The European Commission on 14 August 2024 published technical guidelines for detection orders that national authorities may issue under the proposed Child Sexual Abuse Regulation, clarifying that platforms—including those offering end-to-end encryption—may be required to deploy client-side scanning or other technologies to detect grooming, solicitation and CSAM in private messages when a judicial authority determines the risk is sufficiently serious. Privacy and civil-liberties organizations immediately criticized the guidance, arguing that any mandate to scan encrypted messages undermines the mathematical guarantee of end-to-end encryption and creates systemic security vulnerabilities, while child-safety advocates countered that the regulation is necessary to close the enforcement gap on services where the majority of online abuse now occurs.
The Commission's guidance does not specify which technology satisfies the detection duty, only that the measure must be effective and proportionate. Detection systems that flag patterns of grooming, sextortion or CSAM sharing—rather than reading the content of every message—address the policy objective with a narrower intrusion. Guardii monitors direct messages in real time using behavioral and content classifiers that surface only those conversations exhibiting markers of abuse, blocking hostile contact before it reaches the child and escalating verified threats to the appropriate authority, offering a mechanism that can operate in encrypted environments without requiring the platform to hold a universal key or scan all users indiscriminately.