryption. If Apple loses, the UK model becomes a template for other Five Eyes governments. If Apple wins, Advanced Data Protection might come back to the UK, and the TCN mechanism gets weakened.
Confer's real-world attestation and audit results. Marlinspike's system is architecturally ambitious, but the claims need independent verification. Watch for third-party audits, academic analysis of the confidential computing guarantees, and whether Meta publishes attestation logs. The difference between "the provider can't read it" and "the provider promises not to read it" is entirely in the verifiable implementation.
Regulatory attention to AI chat privacy. As AI conversations increasingly surface in legal proceedings, expect legislative proposals to either protect or compel access to AI chat logs. The W3C's E2EE Task Force and the Global Encryption Coalition are beginning to address this, but the organized advocacy is years behind where messaging encryption advocacy was at the equivalent stage.
What Is the Bigger Pattern Here?
Three forces are converging. Governments are finding procedural and legal mechanisms to erode encryption guarantees, even when the substantive votes go against them. Companies are making contradictory encryption decisions based on product-level incentives, not consistent principles. And a new category of sensitive communication (AI chat) is emerging without the privacy infrastructure that messaging built over decades.
The lesson from all of this is the same one it's been since the Clipper Chip: architecture is more durable than policy. A legal carve-out can be rewritten in trilogue. A corporate promise can be reversed when opt-in rates disappoint. An encryption feature can be disabled for an entire country by a single government order. What persists is what's built into the system in a way that can't be unbuild without breaking the product.
That's what we optimize for when we build Selina. Not perfection (the inference tradeoff is real and we don't pretend otherwise), but architecture that makes the right outcome the default one, not an opt-in checkbox that nobody clicks.
If you want an AI assistant that treats your data this way, start a free 7-day trial, no card required.
Frequently Asked Questions
Why did the EU's Chat Control 1.0 measure pass in July 2026 even though more MEPs voted against it?
The vote required an absolute majority of 361 votes to reject the measure, and opponents only reached 314 votes against versus 276 for, falling 47 votes short of the threshold needed to block it. This procedural quirk meant the measure became law despite more MEPs opposing it than supporting it.
Does the encryption carve-out passed alongside Chat Control mean E2EE services are safe from scanning requirements?
Not fully, because the carve-out only applies to the temporary Chat Control 1.0 derogation, while the permanent CSAR regulation is still being negotiated in trilogue starting September 2026 and could still mandate client-side scanning. The carve-out language has also been described as narrow and possibly redefinable during those negotiations.
What is the current status of Apple's dispute with the UK government over encrypted iCloud data?
Apple filed a new legal challenge in July 2026 at the Investigatory Powers Tribunal against a revised, UK-specific Technical Capability Notice demanding access to encrypted iCloud data, after the original global order was withdrawn in August 2025. UK users still cannot enable Advanced Data Protection while this challenge proceeds, with no ruling timeline announced.
Why did Meta remove end-to-end encryption from Instagram DMs, and what did it launch instead?
Meta cited low opt-in usage as the reason for shutting down optional E2EE on Instagram DMs in May 2026, since maintaining the encrypted pipeline for a small fraction of users wasn't worth the engineering cost. Weeks later it launched 'Incognito Chat' for Meta AI, using Moxie Marlinspike's Confer cryptographic layer to prevent Meta itself from reading prompts and responses.
Does RCS encryption between iPhone and Android fully protect user privacy now?
Person-to-person RCS chats between iOS and Android now have end-to-end encryption by default, built on the GSMA Universal Profile and the MLS protocol. However, business/A2P messages aren't covered, and metadata like who messaged whom and when remains outside the encryption entirely.
Sources & References
- RCS End-to-End Encryption in 2026: What It Means for Business Messaging - nativeMsg
- After Years of Controversy, the EU’s Chat Control Nears Its Final Hurdle: What to Know | Electronic Frontier Foundation
- How end-to-end encryption is becoming the new standard for consumer financial defence
- Global Encryption Day 2026 – Global Encryption Coalition
- End-to-End Encryption and “Going Dark” - Security Boulevard
- End-to-End Encryption and "Going Dark" - Schneier on Security
- Meta to Shut Down Instagram End-to-End Encrypted Chat Support Starting May 2026
- End-to-End Encryption (E2EE) Task Force Call
- nulab faculty christo wilson featured
- Chat control survives, encrypted messaging doesn’t count | Andrea Fortuna
- EU Lawmakers Revive the Chat Control Vote - Cointribune
- EU Chat Control 2026: The Vote That Passed and Failed at the Same Time — Hive Security
- EU Chat Control: The Fight to Scan Every Private Message (Live Tracker)
- Why Chat Control 1.0 is the EU's most Orwellian law yet
- EU Parliament Passes Chat Control 1.0: July 2026 Vote — vpn.social
- Chat Control EU Vote: Encryption and Crypto at Stake
- The Majority Voted No. Chat Control Passed Anyway.
- Apple fights UK's latest push for encrypted user data access
- UK faces new legal challenge from Apple over backdoor access to iCloud data
- Inside Apple’s Ongoing Encryption Battle with the UK | Cyber Magazine
- Apple files legal challenge against UK demand for encrypted data access
- Apple challenges UK government’s latest demand for iCloud backdoor: report | TechCrunch
- Apple launches second legal challenge to UK iCloud backdoor order, per report - 9to5Mac
- Apple Launches New Legal Challenge Against UK Backdoor Demand - MacRumors
- Apple vs UK: The Fight Over Your Encrypted Data
- The UK's Demands for Apple to Break Encryption Is an Emergency for Us All
- Free Trial
- Meta’s confusing new approach to chat privacy | Malwarebytes
- Signal Creator Brings Encryption to Meta AI | The Daily Perspective
- WhatsApp vs Signal vs Telegram: Which Is Most Secure in 2026? • SQ Magazine
- Messenger comparison 2026: Signal, WhatsApp, Telegram – who actually protects your data?
- Top 5 Secure Messaging Apps of 2026: Signal vs WhatsApp vs the Rest | Deepak Gupta
- The Day the Provider Stopped Reading Your Chats:WhatsApp Introduces Encrypted Chats with Meta AI - MIAI
- Signal's Moxie Marlinspike Brings Encryption to Meta AI
- Signal’s Creator Joins Forces to Enhance Encryption for Meta AI – IT Magazine
- encrypted chat
