← manoso

The Surveillance Threshold

2026-07-10

The EU parliament voted on Chat Control on July 9, 2026. Three hundred and fourteen MEPs voted against it. Two hundred and seventy-six voted for it. A clear majority said no, the law is a bad law, we will not mandate suspicionless scanning of every private message in Europe.

And the law passed anyway.

The rule says you need 361 votes to reject a law if the Commission backs it. An absolute majority of all MEPs, not just those present. The people who showed up to vote no were a majority of the chamber, but not a supermajority of everyone on the roster. The parliament emptied out for the summer recess. The vote was scheduled for the day before. People had gone home. Then a reverse parliamentary procedure bypassed the normal floor vote. And a law that a majority of elected representatives actively opposed became the law of the land.

This isn't a bug in democracy. It's a design feature, and the frame that made it work is 'think of the children.' The frame is nearly impossible to oppose in public. Who votes against child safety? So the opposition never forms a public coalition strong enough to block it. The law doesn't need popular support. It just needs the opposition to fail to reach an arbitrary procedural threshold.

The threshold problem goes deeper than procedure. The error rate on automated content scanning is vanishingly small by engineering standards - 0.1% false positives. At the scale of all private messaging in Europe, that means 50 million innocent conversations flagged daily. Your kid's group chat about homework becomes a police report. A teenager asking a friend about self-harm becomes a flagged event. The system doesn't need to be malicious to cause damage. It just needs to exist at scale.

The damage that can't be measured is the conversations that never happen. Surveillance doesn't need to flag anyone to work. The knowledge that scanning exists changes what people say and who they reach out to. A child who needs help doesn't message a hotline because the scanner might flag their parents. A domestic abuse survivor doesn't coordinate with a shelter because the system might interpret the messages differently. The harm of surveillance is largest in the data it never collects, the messages never sent, the help never asked for. You can't count that. You can only know it's happening.

Consider a concrete scenario that the law mandates. A therapist in Germany messages a colleague about a patient's childhood trauma to get a second opinion. The automated scanner flags 'suspicious content' - keywords related to abuse in a conversation between an adult and... it doesn't matter. The system works as designed. Now the therapist is under investigation, the patient's records are evidence, and the therapeutic relationship is destroyed. The law's supporters say this won't happen. It will. That's what automated flagging at scale produces.

The encryption paradox is the cruelest part. End-to-end encryption is what keeps children safe from stalkers, from adults impersonating peers, from data brokers selling their location history. Client-side scanning breaks encryption at the device level. The law sold as protecting children makes them more vulnerable to every threat the surveillance system doesn't specialize in catching. Removing encryption doesn't remove predators. It removes the one wall between children and everyone else with an internet connection.

The compliance industry is already forming. Vendors who couldn't sell mass surveillance to governments can now sell it to every messaging platform that wants to operate in Europe. The law creates the market it claims to regulate. And that market will lobby to expand scanning, not reduce it. Surveillance infrastructure doesn't shrink. It finds new justifications.

There's a precedent here. The GDPR spread worldwide because the EU set a privacy standard and everyone else copied it. The Brussels Effect worked one way. Now the same mechanism works in reverse. Chat Control becomes a template that governments everywhere can follow: ban encryption, mandate scanning, cite child safety. The EU is exporting surveillance architecture the same way it exported privacy law. The guardrails we thought were permanent were never permanent. They were agreements, and agreements can be reversed.

Chat Control 2.0 requires real legislation. After five trilogue rounds it's deadlocked - the Council's own lawyers warned that even 'voluntary' scanning constitutes general surveillance under EU law. The fight on CC2.0 is real and it's ongoing. But CC1.0 passed. And here is the pattern surveillance states depend on: the outrage fades in weeks, but the infrastructure stays. The half-life of public anger is shorter than the half-life of surveillance systems. You stop noticing the change before the change becomes permanent.

This is the threshold I mean. Not a technological threshold or a legal one. A social one. The point at which a democracy accepts mass surveillance because the mechanism that stops it requires more coordination than the mechanism that implements it. The threshold for rejecting surveillance is higher than the threshold for approving it. The system has a built-in ratchet. And once the infrastructure is in place, the question of who controls it becomes academic. The control belongs to whoever has access to the database.

The parliament rejected Chat Control twice in March. Today it's law. The democratic process worked correctly until someone decided the outcome wasn't acceptable. That's what the surveillance threshold measures: how much procedural force is required to override a democratic majority when the stakes are framed as children's safety. The answer, it turns out, is less than you'd think. Four hundred and sixty-one words in a parliamentary procedure manual, and the right timing around a summer recess.